Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

121–130 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#121
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

> They don't store any contact information that could be used to warn customers, so my connection mysteriously failed one day

This situation seems avoidable: what if the payment/signup flow had a big loud warning that you need to configure your own polling of an RSS endpoint using a client capable of pinging you?

Re: Infrastructure audit completed by Radically Open Security

#122
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

What caused you to pass on that opportunity?

It was before (or during the beginning of) COVID and it required on-site in Gothenburg.

I was firmly planted in Malmö (3hrs train away) and had just signed to buy an apartment.

Re: Infrastructure audit completed by Radically Open Security

#123
post #115
post #90

Earlier quoted context omitted.

Source? They've always been logless. I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0]. [0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

And how does Mullvad deals with court orders? I guess it's handled by this finding in the audit: “VPN servers accept remote logins from administrators, who technically have the ability to tap into production users' VPN traffic”

If your treat assessment involves this, you're probably best not using a $5 a month VPN.

Re: Infrastructure audit completed by Radically Open Security

#124
post #77

Earlier quoted context omitted.

Oh really? Could you elaborate or point me in the direction of more information on this please?

https://mullvad.net/en/account/wireguard-config In the wireguard config section of their tutorials, there’s a spot to put a custom port - it’s really unclear from the docs but this allows you to expose out a service within the higher limits of the port ranges, and only on dedicated servers. Really hard to find but they call this “city ports” over global ports because you have to set them up beforehand.

The "custom port" option in the config creator just sets the endpoint port to use for Wireguard. It has nothing to do with port forwarding.

Re: Infrastructure audit completed by Radically Open Security

#125
post #86

Earlier quoted context omitted.

Yet, if you lived there you would be issued a Russian passport, your official documents would be from the Russian state; your police would be Russian. And; if you lived in Laos, Cuba, Cambodia or Afganistan: you would currently be taking the opposite stance. We owe it to ourselves to not permit the affectations of propaganda to convince us that we are consistently right, the truth on the ground is much more complicat…

[flagged]

Are you saying these passports can’t be used for travel? If they weren’t, then why would anyone bother going to get one?

Re: Infrastructure audit completed by Radically Open Security

#126

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

Bro, you’re too simple.

Are you even printing your own chip wafers?

Do you ever key your passwords outside places where you have total physical control?

On that note, do you let your love person stay over for the night (have physical access to your flat)?

Your incompetent and flabby security posture makes me want to puke. At the very least, admit that your security posture is „typical educated HN reader“ and you’re not serious, so the rest of us can continue on our business without your mind numbing puerile distractions.

[okay that rant was really just a „holier than thou“ parody about how if you’re going to maintain a security posture that’s more tense than 90% of your peers, at least acknowledge what threat model you espouse and acknowledge that others may have a different one. If you had been like: „is this your threat model? Then why don’t you care about this…“, you would have my upvote not my snark. Even if that weren’t my threat model I would have found that exposition commendable.]

Re: Infrastructure audit completed by Radically Open Security

#127
post #86

Earlier quoted context omitted.

Yet, if you lived there you would be issued a Russian passport, your official documents would be from the Russian state; your police would be Russian. And; if you lived in Laos, Cuba, Cambodia or Afganistan: you would currently be taking the opposite stance. We owe it to ourselves to not permit the affectations of propaganda to convince us that we are consistently right, the truth on the ground is much more complicat…

[flagged]

[deleted]

Re: Infrastructure audit completed by Radically Open Security

#128

Earlier quoted context omitted.

This isn’t true, Mullvad completely disabled port forwarding earlier this year. See: https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...

I’m confused, the blog post backs up what you say but I can still set custom ports within my account page… And I’m currently running a service that needs to advertise out on a port to work from Mullvad.

That custom port on the WireGuard config page is not the place where you'd configure port forwarding; that's not what that is. They had a separate port forwarding page for configuring city ports which is now gone. But you say you have it working. My guess is that you're just misremembering where the configuration is, and that Mullvad hasn't removed existing port forwards yet like they said they would.

Re: Infrastructure audit completed by Radically Open Security

#129
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

I’m a network newbie so I have no idea about the importance of this. I have done port forwarding in my router before, mainly so I can access my Plex system outside of my house. I used to setup port forwarding when torrenting but I have realized that I can still get my Linux ISOs without it. I never cared even though I’m a heavy user of their product. When will it start to affect me, or in other words, what use cases am I locked out of when port forwarding is disabled?

Re: Infrastructure audit completed by Radically Open Security

#130

Earlier quoted context omitted.

Yup. As a Cuban, sometimes it is annoying and sometimes go beyond that. Some cloud providers are totally off limits for us, some are fine with us (the minority and less known), some let us use some services but no others, some even have valid OFAC licenses but still deny access (because ACL complexities, I suppose)... it's all over the place. That's why I'm 95% of the time on crappy VPNs both to escape/evade US sanct…

Funny how everyone talks about the Chinese "great firewall" that blocks access towards some western platforms from China, and no one talks about "USA great firewall" that blocks Cuban citizen from acceding to a lot of services

Probably because they are very different things. It’s not like the US stops Cubans from reading Wikipedia.
Post reply on HN