Live data from Hacker News

The Mullvad Browser

mullvad.net

311–320 of 434 posts

Re: The Mullvad Browser

#312

If a lot of non-Mullvad users use it, it will create a nice pool of people with at least the same browser fingerprint. Basically, it seems like a good choice if you are already a Mullvad user and your threat model does not require the use of a Tor browser. However, if there's a significant non-Mullvad user base using it, it won't do much, as you'll just stand out as the only person using the Mullvad browser without M…

The browser fingerprint is so crazy... I don't understand how they don't regulate this shit.

The people you are looking to to regulate it are the same people who would exploit it.

I also think this approach of expecting the general public to adopt a borked browser to give deniability to people using it strategically is extremely naive. Human psychology just doesn't work like that, you might as well ask schools of fish to swim differently to hinder shark learning. To be frank, this seems like it will just create confusion vs telling people to use Tor browser.

The way to improve privacy is to provide a tool that actively enhances something incredibly well, and does everything else at least as well. If all browsers are hopelessly compromised, make something that isn't based on HTML and builds cool user interfaces directly from API calls like a videogame UI, for example.

Re: The Mullvad Browser

#313

Earlier quoted context omitted.

That's not very charitable. Some people just want to pick a different point on the tradeoff between convenience and privacy. Imagine User A uses Fastmail every day, logging in manually every morning. User B uses Fastmail every day, with a saved login cookie. How is User B's privacy any worse? What would User B gain from not having that choice?

It's not a matter of user choice, it's a matter of maintenance and product integrity. User B's privacy is objectively lessened by allowing tracking cookies, but that is their choice. What is out of the user's control is what mullvad chooses to spend their time supporting. If mullvad allows users to turn off a privacy feature, now that's a permutation they have to test for. It's also an attack vector they've enabled,…

If someone is logging into fastmail every day how does preventing this from being remembered help?

Re: The Mullvad Browser

#314
post #182
post #105

Earlier quoted context omitted.

I share a VPN subscription with my father, I use it for torrenting so my ISP can't snoop on me, and he uses it to bypass geo blocking to watch UK shows (things like BritBox, Netflix, BBC etc.) in another country. Unfortunately, there is no way to legally pay for most of these services and watch them from abroad. I tried to get us to use Mullvad, as it was perfect for me, but for him it was constant problems with the…

It annoys me that the only way to access iPlayer from abroad is via a VPN. Surely opening it up and allowing international customers to pay some form of license fee could be a nice little revenue stream for the BBC? I'm guessing the reason is just "licensing issues" but if they're making the programmes then what's the problem? I'm sure there's an international market for watching the world class output from the BBC.

a few years ago I moved outside the UK and spent the best part of 3 months (on and off) trying to access BBC content, legally, still holding residency, paying domiciliary and employment taxes, and paying for a bladdy TV loicence

of course, I wanted to do this for as close to free as possible, since plugging an aerial into a tv at home also cost next to nothing

VPNs were already being detected and banned. I tried at least 4 extensively, including tcp, udp, socks, wg, obfuscated servers, etc. to no avail

dodgy residential/mobile proxies were too unreliable for live 720p m3u streams, not to mention expensive

I went through a few cheap linux VPSs with UK ip addresses, forwarding their web streams to my tv outside the UK, until I found one that seemed to work well. so much so I even invested in some fancy routing through intermediary countries for almost jitter-free stability

until a few weeks later, back to the same old shite -- everything 403 Unauthorised

after yet a few more weeks of furious head-scratching shame over the stable-now-vanished CBeebies and BritComs daily consumption, I concluded and confirmed the BBC had just started detecting and banning datacentre IPs more aggressively

it was at this ebb I discovered the wonderful world of illegal IPTV streams and adopted a fuck you too, BBC attitude

Re: The Mullvad Browser

#315
post #182

Earlier quoted context omitted.

It annoys me that the only way to access iPlayer from abroad is via a VPN. Surely opening it up and allowing international customers to pay some form of license fee could be a nice little revenue stream for the BBC? I'm guessing the reason is just "licensing issues" but if they're making the programmes then what's the problem? I'm sure there's an international market for watching the world class output from the BBC.

a few years ago I moved outside the UK and spent the best part of 3 months (on and off) trying to access BBC content, legally, still holding residency, paying domiciliary and employment taxes, and paying for a bladdy TV loicence of course, I wanted to do this for as close to free as possible, since plugging an aerial into a tv at home also cost next to nothing VPNs were already being detected and banned. I tried at l…

I used a small independent proxy company that I paid £50 a year annually through PayPal. I think they must've been small enough to fly under the radar of the detection algorithms. When I went onto google maps connected to the proxy, it always thought I was in Dubai, which gives you an idea of the clientele.

Maybe it was something to do with the fact that it was a Proxy and not a VPN, though I'm not sure if this makes it any less detectable. I even had a Firefox extension that automatically turned on the proxy when opening iPlayer tabs! It worked very well, though I wish I could've paid the license fee and just got access.

Re: The Mullvad Browser

#316

Another useless skinjob of Firefox for folks too conditioned and paranoid to use Tor Browser or know how to edit about:config themselves, by a company selling literal snakeoil ("trustworthy VPN").

Unlike other VPNs, Mullvad states what they protect against and what they don't. This browser seems to bridge the gap about what they previously couldn't.

Considering there's no vendor lock-in and the browser is open source, I think your criticism is completely unwarranted.

Re: The Mullvad Browser

#317
post #20

I guess why not. This is an open source, rebranded Firefox and Firefox-like browsers could use some publicity. It promotes privacy and privacy can use some publicity too. Tor too. Mullvad seems to be honest in the fact that their business model is selling VPNs and it's nice they are saying it's not enough. They are not saying that you might not need one though. We need a Firefox with good defaults and it seems like t…

I'm quite surprised nobody mentioned Librewolf yet. https://librewolf.net/ It's a custom build of Firefox with somewhat sensible, sometimes strict, privacy respecting default settings. There's also the Arkenfox user.js which you can put on top of vanilla Firefox, aiming for the most privacy and security possible. https://github.com/arkenfox/user.js

My issue with these browsers, including Firefox with things like fingerprint resisting enabled, is that it breaks a lot of sites. Add a VPN to the mix and a lot of sites flat out refuse to let you interact with them, or they give you 5 minutes of captchas, or they require 2 factor login despite asking them to remember your device. I have to open some sites (banking, brokerage, health insurance) on a near-daily basis in Chrome with no extensions and no VPN instead of my regular firefox+vpn.

A lot of sites allow interaction even with the above but they shadowban you without telling you. Craigslist shadow bans and auto-spam-filters any submissions done with a VPN, and then also auto-spam-filters any subsequent submissions on the same account even with the VPN turned off.

Reddit also universally spam-filters any submissions and comments done under a VPN, and rate limits your commenting a shitload on VPNs.

Re: The Mullvad Browser

#318
post #20

I guess why not. This is an open source, rebranded Firefox and Firefox-like browsers could use some publicity. It promotes privacy and privacy can use some publicity too. Tor too. Mullvad seems to be honest in the fact that their business model is selling VPNs and it's nice they are saying it's not enough. They are not saying that you might not need one though. We need a Firefox with good defaults and it seems like t…

Tor is borderline useless for privacy. It was literally built for the government [1] 1: https://en.wikipedia.org/wiki/Tor_(network)#History

You do realize that tor is open source and has been under scrutiny by some of the worlds leading security researchers? It may not be 100% perfect, but claiming it’s useless and ineffective simply because it was born out of government research is completely asinine.

Re: The Mullvad Browser

#319
post #97

Earlier quoted context omitted.

But isn't this what Firefox containers achieve? My understanding is that cookies etc aren't shared between containers, so I can stay logged in, and not be tracked across websites. If it's achievable, why compromise?

What I'd like is a Mullvad container in regular Firefox so I can choose what sites to open in it, or rather make it the default and move a site to another container if I want permanent cookies. I use temporary containers now but the extra fingerprinting features appeal to me.

You could look into Mozilla's VPN offering, it does what you want and is powered by Mullvad.

Re: The Mullvad Browser

#320
post #281

Earlier quoted context omitted.

Can you provide a few examples? Has this been reported to Mullvad?

Split tunnel + qbittorrent leaks your ip

There's absolutely no way for qbittorrent to leak your IP if you've configured it correctly to only use the Mullvad network interface.
Post reply on HN