Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

181–190 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#181
post #90

Then when audit team is gone, they enable user logging. I think thats a possibility in every provider. IMO based on the transparency they handle police requests to get access emails, I will keep using protonvpn.

Source? They've always been logless. I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0]. [0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

As any other company operating legally, we have to respect the local legislation, which is what happened in this case. The case also shows that our encryption works as intended - we were not able to share any of the user's data stored encrypted on our servers (email content, attachments, etc.), because we don't have access to it ourselves.

Note also, that the case pertains to Proton Mail, and not Proton VPN. Proton Mail is considered to be a communication service, and in most countries (including Switzerland), communication services are regulated to some extent. The treatment of VPNs is different. There are no Swiss laws compelling us to log IP addresses, personal identifiers, traffic or browsing history, as proven in a 2019 legal case (we were not able to provide the requested information because we don't keep any: https://protonvpn.com/blog/transparency-report/).

Re: Infrastructure audit completed by Radically Open Security

#182

Earlier quoted context omitted.

I’m a network newbie so I have no idea about the importance of this. I have done port forwarding in my router before, mainly so I can access my Plex system outside of my house. I used to setup port forwarding when torrenting but I have realized that I can still get my Linux ISOs without it. I never cared even though I’m a heavy user of their product. When will it start to affect me, or in other words, what use cases…

You'd need that feature if you desired to host an actual service (a webserver for example) behind the VPN

Oh!! That makes a ton of sense now, I feel dumb for not thinking about that since I was just doing some config changes for Docker services running in my home server. I realized I couldn’t access it from another machine because the Dockerfile didn’t have ports forwarded appropriately. Thank you very much!

Re: Infrastructure audit completed by Radically Open Security

#183

Earlier quoted context omitted.

None as solid, no. My needs are fairly specific (exit node in a specific country, torrent-friendly, good speed, not too expensive, not too shady, first-party support for my OS'es, doesn't have to be government-proof), so you'll need to do your own research. For what's worth, I eventually went with Proton VPN, but it's more expensive and gives a used-car-salesman feeling.

> gives a used-car-salesman feeling. I really don't like the aesthetic direction Proton's been taking in the last few years, from top to bottom. I'm finding their mail apps, both in desktop web browser and on mobile, less and less usable. In addition I get this feeling from their design choices as well. I know their mission is to grow enough to challenge predatory providers like gmail, but it makes me wary and makes…

Proton has unfortunately become incredibly bloated over the past few years. Meanwhile ProtonMail doesn't yet support auto-forwarding or (on mobile) email content search.

Re: Infrastructure audit completed by Radically Open Security

#184
post #179
post #148

Earlier quoted context omitted.

I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…

Port forwarding doesn't seem to be a problem for long-established independent VPNs like AirVPN (based in Italy but very ingeniously without exit servers in Italy) or AzireVPN (Swedish; added port forwarding -- all mappings in memory, no static records -- just recently [1]). What makes Mullvad's situation different? Is it a question of margins for high traffic port forwarding users (Mullvad is branching out in browser…

It seems pretty evident why they had to turn it off:

> The manner and extent in which it came to be abused in recent months made it unacceptable for us to continue providing it.

Probably the difference between Mullvad and AirVPN/AzireVPN is how popular the service is, which also usually dictates how popular it is for people to try to abuse it.

Maybe 1% of each service's traffic is abuse, which for AirVPN/AzireVPN is not that much, but on Mullvads scale it becomes a whole nother beast.

Re: Infrastructure audit completed by Radically Open Security

#185

Mullvad is THE ONLY mainstream VPN that doesn't have seriously questionable credibility. Not even Proton VPN is OK - sleuths have figured out that it's just a white-labeled version of NordVPN. I am thankful that Mullvad is doubling down on their commitment to integrity, because there isn't an alternative.

Do you have any sources for the NordVPN claim?

Edit: I just had a look through your post history and you seem to have been claiming this for months, without providing any evidence. Shady.

Re: Infrastructure audit completed by Radically Open Security

#186
post #154

any competent opinions on protonvpn vs mullvad vpn?

Both are fine for vpn performance. However, Mullvad has won me over with their business practices. Mullvad accepts my payment for a month of use at a time, and I manually renew it (after I receive a reminder) each month. If I don’t need a vpn the following month, I don’t pay for another month. I also find Mullvad works a bit better on Linux too. I just got hit with a 2 year auto renewal charge from proton for my old…

Please note that Proton subscriptions are automatically renewed, as well as that if you are using multiple services under the same Proton account, the access to all of them will be suspended if an invoice has not been cleared for longer than 14 days: https://proton.me/support/delinquency. We cannot downgrade a subscription for you automatically, as only you can choose what data should be removed from your Proton account - it is impossible to downgrade the account to a Free subscription if it exceeds the limits of the Free subscription.

However, as soon as you downgrade the account yourself and cancel the subscription, we will automatically refund you for the unused time. The refund is automatically issued in the form of Proton credits which you can use for a Proton paid service in the future, or you can request the credits to be refunded back to your original payment method by contacting our support team: https://proton.me/support/contact.

Re: Infrastructure audit completed by Radically Open Security

#187
post #148
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…

This is a very articulately worded and elegant response.

Re: Infrastructure audit completed by Radically Open Security

#188
post #95

Earlier quoted context omitted.

You can't trust anything you have not built, incl. your laptop, keyboard, mouse, phone, car, even your teabag (what happens if they're randomly drugging your tea to test some pathogens, with a request from your government). Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible. So, the hole has no bottom.

To achieve true privacy, first you must create the universe.

The universe you create is inside the universe you inhabit in, which has no privacy, so the universe you create also has no privacy.

Re: Infrastructure audit completed by Radically Open Security

#189

Mullvad is THE ONLY mainstream VPN that doesn't have seriously questionable credibility. Not even Proton VPN is OK - sleuths have figured out that it's just a white-labeled version of NordVPN. I am thankful that Mullvad is doubling down on their commitment to integrity, because there isn't an alternative.

Do you have any sources for the NordVPN claim? Edit: I just had a look through your post history and you seem to have been claiming this for months, without providing any evidence. Shady.

>Do you have any sources for the NordVPN claim?

The trail is a rabbithole, and you might not be personally satisfied with the standard of evidence. Here is a start for you: https://news.ycombinator.com/item?id=23571653

Note in the link above [1] doesnt work anymore since Nord actually removed the product page for their white label product, but it does exist and you can see it in the Products dropdown as NordWL.

And since the link to [2] in what I linked above is broken, here is the archived version: https://archive.is/iZ2l2

Re: Infrastructure audit completed by Radically Open Security

#190

Mullvad is THE ONLY mainstream VPN that doesn't have seriously questionable credibility. Not even Proton VPN is OK - sleuths have figured out that it's just a white-labeled version of NordVPN. I am thankful that Mullvad is doubling down on their commitment to integrity, because there isn't an alternative.

Ick. Do you have a source?
Post reply on HN