Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

151–160 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#151
post #148
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…

What sort of abuses you have encountered when dealing with port forwarding? Was it DMCA'd content hosting or were there other major issues with it? Also how does other VPNs that offer port forwarding (like Proton) function against those sort of abuses?

Re: Infrastructure audit completed by Radically Open Security

#152
post #99

Earlier quoted context omitted.

Have you found a replacement? I did some light investigation but nothing really felt as solid as Mullvad so I haven't jumped ship yet.

Not that person but I've spinned a 1984 instance paid with bitcoin without KYC. Then setup nat+rdr rules that foward to my service through a wireguard tunnel.

This might be the way I go. Thanks.

Re: Infrastructure audit completed by Radically Open Security

#153
post #90

Then when audit team is gone, they enable user logging. I think thats a possibility in every provider. IMO based on the transparency they handle police requests to get access emails, I will keep using protonvpn.

Source? They've always been logless. I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0]. [0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

>maliciously

They literally had no choice, it was a court order.

Re: Infrastructure audit completed by Radically Open Security

#154

any competent opinions on protonvpn vs mullvad vpn?

Both are fine for vpn performance. However, Mullvad has won me over with their business practices.

Mullvad accepts my payment for a month of use at a time, and I manually renew it (after I receive a reminder) each month. If I don’t need a vpn the following month, I don’t pay for another month. I also find Mullvad works a bit better on Linux too.

I just got hit with a 2 year auto renewal charge from proton for my old proton account (email, storage, vpn) for roughly $200 with no email reminder. I thought I had cancelled the auto renewal, but I apparently hadn’t. When I went to cancel it after receiving the charge, the process was full of dark patterns and offers to continue my service, ending with the inability downgrade because it required me to manually delete emails for 30 minutes to free up storage to downgrade to the free account.

It feels like proton has shifted their focus to metrics and profit growth over user experience while Mullvad simply provides a great product with no trickery.

Re: Infrastructure audit completed by Radically Open Security

#155

Earlier quoted context omitted.

[flagged]

Are you saying these passports can’t be used for travel? If they weren’t, then why would anyone bother going to get one?

The Crimean issued passports are accepted only by Russia and other occupied areas such as South Ossetia and Abkhazia.

Practically they are required for many domestic tasks, and Russia won't let you leave the region with a real passport so you need one to get out. The European Union has emphasized to its member states that possession of one of these "passports" should also expedite the issuance of a humanitarian/refugee passport.

Re: Infrastructure audit completed by Radically Open Security

#156
post #148
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…

Thanks for the reply. I'm sorry my negative comment got to first spot on what should have been a positive post. I understand why the decision was made, and I think I'd have done the same.

I really hope you guys stick around, Mullvad has exactly the posture that we need from security services.

Re: Infrastructure audit completed by Radically Open Security

#157
As an occasional mullvad customer im glad to hear.

That being said, I wonder why we arent hearing about any cases involving them and cybercrime. Letter soup agency smear campaigns or actual cybercrime.

They operate totally in the clear as opposed to Tor and other overlay networks, but unlike with Tor, there are no "opinion articles" or biased news articles slamming them as pedophile enablers.

I just find this odd. /Paranoid schizo mode off

Re: Infrastructure audit completed by Radically Open Security

#158
post #90

Then when audit team is gone, they enable user logging. I think thats a possibility in every provider. IMO based on the transparency they handle police requests to get access emails, I will keep using protonvpn.

Source? They've always been logless. I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0]. [0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

“The Swiss legal system, while not perfect, does provide a number of checks and balances, and it’s worth noting that even in this case, approval from three authorities in two countries was required, and that’s a fairly high bar which prevents most (but not all) abuse of the system.”

Re: Infrastructure audit completed by Radically Open Security

#159
post #3

Thought experiment: design an architecture that passes this audit scope as written that allows for logging of user activity. I can think of at least one.

Thought experiment: build your own VPN company that doesn't log anything and try to convince people like you that you don't do any logging

I think you misunderstood me. You seem to take my comment as input to an assumption that I think they are logging.

I don't know if they are logging or not. They say they aren't. The audit says they didn't see evidence that they are.

It's impossible to prove a negative.

Re: Infrastructure audit completed by Radically Open Security

#160
post #110

Earlier quoted context omitted.

I don't understand this area well enough, I think. Doesn't a VPN encrypt the routing information that tells the packet where to ultimately end up? I.e. my ISP can see the traffic going to the VPN, but can't look inside it, and can't see where it goes from there?

Correct, but the destination ISP chain (and of course the destination service itself) can equally see the traffic coming from the VPN, and if you have packet metadata (precise timing and packet sizes) from two sources on either side of the VPN, it is trivial to correlate those two streams.

Note that Mullvad's WireGuard settings offer a "multihop" feature, meaning the VPN destination your ISP sees and the VPN endpoint the end service sees differ.
Post reply on HN