Live data from Hacker News

Mullvad VPN now accepts Monero payments

mullvad.net

161–170 of 246 posts

Re: Mullvad VPN now accepts Monero payments

#161

Earlier quoted context omitted.

> My only issue is that is seems to have become increasingly difficult to access many websites through their servers. Welcome to the world of Tor users. People who value online dignity need to work together against privacy hostile web technologies. My present bugbear is Cloudflare, who seem to do a lot to disrupt privacy respecting technologies. Ultimately though, the power lies with web service designers. One can no…

Yea problem from an admin perspective is that all malicious traffic attempts to use privacy respecting technology. It’s more guilt by association than anything else for the legitimate users. One of the weird realities is that in order to combat fraud you need to be able to identify the source, which is a hard reality as a privacy advocate.

Not specifically picking on you (thanks for replying) but may I rephrase that a little and then ask something;

  "Sinners look just like saints, so it's necessary to punish all, to
  destroy the riches of the many in order that wicked few do not
  escape."
Is that a fair framing of the "ethics" of what you said? (I'm not attributing that as 'your' argument, I understand you're kinda just trying to 'explain' something as you see it).

Do you think this kind of thinking can continue to stand if technology is ever going to be fair and useful to everyone? Or do we just accept that technology always amplifies as least as many problems and injustices as it solves?

Re: Mullvad VPN now accepts Monero payments

#162

Earlier quoted context omitted.

Yea problem from an admin perspective is that all malicious traffic attempts to use privacy respecting technology. It’s more guilt by association than anything else for the legitimate users. One of the weird realities is that in order to combat fraud you need to be able to identify the source, which is a hard reality as a privacy advocate.

Not specifically picking on you (thanks for replying) but may I rephrase that a little and then ask something; "Sinners look just like saints, so it's necessary to punish all, to destroy the riches of the many in order that wicked few do not escape." Is that a fair framing of the "ethics" of what you said? (I'm not attributing that as 'your' argument, I understand you're kinda just trying to 'explain' something as yo…

No, because you're framing it like they're blocking or challenging every user that comes to their site. Instead, when 90% of your malicious traffic comes from VPNs/TOR, it makes way more sense to just block or challenge those specifically even if it causes an inconvenience on the ones who use those services in a non-malicious way.

Re: Mullvad VPN now accepts Monero payments

#163

Earlier quoted context omitted.

> My only issue is that is seems to have become increasingly difficult to access many websites through their servers. Welcome to the world of Tor users. People who value online dignity need to work together against privacy hostile web technologies. My present bugbear is Cloudflare, who seem to do a lot to disrupt privacy respecting technologies. Ultimately though, the power lies with web service designers. One can no…

Yea problem from an admin perspective is that all malicious traffic attempts to use privacy respecting technology. It’s more guilt by association than anything else for the legitimate users. One of the weird realities is that in order to combat fraud you need to be able to identify the source, which is a hard reality as a privacy advocate.

Where do you have the information from that "all malicious traffic attempts to use privacy respecting technology."? I just checked an access.log (from a searx instance) and an auth.log for malicious traffic and it doesn't look at all like that.

ssh bruteforce top 5 offenders:

147 (Tor: 0) TENCENT-NET-AP-CN

133 (Tor: 0) DIGITALOCEAN-ASN

31 (Tor: 0) CHINANET-BACKBONE

17 (Tor: 0) BAIDU

13 (Tor: 0) CHINANET-SH-AP

Overall there where 737 unique IPs from 241 ASNs and 1 was a Tor node.

access log top 5 offenders:

76 (Tor: 0) DIGITALOCEAN-ASN

58 (Tor: 0) CONTABO

54 (Tor: 0) AMAZON-AES

50 (Tor: 0) KAZTELECOM-AS

34 (Tor: 0) CORBINA-AS

Overall there where 1672 unique IPs from 618 ASNs and 4 where Tor nodes.

Re: Mullvad VPN now accepts Monero payments

#164
post #72

What are people using VPNs for mostly, if they're living in a country without internet censorship? It's either your ISP or the VPN provider, which can log the websites you have visited, so there isn't a clear advantage of using a VPN. Sure the VPN provider may claim to log nothing, but that's hard to confirm and not proven to be true in some cases (related thread regarding Protonmail: https://news.ycombinator.com/ite…

I use Mullvad mainly for privacy but also to dodge EU cookie bullshit. The internet becomes so much better just by using a Swiss IP addres.

Re: Mullvad VPN now accepts Monero payments

#165
post #54

Thank you, Mullvad team! This is quite literally the only feature I've been wanting. Everything else works well. Bandwidth? Excellent. Apps? Excellent. WireGuard? Excellent. No form of KYC required, period? Excellent. Payment options? Excellent. I hope I don't live to see you turn into every other shady VPN service.

I really like mullvad's service too (wiregaurd)... My only issue is that is seems to have become increasingly difficult to access many websites through their servers. I suppose this is inevitable to some degree with any VPN service, it's part of the deal for more privacy, you have to share an IP with potential sources of abuse. But it seems to have gotten really bad recently to the point that I end up server hoping t…

>seems to have become increasingly difficult to access many websites through their servers.

And i, very happily, continue on without those 'many websites'. Of which, there are actually, very, very few for me. Nevertheless - fuck 'em; and not missed.

Re: Mullvad VPN now accepts Monero payments

#166

Earlier quoted context omitted.

Yea problem from an admin perspective is that all malicious traffic attempts to use privacy respecting technology. It’s more guilt by association than anything else for the legitimate users. One of the weird realities is that in order to combat fraud you need to be able to identify the source, which is a hard reality as a privacy advocate.

HN tends to be pretty micropayment / cryptobro averse (for good reason, mostly) but I think this is a problem that crypto could legitimately solve - Tie an anonymous 'identity' to a well-seasoned (unmoved for >x time, where x = days for some things or maybe years for some things) wallet with some reasonable amount of funding in it ($100 or something) and you become 'Guy who owns that hundred bucks'. Moving the hundre…

Your talking about earned capital as a forfeitable deposit. Sure that scheme has its place.

I joined HN for one or two reasons. To research a book. But also to promote my last book. Anyone can post here with a throwaway, yet I didn't want to be an interloping dick who felt entitled to hit and run posting links to my own vanities... so I decided; join, contribute, participate, earn. After a few months I don't feel bad about plying my own wares a little. Reputation (social capital) is natural and ancient and doesn't really need crypto.

Most of the Web isn't that though. As an information system, as Sir Tim first coined it, it's a publishing machine: You advertise a service, I send "requests", you send "responses", we part ways without complications. Quick anonymous sex on the beach. So-called Web2.0 f-cked that massively. Web2.0 wants to exchange phone numbers. And once the surveillance capitalist creeps latched on to stalking everyone around the neighbourhood... well here we are.

I think what some Web3.0 people think is that crypto can repair some kind of "middle ground", where Web2.0 type behaviours can take place but anonymously and under conditions controlled by "stakes". I think this won't work for psychological and game theoretical reasons we can't get into here. Instead I think we need to repair the Web1.0 layer at least, and since transport level security and anonymity have become necessary in a post-Snowden era, for me that means getting rid of the selective prejudice inflicted by systems like Cloudflare.

Re: Mullvad VPN now accepts Monero payments

#167

Earlier quoted context omitted.

Not really, this happens with any VPN service to the point that if VPN providers were more honest this is what they would tell people: Online stores are more likely to flag your purchase as suspicious on the admin side(e.g the Shopify console) You will run into captchas and prompts for authentication more often You may not be able to log into some of your more sensitive services(like banking) Streaming sites will blo…

> Online stores are more likely to flag your purchase as suspicious on the admin side(e.g the Shopify console) I'm not sure a VPN provides much utility when you're already punching your (billing|shipping) address and CC number into a website - that is, unless you're using a drop site for your packages, which definitely will make you look like someone who has stolen CC digits and is trying to cash in on them.

Well, to give one use case example, when I'm traveling I want to access websites from a US IP address so that l18n settings on websites don't serve me in another language or metric units by default. That's one way I use VPNs that have nothing to do with trying to hide from the NSA or whatever people think they're doing.

Re: Mullvad VPN now accepts Monero payments

#168
post #118

Mullvad always seemed too good to be true. So that's why i'd won't use it if i'd had critical stuff to do. I do love Mullvad, but so aircrack-ng

Thank you for the compliment! We are indeed for real, but I don't expect this comment will convince you. I'd love to know what we could do that would change your mind. The same goes for anyone else reading this. Are you worried that we are too good to be true? What could we do to become more trustworthy in your eyes? Cheers, Fredrik Stromberg (cofounder of Mullvad)

My only feedback is that Mullvad is based out of Sweden which is a member of Fourteen Eyes. I don’t expect you to move your location but it is the only detractor I can think of.

Re: Mullvad VPN now accepts Monero payments

#169

Earlier quoted context omitted.

Not specifically picking on you (thanks for replying) but may I rephrase that a little and then ask something; "Sinners look just like saints, so it's necessary to punish all, to destroy the riches of the many in order that wicked few do not escape." Is that a fair framing of the "ethics" of what you said? (I'm not attributing that as 'your' argument, I understand you're kinda just trying to 'explain' something as yo…

No, because you're framing it like they're blocking or challenging every user that comes to their site. Instead, when 90% of your malicious traffic comes from VPNs/TOR, it makes way more sense to just block or challenge those specifically even if it causes an inconvenience on the ones who use those services in a non-malicious way.

Just to be clear I was asking that of the parent poster brightball.

I'm trying to map the technical explanations people give onto what may be going on for them at "ethical reasoning" level.

You're welcome to add your interpretation of course.

You probably guessed I'm looking to distinguish a Bentham from Mill sort of utilitarianism.

Re: Mullvad VPN now accepts Monero payments

#170

Earlier quoted context omitted.

Yea problem from an admin perspective is that all malicious traffic attempts to use privacy respecting technology. It’s more guilt by association than anything else for the legitimate users. One of the weird realities is that in order to combat fraud you need to be able to identify the source, which is a hard reality as a privacy advocate.

Where do you have the information from that "all malicious traffic attempts to use privacy respecting technology."? I just checked an access.log (from a searx instance) and an auth.log for malicious traffic and it doesn't look at all like that. ssh bruteforce top 5 offenders: 147 (Tor: 0) TENCENT-NET-AP-CN 133 (Tor: 0) DIGITALOCEAN-ASN 31 (Tor: 0) CHINANET-BACKBONE 17 (Tor: 0) BAIDU 13 (Tor: 0) CHINANET-SH-AP Overall…

Not necessarily Tor, but a VPN could be coming from any of those sources.

I spent a recent chunk of my career combating fraud on a niche-eBay style site and the people trying to defraud other users, pay with stolen credit cards, login with phished credentials, etc were consistently trying to hide their origin.

Until we started using fingerprinting techniques to track them across multiple accounts and IPs, we had no way to spot this. It was a shock to me when I realized there were legitimate uses for fingerprinting technology because I'd always associated it with ad networks and trackers. They're fairly necessary for combating fraud though.

When we stopped letting any untrusted users run a credit card if their connection couldn't be trusted, our charge backs virtually stopped. That experience makes me completely understand sites scrutinizing anonymized traffic.

Post reply on HN