Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

31–40 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#31

It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convin…

At some point of paranoia people should really look into selfhosting a VPN service. Sure, your VPS provider can see one side of the traffic so its not bullet proof, but that can be mitigated.

Mullvad is a nice middle ground for those who don't see that as worth their time or don't know how. Its good to see they're at the very least trying to keep up appearances.

Re: Infrastructure audit completed by Radically Open Security

#32
Mullvad looks like one of of the best VPN providers out there. However the use of a customised Linux Kernel and Ubuntu distribution gives pause for thought. Are they going to be able to integrate security patches quickly? Wouldn't it be better to use a standardised security focused OS?

Re: Infrastructure audit completed by Radically Open Security

#33
post #7

Title is missing the word "Radically". I didn't know "Open Security" but "Radically Open Security" is the place I've written a thesis at Edit: u/progbits is 1 minute faster than me https://news.ycombinator.com/item?id=37060828

One of the projects I worked on a couple of years ago was audited by Radically Open Security - I was extremely impressed with the quality of their specialists.

They didn't find anything of course (in the the system I was responsible for) beyond a couple of remarks (which I believe we had already explicitly marked with comments as they were marked for improvement by our static analysis tools; think "you can use a better variable name here" and "this can be simplified by using guard clauses" level). Not bad for something built under extreme circumstances and very little sleep (6-month-old-baby + COVID + crunch + 2 other busy young kids = hell).

Re: Infrastructure audit completed by Radically Open Security

#34

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

> That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago.

In the U.S, VPNs are not effective against targeted surveillance. But they very well may be effective against government passive surveillance programs like the President’s Surveillance Program.

The Snowden leaks revealed many things. What stood out most to me about them was that the government _tried_ to stay within the confines of the law. It was a very twisted, contortionist, interpretation of the law, but they did try very hard to stay within the bounds of the legal theory that allowed the program to exist.

Based on the leaks, if you’d have been running HTTPS over a VPN during the PSP, it’s likely a good portion of your traffic would have evaded the program.

https://everytwoyears.org/2020/07/13/tactical-privacy.html

Re: Infrastructure audit completed by Radically Open Security

#36

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

Hence the archive records of their yearly audit dating back to their founding year.

Re: Infrastructure audit completed by Radically Open Security

#37

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

You can't trust anything you have not built, incl. your laptop, keyboard, mouse, phone, car, even your teabag (what happens if they're randomly drugging your tea to test some pathogens, with a request from your government).

Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible.

So, the hole has no bottom.

Re: Infrastructure audit completed by Radically Open Security

#38
Up front, I believe Mullvad is the best commercial VPN solution and is doing a great job at making good privacy more accessible.

However, a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet.

I would like to remind people that VPNs only really protect you against two things: your ISP and the endpoint. And that's assuming that your ISP isn't doing some shady analytics.

That being said, knocking those two things off the board is a huge benefit to privacy and absolutely should be done.

Re: Infrastructure audit completed by Radically Open Security

#39
post #3

Thought experiment: design an architecture that passes this audit scope as written that allows for logging of user activity. I can think of at least one.

Like sending logs over the network?

It's quite common for servers to boot from the network and have no disk, and have application logs actually sent to a log server via http/udp [0].

[0] For example: https://docs.splunk.com/Documentation/Splunk/9.1.0/Data/HECE...

Re: Infrastructure audit completed by Radically Open Security

#40
post #3

Thought experiment: design an architecture that passes this audit scope as written that allows for logging of user activity. I can think of at least one.

Thought experiment: build your own VPN company that doesn't log anything and try to convince people like you that you don't do any logging
Post reply on HN