Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

71–80 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#71
post #64
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

[flagged]

I am speechless; I can think of a dozen or so glib responses to put down this line of reasoning in a combative way.

I will do my best to go against that instinct and instead say;

1) I don't believe necessarily that Crimeans are "Russian"

2) I don't believe that we can talk about a countries people as being homogeneous.

3) I don't believe we should be deciding what liberty people should be entitled to, that feels decidedly totalitarian to me, it would be very easy to decide that you dear reader are not entitled to liberty either, since you implicitly support *gestures broadly*.

Re: Infrastructure audit completed by Radically Open Security

#72

Up front, I believe Mullvad is the best commercial VPN solution and is doing a great job at making good privacy more accessible. However, a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet. I would like to remind people that VPNs only really protect you against two things: your ISP and the endpoint. And that's assuming that your ISP isn't doing some shady analytic…

those two are huge though, and part of any multilayered approach to security. I doubt if most people think "VPN and done"

Re: Infrastructure audit completed by Radically Open Security

#73
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

I also got upset when I had to implement geoip tracking to block specific countries and thought about the people that wouldn't have access to the free service we were providing, which I thought could help someone bootstrapping their small business and potentially improve their lives.

That being said, many people consider sanctions as an act of war[0] and if you think of them like that, well obviously it sucks, it's war and war-like consequences always suck for the people on the ground.

Just make sure when your boss asks you to implement geoblock bans for sanctions, do what you need to do and not more like trying to block VPN users or other shenanigans. Don't break the law but don't make it harder for people on the ground to use their right to internet access.

[0] https://moderndiplomacy.eu/2022/06/29/economic-sanctions-as-...

Re: Infrastructure audit completed by Radically Open Security

#74

Up front, I believe Mullvad is the best commercial VPN solution and is doing a great job at making good privacy more accessible. However, a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet. I would like to remind people that VPNs only really protect you against two things: your ISP and the endpoint. And that's assuming that your ISP isn't doing some shady analytic…

> that's assuming that your ISP isn't doing some shady analytics Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?

the reason the uk wants an encryption backdoor is because it's expensive to do statistical analysis of encrypted traffic. there's ways to make it more difficult, but if you own the certificate that a tls endpoint uses you can just open it and reencrypt it for the destination. this is called break and inspect. if a vpn uses different certificates and is built well, there would have to be a flaw (spyware, vulnerability, etc) on one of the endpoints for anyone other than you and the vpn to read the encrypted data.

Re: Infrastructure audit completed by Radically Open Security

#75

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

You can't trust anything you have not built, incl. your laptop, keyboard, mouse, phone, car, even your teabag (what happens if they're randomly drugging your tea to test some pathogens, with a request from your government). Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible. So, the hole has no bottom.

if you want privacy on the internet you have options. VPNs give you privacy from your local network and ISP and a little bit from the destination service, and that's it.

there are options to have privacy from additional kinds of parties. i2p, tor. whonix distribution of linux, tails…

Re: Infrastructure audit completed by Radically Open Security

#76
post #46

Earlier quoted context omitted.

> that's assuming that your ISP isn't doing some shady analytics Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?

Why would they even do so ? Large ISPs are public, so this activity would appear as extra revenue (if they sell traffic data) in their financial reports and annual reports. The most likely is that ISPs are just respecting the local laws, and doing the minimum retention as required by the law (because more data storage = more costs), and that their actual fear is that someone leaks this data and causes reputation dama…

for security, all dangerous malware runs on encrypted traffic

Re: Infrastructure audit completed by Radically Open Security

#77
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

They still support opening up ports, it’s just randomized instead of dedicated like uPnP.

Oh really? Could you elaborate or point me in the direction of more information on this please?

Re: Infrastructure audit completed by Radically Open Security

#78

It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convin…

At some point of paranoia people should really look into selfhosting a VPN service. Sure, your VPS provider can see one side of the traffic so its not bullet proof, but that can be mitigated. Mullvad is a nice middle ground for those who don't see that as worth their time or don't know how. Its good to see they're at the very least trying to keep up appearances.

why would self host be better? Do you have a list of VPS that are better than mullvad?

Re: Infrastructure audit completed by Radically Open Security

#79
post #56

I have PIA paid until December but I'm getting so many captchas with them that I've been seriously considering paying for Mullvad, too. Glad to see people are still happy with them so I can go ahead.

You'll get captchas with any VPN provider these days. Cloudflare is taking over my friend.

Re: Infrastructure audit completed by Radically Open Security

#80

Earlier quoted context omitted.

Is that an option? I've been paying 5 euros a month for a number of years and probably use it for 10 minutes a month, on average. I would love to just plunk down 20 euros and be good for the foreseeable future, if it was a couple cents per minute.

> I would love to just plunk down 20 euros and be good for the foreseeable future Simple, buy the number of gift vouchers on Amazon that meets your budget. There is no limit on the number of gift vouchers you can apply to a single account.

I just send them enough cash for a year at a time. No issues yet. I suppose there is a chance someone grabs it out of the mail but I'm willing to risk it.
Post reply on HN