Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

111–120 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#111
post #95

Earlier quoted context omitted.

You can't trust anything you have not built, incl. your laptop, keyboard, mouse, phone, car, even your teabag (what happens if they're randomly drugging your tea to test some pathogens, with a request from your government). Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible. So, the hole has no bottom.

To achieve true privacy, first you must create the universe.

Looking for Universe SDK in case you have a link

Re: Infrastructure audit completed by Radically Open Security

#112
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

Yup. As a Cuban, sometimes it is annoying and sometimes go beyond that. Some cloud providers are totally off limits for us, some are fine with us (the minority and less known), some let us use some services but no others, some even have valid OFAC licenses but still deny access (because ACL complexities, I suppose)... it's all over the place. That's why I'm 95% of the time on crappy VPNs both to escape/evade US sanct…

> Anyway, and sadly, the sanctions affect "regular" people like me the most. The ruling elite? Not at all.

This confirms my secondhand knowledge of financial sanctions. It seems to universally be this way and makes me wonder why we still tout them as if they were effective. They sure don’t seem to be.

Re: Infrastructure audit completed by Radically Open Security

#113
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

Yup. As a Cuban, sometimes it is annoying and sometimes go beyond that. Some cloud providers are totally off limits for us, some are fine with us (the minority and less known), some let us use some services but no others, some even have valid OFAC licenses but still deny access (because ACL complexities, I suppose)... it's all over the place. That's why I'm 95% of the time on crappy VPNs both to escape/evade US sanct…

Funny how everyone talks about the Chinese "great firewall" that blocks access towards some western platforms from China, and no one talks about "USA great firewall" that blocks Cuban citizen from acceding to a lot of services

Re: Infrastructure audit completed by Radically Open Security

#114
post #93

Given that it's in the West I still think it's probably NSA compromised, but I'm not nearly important enough for the government to blow their cover about.

That's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's. If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.

> their total budget is a fraction of Big Tech's

The NSA was getting $10.5bn to spend in 2013[0]. I can only imagine it's gone up since then year on year. That's not a bad fraction when your whole goal is signals intelligence.

[0] https://www.washingtonpost.com/world/national-security/black...

Re: Infrastructure audit completed by Radically Open Security

#115
post #90

Then when audit team is gone, they enable user logging. I think thats a possibility in every provider. IMO based on the transparency they handle police requests to get access emails, I will keep using protonvpn.

Source? They've always been logless. I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0]. [0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

And how does Mullvad deals with court orders?

I guess it's handled by this finding in the audit:

“VPN servers accept remote logins from administrators, who technically have the ability to tap into production users' VPN traffic”

Re: Infrastructure audit completed by Radically Open Security

#116

Sadly I can easily imagine a future where mullvad suffers because big tech simply rangebans all their datacenters (already happens to some degree between cloudflare and individual admins - people are seemingly even banned from using chatgpt if they connect over it, or at least it's involved) and you need the shady residential proxies to actually be able to connect/scrape anything. A self hosted VPS may also work if t…

[deleted]

Re: Infrastructure audit completed by Radically Open Security

#117
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

The discontinuation of port forwarding forced me to leave which is unfortunate because they are excellent.

Re: Infrastructure audit completed by Radically Open Security

#118
post #93

Given that it's in the West I still think it's probably NSA compromised, but I'm not nearly important enough for the government to blow their cover about.

That's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's. If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.

Are you familiar with PRISM or the information Edward Snowden disclosed? The NSA doesn't need "magical" knowledge from the future, they have back doors and exploits in hardware, data collection methods directly arranged with ISPs and FAANGs, and free legal reign. The "best people" at FAANGs readily cooperated with the NSA and FBI, doing everything they could to assist them. If you've never looked into PRISM, I highly recommend going down the rabbit hole.

https://en.wikipedia.org/wiki/PRISM?wprov=sfti1

Re: Infrastructure audit completed by Radically Open Security

#119

Earlier quoted context omitted.

This isn’t true, Mullvad completely disabled port forwarding earlier this year. See: https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...

I’m confused, the blog post backs up what you say but I can still set custom ports within my account page… And I’m currently running a service that needs to advertise out on a port to work from Mullvad.

Is it a torrent client, by any chance? Those can still work without port forwarding, if the swarm member you're sharing data with (regardless of direction) has an open port on their side.

Try creating a new torrent with some random file, seeding it from a Mullvad device and downloading it from a different Mullvad device. That should only work if you have port forwarding set up (or if you're not actually going through Mullvad - you will see that by the peer IP in the torrent client).

Re: Infrastructure audit completed by Radically Open Security

#120
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

What caused you to pass on that opportunity?
Post reply on HN