Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

61–70 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#61
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

Sidenote: I know a bunch of people from Crimea and many things we take for granted are surprisingly complex for them. People from Cuba or Iran at least have the certainty of which country they are in.

Re: Infrastructure audit completed by Radically Open Security

#62
post #46

Earlier quoted context omitted.

> that's assuming that your ISP isn't doing some shady analytics Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?

Why would they even do so ? Large ISPs are public, so this activity would appear as extra revenue (if they sell traffic data) in their financial reports and annual reports. The most likely is that ISPs are just respecting the local laws, and doing the minimum retention as required by the law (because more data storage = more costs), and that their actual fear is that someone leaks this data and causes reputation dama…

This view is extremely western, not all ISPs are obligated to show "financial reports", and "shady analytics" does not imply a user's complete network traffic record into perpetuity. And even if your arguments were valid, this is not limited to the ISPs financial gain, but surveillance which occurs in every country.

Re: Infrastructure audit completed by Radically Open Security

#63
post #26

Earlier quoted context omitted.

Isn’t trading with certain states like sanctioning of how they treat their population? Withholding trade seems fair. We don’t want to deal with you because you start murderous wars for example seems fair. As for “multi polarity”.. seems so far like the catchphrase of shitty governments and unhappy people here that dream of some radical change.. It’s a false word somehow

Yup - there's no "multi". You either live in a country that's aligned with the USA. Or you live in some sort of authoritarian hellhole. There's no democratic and prosperous country that isn't aligned with the USA somehow. Russia had the chance to become a country like that in the 90s, but they chose to have another tsar instead.

At some point, we thought it would be the BRICS. All of them have moved away from that in the last decade.

Re: Infrastructure audit completed by Radically Open Security

#64
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

[flagged]

Re: Infrastructure audit completed by Radically Open Security

#65
post #56

I have PIA paid until December but I'm getting so many captchas with them that I've been seriously considering paying for Mullvad, too. Glad to see people are still happy with them so I can go ahead.

I don't want to discourage you from using Mullvad, but there are lots of captcha and cloudflare problems there, too. I consider it a cost of doing business.

Re: Infrastructure audit completed by Radically Open Security

#66
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

I'm glad to read this. We considered switching to them earlier this year (couldn't find the budget) and it was still on the table, but this is a deal breaker. If we'd switched I'd have been in the same situation, with a lot of prepaid service I couldn't use as intended.

Re: Infrastructure audit completed by Radically Open Security

#67
post #64
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

[flagged]

"The people" value different things depending on who they are. I'm sure you can find Russians who value liberty and peace, and I'm sure you can find Americans (or Germans, or Canadians, or Australian Aboriginals) who don't.

Re: Infrastructure audit completed by Radically Open Security

#68
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

They still support opening up ports, it’s just randomized instead of dedicated like uPnP.

Re: Infrastructure audit completed by Radically Open Security

#69

Up front, I believe Mullvad is the best commercial VPN solution and is doing a great job at making good privacy more accessible. However, a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet. I would like to remind people that VPNs only really protect you against two things: your ISP and the endpoint. And that's assuming that your ISP isn't doing some shady analytic…

> that's assuming that your ISP isn't doing some shady analytics Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?

It is my understanding that many ISPs and backbone providers sell or otherwise disclose full detailed packet metadata, including precision timestamps, and that there are companies that aggregate this data across the entire Internet.

At which point your VPN becomes just another hop in the trace.

VPNs, no matter how secure they themselves are, are effective for accessing lightly geo-locked content and defeating unsophisticated analytics and tracking. They are really not a serious privacy solution in any sense, unfortunately.

Re: Infrastructure audit completed by Radically Open Security

#70
post #64
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

[flagged]

Bit of a generalisation there, how many of us in the west were against and protested against the various wars we’ve been involved in and been basically just ignored because the government just does what it wants?
Post reply on HN