Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

11–20 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#11
You’re still trusting that

Mullvad never changes

Mullvad never is compelled to change by coercion

The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion

That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago.

All VPNs have this limitation. They’re just internet resellers that amusingly try to differentiate an audience based on privacy.

Re: Infrastructure audit completed by Radically Open Security

#13
post #10
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

[flagged]

What are you doing about western governments pursuing journalists who reported war crimes in iraq?

This moral superiority about expecting people from other places to do what we don’t would be hilarious if it was completely outrageous

We’re expecting normal people to stand up against armed regimes while around the world our governments commit the worst human crimes while we’re zapping on netflix I have absolutely no words, I’m terrified

Re: Infrastructure audit completed by Radically Open Security

#14
post #10
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

[flagged]

The world is not as black and white as you paint it, taken from an outside perspective the US has also done many things that we would likely go to war for if it was anyone else, including chasing journalists across borders, forcing down diplomatic aircraft and spying on allied governments (Merkel in particular).

Regardless; your enemies are not my enemies. Even then: Sanctioning occupied territories only serves to push the occupied territory further into the occupiers hands.

Re: Infrastructure audit completed by Radically Open Security

#15
post #10
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

[flagged]

I mean, I'm super against supporting hostile government countries, but a lot of stuff is made in the US. It's hard to avoid money going there.

Re: Infrastructure audit completed by Radically Open Security

#16
post #10
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

[flagged]

Hostile to Western interests. Sanctions are nothing but legitimatized bullying of the strong over the weak. Thanks, but not. Multi-polarity is coming.

Re: Infrastructure audit completed by Radically Open Security

#17

It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convin…

I would have liked it if the audit had also provided a number of logins to be used on that server to act like typical users. Just so it was operating as a normal server would.

This could have led onto auditing a live server.

Auditing an in use customer facing server would definitely require a good amount of controls to ensure the auditors didn’t log any possible customer data.

Re: Infrastructure audit completed by Radically Open Security

#19

It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convin…

It wouldn’t make that much of a difference, I think, since they could just do the same with the real servers but only for the period of the audit. There has to be some faith that the subject isn’t actively deceptive and malicious, or the audit has to be random and at any time.

Re: Infrastructure audit completed by Radically Open Security

#20

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

Which data center company do they use?
Post reply on HN