I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…
I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…
Infrastructure audit completed by Radically Open Security
161–170 of 290 posts
Re: Infrastructure audit completed by Radically Open Security
#162Earlier quoted context omitted.
> that's assuming that your ISP isn't doing some shady analytics Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?
Why would they even do so ? Large ISPs are public, so this activity would appear as extra revenue (if they sell traffic data) in their financial reports and annual reports. The most likely is that ISPs are just respecting the local laws, and doing the minimum retention as required by the law (because more data storage = more costs), and that their actual fear is that someone leaks this data and causes reputation dama…
Ehh, not really. China Telecom for example is 70% owned by the State. You aren't going to be able to buy shares in Parsnet.
Re: Infrastructure audit completed by Radically Open Security
#163Earlier quoted context omitted.
To achieve true privacy, first you must create the universe.
Looking for Universe SDK in case you have a link
Re: Infrastructure audit completed by Radically Open Security
#164any competent opinions on protonvpn vs mullvad vpn?
Re: Infrastructure audit completed by Radically Open Security
#165Earlier quoted context omitted.
I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…
What sort of abuses you have encountered when dealing with port forwarding? Was it DMCA'd content hosting or were there other major issues with it? Also how does other VPNs that offer port forwarding (like Proton) function against those sort of abuses?
[1]: https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...
Re: Infrastructure audit completed by Radically Open Security
#166I switched to Mullvad after teh last article i read here on HN about how they didn't log and couldn't offer logs to the authorities. I don't have the link but I was impressed and these audits are further proof that that decision was correct.
> I switched to Mullvad after teh last article i read here on HN about how they didn't log and couldn't offer logs to the authorities It should also be pointed out that OVPN[1] is an option as well. They were taken to court and won[2], so they demonstrated above all reasonable doubt that OVPN no-logging means no-logging. See the link for the detail, but I quote: "the Rights Alliance and their security experts have no…
Re: Infrastructure audit completed by Radically Open Security
#167I am thankful that Mullvad is doubling down on their commitment to integrity, because there isn't an alternative.
Re: Infrastructure audit completed by Radically Open Security
#168Earlier quoted context omitted.
Thought experiment: build your own VPN company that doesn't log anything and try to convince people like you that you don't do any logging
If you don't do any logging and don't want to know what your users are doing - it means that you won't have to deal with the cops as much. And there won't be any risk of those logs getting leaked or stolen . Unless you're de-facto part of the government like Google and Microsoft - I see no good reason to log anything more than what's legally required.
Re: Infrastructure audit completed by Radically Open Security
#169Earlier quoted context omitted.
Yet, if you lived there you would be issued a Russian passport, your official documents would be from the Russian state; your police would be Russian. And; if you lived in Laos, Cuba, Cambodia or Afganistan: you would currently be taking the opposite stance. We owe it to ourselves to not permit the affectations of propaganda to convince us that we are consistently right, the truth on the ground is much more complicat…
[flagged]
Re: Infrastructure audit completed by Radically Open Security
#170Earlier quoted context omitted.
Crimea is in Ukraine.
Yet, if you lived there you would be issued a Russian passport, your official documents would be from the Russian state; your police would be Russian. And; if you lived in Laos, Cuba, Cambodia or Afganistan: you would currently be taking the opposite stance. We owe it to ourselves to not permit the affectations of propaganda to convince us that we are consistently right, the truth on the ground is much more complicat…
And, most likely, your personal allegiance would be Russian.