Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

81–90 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#81
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

They still support opening up ports, it’s just randomized instead of dedicated like uPnP.

This isn’t true, Mullvad completely disabled port forwarding earlier this year. See: https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...

Re: Infrastructure audit completed by Radically Open Security

#82
post #61
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

Sidenote: I know a bunch of people from Crimea and many things we take for granted are surprisingly complex for them. People from Cuba or Iran at least have the certainty of which country they are in.

Crimea is in Ukraine.

Re: Infrastructure audit completed by Radically Open Security

#83

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

Always critics but never providing a viable alternative. So please tell us your model, yank the cable out of the wall and pitch your phone in the lake? I'm mostly concerned about advertisers, corps, and my ISP. I know that in my country (the USA) that if they want something out of me they'll take me to a back room and beat it out of me, so generally I don't do illegal stuff.

Re: Infrastructure audit completed by Radically Open Security

#84

Up front, I believe Mullvad is the best commercial VPN solution and is doing a great job at making good privacy more accessible. However, a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet. I would like to remind people that VPNs only really protect you against two things: your ISP and the endpoint. And that's assuming that your ISP isn't doing some shady analytic…

>..a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet.

..where?

Re: Infrastructure audit completed by Radically Open Security

#85

any competent opinions on protonvpn vs mullvad vpn?

There is a pretty heavy bias against proton anything here, imo. They are seen as a marketing company is my interpretation of the sentiment.

If you experience something, it's already subjective. No need for the "imo" -escape. Same goes for sentiment. The sentiment is already what you observed, no need to further interprete that. Just share what you see. This is overly careful to a point where it almost lacks any content.

Edit: To make this constructive, you could add why people think so and share a related link or something.

Re: Infrastructure audit completed by Radically Open Security

#86
post #61

Earlier quoted context omitted.

Sidenote: I know a bunch of people from Crimea and many things we take for granted are surprisingly complex for them. People from Cuba or Iran at least have the certainty of which country they are in.

Crimea is in Ukraine.

Yet, if you lived there you would be issued a Russian passport, your official documents would be from the Russian state; your police would be Russian.

And; if you lived in Laos, Cuba, Cambodia or Afganistan: you would currently be taking the opposite stance.

We owe it to ourselves to not permit the affectations of propaganda to convince us that we are consistently right, the truth on the ground is much more complicated.

I certainly believe Crimea is an invaded territory of Ukraine, but I cannot pretend that it's a wise notion to demerit the entire conflict down to "Crimea is in Ukraine".

It does nothing to help the people there, and is completely meaningless in the face of my initial comment: that while I could sell games to Ukrainians, I could not allow them to play from within Crimea... a territory you claim; is Ukraine. The implicit argument you just made is that we have created sanctions against Ukraine itself.

Re: Infrastructure audit completed by Radically Open Security

#87
post #77

Earlier quoted context omitted.

They still support opening up ports, it’s just randomized instead of dedicated like uPnP.

Oh really? Could you elaborate or point me in the direction of more information on this please?

https://mullvad.net/en/account/wireguard-config

In the wireguard config section of their tutorials, there’s a spot to put a custom port - it’s really unclear from the docs but this allows you to expose out a service within the higher limits of the port ranges, and only on dedicated servers.

Really hard to find but they call this “city ports” over global ports because you have to set them up beforehand.

Re: Infrastructure audit completed by Radically Open Security

#88
post #61

Earlier quoted context omitted.

Sidenote: I know a bunch of people from Crimea and many things we take for granted are surprisingly complex for them. People from Cuba or Iran at least have the certainty of which country they are in.

Crimea is in Ukraine.

That's disputed (literally :P)

Re: Infrastructure audit completed by Radically Open Security

#89
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

I'm glad to read this. We considered switching to them earlier this year (couldn't find the budget) and it was still on the table, but this is a deal breaker. If we'd switched I'd have been in the same situation, with a lot of prepaid service I couldn't use as intended.

To be fair, the announcement came with the option of asking for refunds, and I have no reason to doubt them. My few interactions with their support were pretty good.

Re: Infrastructure audit completed by Radically Open Security

#90

Then when audit team is gone, they enable user logging. I think thats a possibility in every provider. IMO based on the transparency they handle police requests to get access emails, I will keep using protonvpn.

Source? They've always been logless.

I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0].

[0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

Post reply on HN