I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…
I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…
Infrastructure audit completed by Radically Open Security
151–160 of 290 posts
Re: Infrastructure audit completed by Radically Open Security
#152Earlier quoted context omitted.
Have you found a replacement? I did some light investigation but nothing really felt as solid as Mullvad so I haven't jumped ship yet.
Not that person but I've spinned a 1984 instance paid with bitcoin without KYC. Then setup nat+rdr rules that foward to my service through a wireguard tunnel.
Re: Infrastructure audit completed by Radically Open Security
#153Then when audit team is gone, they enable user logging. I think thats a possibility in every provider. IMO based on the transparency they handle police requests to get access emails, I will keep using protonvpn.
Source? They've always been logless. I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0]. [0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...
They literally had no choice, it was a court order.
Re: Infrastructure audit completed by Radically Open Security
#154any competent opinions on protonvpn vs mullvad vpn?
Mullvad accepts my payment for a month of use at a time, and I manually renew it (after I receive a reminder) each month. If I don’t need a vpn the following month, I don’t pay for another month. I also find Mullvad works a bit better on Linux too.
I just got hit with a 2 year auto renewal charge from proton for my old proton account (email, storage, vpn) for roughly $200 with no email reminder. I thought I had cancelled the auto renewal, but I apparently hadn’t. When I went to cancel it after receiving the charge, the process was full of dark patterns and offers to continue my service, ending with the inability downgrade because it required me to manually delete emails for 30 minutes to free up storage to downgrade to the free account.
It feels like proton has shifted their focus to metrics and profit growth over user experience while Mullvad simply provides a great product with no trickery.
Re: Infrastructure audit completed by Radically Open Security
#155Earlier quoted context omitted.
[flagged]
Are you saying these passports can’t be used for travel? If they weren’t, then why would anyone bother going to get one?
Practically they are required for many domestic tasks, and Russia won't let you leave the region with a real passport so you need one to get out. The European Union has emphasized to its member states that possession of one of these "passports" should also expedite the issuance of a humanitarian/refugee passport.
Re: Infrastructure audit completed by Radically Open Security
#156I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…
I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…
I really hope you guys stick around, Mullvad has exactly the posture that we need from security services.
Re: Infrastructure audit completed by Radically Open Security
#157That being said, I wonder why we arent hearing about any cases involving them and cybercrime. Letter soup agency smear campaigns or actual cybercrime.
They operate totally in the clear as opposed to Tor and other overlay networks, but unlike with Tor, there are no "opinion articles" or biased news articles slamming them as pedophile enablers.
I just find this odd. /Paranoid schizo mode off
Re: Infrastructure audit completed by Radically Open Security
#158Then when audit team is gone, they enable user logging. I think thats a possibility in every provider. IMO based on the transparency they handle police requests to get access emails, I will keep using protonvpn.
Source? They've always been logless. I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0]. [0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...
Re: Infrastructure audit completed by Radically Open Security
#159Thought experiment: design an architecture that passes this audit scope as written that allows for logging of user activity. I can think of at least one.
Thought experiment: build your own VPN company that doesn't log anything and try to convince people like you that you don't do any logging
I don't know if they are logging or not. They say they aren't. The audit says they didn't see evidence that they are.
It's impossible to prove a negative.
Re: Infrastructure audit completed by Radically Open Security
#160Earlier quoted context omitted.
I don't understand this area well enough, I think. Doesn't a VPN encrypt the routing information that tells the packet where to ultimately end up? I.e. my ISP can see the traffic going to the VPN, but can't look inside it, and can't see where it goes from there?
Correct, but the destination ISP chain (and of course the destination service itself) can equally see the traffic coming from the VPN, and if you have packet metadata (precise timing and packet sizes) from two sources on either side of the VPN, it is trivial to correlate those two streams.