Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

41–50 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#41

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

VPNs are for escaping private adtech firms, not governments. I don't know where you got this impression from.

Re: Infrastructure audit completed by Radically Open Security

#42

Picked up Mullvad a couple months ago, I love it's concept of just paying for the time I use.

Is that an option? I've been paying 5 euros a month for a number of years and probably use it for 10 minutes a month, on average. I would love to just plunk down 20 euros and be good for the foreseeable future, if it was a couple cents per minute.

> I would love to just plunk down 20 euros and be good for the foreseeable future

Simple, buy the number of gift vouchers on Amazon that meets your budget.

There is no limit on the number of gift vouchers you can apply to a single account.

Re: Infrastructure audit completed by Radically Open Security

#43

Up front, I believe Mullvad is the best commercial VPN solution and is doing a great job at making good privacy more accessible. However, a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet. I would like to remind people that VPNs only really protect you against two things: your ISP and the endpoint. And that's assuming that your ISP isn't doing some shady analytic…

> that's assuming that your ISP isn't doing some shady analytics

Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?

Re: Infrastructure audit completed by Radically Open Security

#44

It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convin…

At some point of paranoia people should really look into selfhosting a VPN service. Sure, your VPS provider can see one side of the traffic so its not bullet proof, but that can be mitigated. Mullvad is a nice middle ground for those who don't see that as worth their time or don't know how. Its good to see they're at the very least trying to keep up appearances.

I doubt that's the better way. How is self-hosting helping with the paranoia vs. using Mullvad?

I don't really see how it's more secure to run some software that you haven't audited on a VPS somewhere at a provider you haven't audited. I'd trust a company with resources to run their own hardware, investing into a more secure setup [1] and contributing to more open infrastructure [2] much more than I trust myself to run something securely which isn't my sole occupation.

[1] https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur...

[2] https://mullvad.net/en/blog/2019/8/7/open-source-firmware-fu...

Re: Infrastructure audit completed by Radically Open Security

#45

I switched to Mullvad after teh last article i read here on HN about how they didn't log and couldn't offer logs to the authorities. I don't have the link but I was impressed and these audits are further proof that that decision was correct.

> I switched to Mullvad after teh last article i read here on HN about how they didn't log and couldn't offer logs to the authorities

It should also be pointed out that OVPN[1] is an option as well. They were taken to court and won[2], so they demonstrated above all reasonable doubt that OVPN no-logging means no-logging.

See the link for the detail, but I quote: "the Rights Alliance and their security experts have not been able prove any weaknesses in OVPN's systems that could mean that logs are stored. "

[1]https://www.ovpn.com/en [2]https://www.ovpn.com/en/blog/ovpn-wins-court-order

Re: Infrastructure audit completed by Radically Open Security

#46

Up front, I believe Mullvad is the best commercial VPN solution and is doing a great job at making good privacy more accessible. However, a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet. I would like to remind people that VPNs only really protect you against two things: your ISP and the endpoint. And that's assuming that your ISP isn't doing some shady analytic…

> that's assuming that your ISP isn't doing some shady analytics Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?

Why would they even do so ? Large ISPs are public, so this activity would appear as extra revenue (if they sell traffic data) in their financial reports and annual reports.

The most likely is that ISPs are just respecting the local laws, and doing the minimum retention as required by the law (because more data storage = more costs),

and that their actual fear is that someone leaks this data and causes reputation damage, so they'd avoid storing anything if they can.

Re: Infrastructure audit completed by Radically Open Security

#48
post #29
post #26

Earlier quoted context omitted.

Yup - there's no "multi". You either live in a country that's aligned with the USA. Or you live in some sort of authoritarian hellhole. There's no democratic and prosperous country that isn't aligned with the USA somehow. Russia had the chance to become a country like that in the 90s, but they chose to have another tsar instead.

It's honestly very sad the way the world moves :( There was a real possibility that Russia could have joined Europe, but something got broken along the way. I'm not sure that USA is really a strong ally of Europe. It's something in-between. US has its own interests before all. They would lend us (Europe) money and sell us weapons in case we go to war, but a friend giving you a loan and making profit out of you isn't…

Every country has their own interests.

The USA is not perfect, but there isn't anyone else out there.

Beggars can't be choosers. Especially after European NATO members underinvested in defence for decades and refused to see Russia as a threat that it is.

Not that long ago France even attempted to sell them aircraft carriers.

Re: Infrastructure audit completed by Radically Open Security

#49
> These servers were deployed as though they were to be production customer-facing servers, however these servers have never been utilised as such.

> Servers that ROS was given access to for testing purposes should be isolated from production data, but we found that the Wireguard host was receiving production user traffic via multihop configuration

Ouch

Post reply on HN