Earlier quoted context omitted.
You can't trust anything you have not built, incl. your laptop, keyboard, mouse, phone, car, even your teabag (what happens if they're randomly drugging your tea to test some pathogens, with a request from your government). Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible. So, the hole has no bottom.
To achieve true privacy, first you must create the universe.
Infrastructure audit completed by Radically Open Security
111–120 of 290 posts
Re: Infrastructure audit completed by Radically Open Security
#112My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…
Yup. As a Cuban, sometimes it is annoying and sometimes go beyond that. Some cloud providers are totally off limits for us, some are fine with us (the minority and less known), some let us use some services but no others, some even have valid OFAC licenses but still deny access (because ACL complexities, I suppose)... it's all over the place. That's why I'm 95% of the time on crappy VPNs both to escape/evade US sanct…
This confirms my secondhand knowledge of financial sanctions. It seems to universally be this way and makes me wonder why we still tout them as if they were effective. They sure don’t seem to be.
Re: Infrastructure audit completed by Radically Open Security
#113My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…
Yup. As a Cuban, sometimes it is annoying and sometimes go beyond that. Some cloud providers are totally off limits for us, some are fine with us (the minority and less known), some let us use some services but no others, some even have valid OFAC licenses but still deny access (because ACL complexities, I suppose)... it's all over the place. That's why I'm 95% of the time on crappy VPNs both to escape/evade US sanct…
Re: Infrastructure audit completed by Radically Open Security
#114Given that it's in the West I still think it's probably NSA compromised, but I'm not nearly important enough for the government to blow their cover about.
That's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's. If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.
The NSA was getting $10.5bn to spend in 2013[0]. I can only imagine it's gone up since then year on year. That's not a bad fraction when your whole goal is signals intelligence.
[0] https://www.washingtonpost.com/world/national-security/black...
Re: Infrastructure audit completed by Radically Open Security
#115Then when audit team is gone, they enable user logging. I think thats a possibility in every provider. IMO based on the transparency they handle police requests to get access emails, I will keep using protonvpn.
Source? They've always been logless. I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0]. [0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...
I guess it's handled by this finding in the audit:
“VPN servers accept remote logins from administrators, who technically have the ability to tap into production users' VPN traffic”
Re: Infrastructure audit completed by Radically Open Security
#116Sadly I can easily imagine a future where mullvad suffers because big tech simply rangebans all their datacenters (already happens to some degree between cloudflare and individual admins - people are seemingly even banned from using chatgpt if they connect over it, or at least it's involved) and you need the shady residential proxies to actually be able to connect/scrape anything. A self hosted VPS may also work if t…
Re: Infrastructure audit completed by Radically Open Security
#117I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…
Re: Infrastructure audit completed by Radically Open Security
#118Given that it's in the West I still think it's probably NSA compromised, but I'm not nearly important enough for the government to blow their cover about.
That's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's. If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.
Re: Infrastructure audit completed by Radically Open Security
#119Earlier quoted context omitted.
This isn’t true, Mullvad completely disabled port forwarding earlier this year. See: https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...
I’m confused, the blog post backs up what you say but I can still set custom ports within my account page… And I’m currently running a service that needs to advertise out on a port to work from Mullvad.
Try creating a new torrent with some random file, seeding it from a Mullvad device and downloading it from a different Mullvad device. That should only work if you have port forwarding set up (or if you're not actually going through Mullvad - you will see that by the peer IP in the torrent client).
Re: Infrastructure audit completed by Radically Open Security
#120My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…