Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

91–100 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#91
post #53
post #44

Earlier quoted context omitted.

I doubt that's the better way. How is self-hosting helping with the paranoia vs. using Mullvad? I don't really see how it's more secure to run some software that you haven't audited on a VPS somewhere at a provider you haven't audited. I'd trust a company with resources to run their own hardware, investing into a more secure setup [1] and contributing to more open infrastructure [2] much more than I trust myself to r…

Self-hosting also makes you vulnerable to the network hosting you (not only the hosting server itself, but also the internet transit provider) and of course the website you are visiting, as you are the only user from that source IP (rendering a VPN practically useless).

There may be holes in this but:

1. |Router| -> Wireguard / OpenVPN -> |VPS|

2. |Device| -> Wifi -> |Router|

3. |Device| -> app -> |Mullvad|

= |Device| -> |VPS| -> |Mullvad| -> Internet

Can do various mixing and matching if you have more than one VPS. Again, it rearranges rather than removing the vulnerabilities, and it's pure window dressing against an organised, financed actor.

I've done this as an intellectual challenge more than anything else.

Re: Infrastructure audit completed by Radically Open Security

#92

Earlier quoted context omitted.

They still support opening up ports, it’s just randomized instead of dedicated like uPnP.

This isn’t true, Mullvad completely disabled port forwarding earlier this year. See: https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...

I’m confused, the blog post backs up what you say but I can still set custom ports within my account page… And I’m currently running a service that needs to advertise out on a port to work from Mullvad.

Re: Infrastructure audit completed by Radically Open Security

#93

Given that it's in the West I still think it's probably NSA compromised, but I'm not nearly important enough for the government to blow their cover about.

That's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's.

If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.

Re: Infrastructure audit completed by Radically Open Security

#94
Sadly I can easily imagine a future where mullvad suffers because big tech simply rangebans all their datacenters (already happens to some degree between cloudflare and individual admins - people are seemingly even banned from using chatgpt if they connect over it, or at least it's involved) and you need the shady residential proxies to actually be able to connect/scrape anything.

A self hosted VPS may also work if the company is small enough to avoid the coming BlanketBans, but only time will tell.

Re: Infrastructure audit completed by Radically Open Security

#95

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

You can't trust anything you have not built, incl. your laptop, keyboard, mouse, phone, car, even your teabag (what happens if they're randomly drugging your tea to test some pathogens, with a request from your government). Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible. So, the hole has no bottom.

To achieve true privacy, first you must create the universe.

Re: Infrastructure audit completed by Radically Open Security

#96

Earlier quoted context omitted.

This isn’t true, Mullvad completely disabled port forwarding earlier this year. See: https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...

I’m confused, the blog post backs up what you say but I can still set custom ports within my account page… And I’m currently running a service that needs to advertise out on a port to work from Mullvad.

I don't want to revoke a key to test but I'm pretty sure that just sets the port in the Endpoint part of the WireGuard config file. (the port you use to connect, for if the regular one is blocked). Are you sure your service behind Mullvad is accepting incoming connections?

Re: Infrastructure audit completed by Radically Open Security

#97
post #53

Earlier quoted context omitted.

Self-hosting also makes you vulnerable to the network hosting you (not only the hosting server itself, but also the internet transit provider) and of course the website you are visiting, as you are the only user from that source IP (rendering a VPN practically useless).

There may be holes in this but: 1. |Router| -> Wireguard / OpenVPN -> |VPS| 2. |Device| -> Wifi -> |Router| 3. |Device| -> app -> |Mullvad| = |Device| -> |VPS| -> |Mullvad| -> Internet Can do various mixing and matching if you have more than one VPS. Again, it rearranges rather than removing the vulnerabilities, and it's pure window dressing against an organised, financed actor. I've done this as an intellectual chal…

I do this, mostly for the static IP that isn't linked directly to me and my approximate location, with mullvad exit only for 'sensitive' stuff. The degree of separation is nice even if the breadcrumbs are there. Best if the VPS allows crypto or cash payments.

Re: Infrastructure audit completed by Radically Open Security

#98
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

Yup. As a Cuban, sometimes it is annoying and sometimes go beyond that. Some cloud providers are totally off limits for us, some are fine with us (the minority and less known), some let us use some services but no others, some even have valid OFAC licenses but still deny access (because ACL complexities, I suppose)... it's all over the place. That's why I'm 95% of the time on crappy VPNs both to escape/evade US sanctions and my own country censoring mechanisms.

The thing is, I somewhat understand why the sanctions were placed decades ago, but... is that rationale still valid? Anyway, and sadly, the sanctions affect "regular" people like me the most. The ruling elite? Not at all.

Thank you for your position, BTW!

Re: Infrastructure audit completed by Radically Open Security

#99
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

Have you found a replacement? I did some light investigation but nothing really felt as solid as Mullvad so I haven't jumped ship yet.

Re: Infrastructure audit completed by Radically Open Security

#100

Earlier quoted context omitted.

You can't trust anything you have not built, incl. your laptop, keyboard, mouse, phone, car, even your teabag (what happens if they're randomly drugging your tea to test some pathogens, with a request from your government). Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible. So, the hole has no bottom.

if you want privacy on the internet you have options. VPNs give you privacy from your local network and ISP and a little bit from the destination service, and that's it. there are options to have privacy from additional kinds of parties. i2p, tor. whonix distribution of linux, tails…

> there are options to have privacy from additional kinds of parties.

like ones you pay to use their VPN servers...?

Post reply on HN