Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

51–60 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#51
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

It is probably not too late

Last time I was in Gothenburg in Sweden, about one year ago, I even saw advertisements on the trams about Mullvad hiring people.

If you want to work for them, reach out to them. Maybe they need more people like us still :)

Re: Infrastructure audit completed by Radically Open Security

#53
post #44

Earlier quoted context omitted.

At some point of paranoia people should really look into selfhosting a VPN service. Sure, your VPS provider can see one side of the traffic so its not bullet proof, but that can be mitigated. Mullvad is a nice middle ground for those who don't see that as worth their time or don't know how. Its good to see they're at the very least trying to keep up appearances.

I doubt that's the better way. How is self-hosting helping with the paranoia vs. using Mullvad? I don't really see how it's more secure to run some software that you haven't audited on a VPS somewhere at a provider you haven't audited. I'd trust a company with resources to run their own hardware, investing into a more secure setup [1] and contributing to more open infrastructure [2] much more than I trust myself to r…

Self-hosting also makes you vulnerable to the network hosting you (not only the hosting server itself, but also the internet transit provider) and of course the website you are visiting, as you are the only user from that source IP (rendering a VPN practically useless).

Re: Infrastructure audit completed by Radically Open Security

#54
As ivpn's gateway in Brussels is more often than not 100% [0] during the evenings, I'm looking for an alternative. This wasn't the case until some 6-12 month. Anyone experience with mullvad's [1] throughput in Belgium?

[0] https://www.ivpn.net/status/

[1] https://mullvad.net/en/servers

Re: Infrastructure audit completed by Radically Open Security

#55
post #3

Thought experiment: design an architecture that passes this audit scope as written that allows for logging of user activity. I can think of at least one.

Thought experiment: build your own VPN company that doesn't log anything and try to convince people like you that you don't do any logging

If you don't do any logging and don't want to know what your users are doing - it means that you won't have to deal with the cops as much. And there won't be any risk of those logs getting leaked or stolen .

Unless you're de-facto part of the government like Google and Microsoft - I see no good reason to log anything more than what's legally required.

Re: Infrastructure audit completed by Radically Open Security

#57

any competent opinions on protonvpn vs mullvad vpn?

I think those two are the most reputable VPNs. I’ve used ProtonVPN for years just since I wasn’t aware of Mullvad at the time and can’t be bothered to switch. I believe ProtonVPN hasn’t had infrastructure audits, which Mullvad has had.

Re: Infrastructure audit completed by Radically Open Security

#58
post #50

[deleted]

FWIW you can look at the network traffic in your browser devtools and verify that only the public key is being sent to them. You can even hit their API endpoint with the public key you want to add manually, I just tried it and it worked.

Either way, if you don't trust them it hardly matters if your connection to their server is secure - they're the ones decrypting it!

Re: Infrastructure audit completed by Radically Open Security

#59
I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account.

Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers, so my connection mysteriously failed one day and I was left with several months of prepaid service.

I'm a bit bitter for that, but honestly their technical writing and security decisions have earned enough good will from me that I want them to keep the money. As the only VPN that doesn't feel shady, I wish them all the best.

[1] https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...

Re: Infrastructure audit completed by Radically Open Security

#60
post #46

Earlier quoted context omitted.

> that's assuming that your ISP isn't doing some shady analytics Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?

Why would they even do so ? Large ISPs are public, so this activity would appear as extra revenue (if they sell traffic data) in their financial reports and annual reports. The most likely is that ISPs are just respecting the local laws, and doing the minimum retention as required by the law (because more data storage = more costs), and that their actual fear is that someone leaks this data and causes reputation dama…

ISPs are also in the business of analytics [1, 2], and a significant percentage of customers hiding their traffic reduces the value of their analytic products.

1: https://www.bleepingcomputer.com/news/security/ftc-isps-coll... 2: https://surfshark.com/blog/isp-selling-data

Post reply on HN