You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…
Always critics but never providing a viable alternative. So please tell us your model, yank the cable out of the wall and pitch your phone in the lake? I'm mostly concerned about advertisers, corps, and my ISP. I know that in my country (the USA) that if they want something out of me they'll take me to a back room and beat it out of me, so generally I don't do illegal stuff.
Infrastructure audit completed by Radically Open Security
201–210 of 290 posts
Re: Infrastructure audit completed by Radically Open Security
#202You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…
VPNs are for escaping private adtech firms, not governments. I don't know where you got this impression from.
this attracts people that want a subpoena to yield nothing
Re: Infrastructure audit completed by Radically Open Security
#203Earlier quoted context omitted.
I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…
Thanks for the reply. I'm sorry my negative comment got to first spot on what should have been a positive post. I understand why the decision was made, and I think I'd have done the same. I really hope you guys stick around, Mullvad has exactly the posture that we need from security services.
Re: Infrastructure audit completed by Radically Open Security
#204Earlier quoted context omitted.
What sort of abuses you have encountered when dealing with port forwarding? Was it DMCA'd content hosting or were there other major issues with it? Also how does other VPNs that offer port forwarding (like Proton) function against those sort of abuses?
VPN port forwarding is, by and large, used for BitTorrent because you can't seed without it. VPNs are used for BitTorrent in general because it's well-known that IPs participating in BitTorrent are monitored and logged by anyone who wants to[0]. I bet it's at least 100 BitTorrent users for every 1 user using port forwarding for any other purpose. [0] https://iknowwhatyoudownload.com/
So you can still seed, it just won't be as usable.
Re: Infrastructure audit completed by Radically Open Security
#205Earlier quoted context omitted.
That's honestly a great idea for an alternative to newsletters... it would be nice if there was better first-party RSS support (what about in the email client?) since I don't think any OSs have it, because right now that would probably confuse most customers
The likelihood of being confused by rss among mullvad customers can't be very high.
I wish RSS had more surface area with general computer users, but I reckon even being called RSS makes it unlikely. Folks in tech often forget how intimidating opaque names can be for nontechnical users.
Re: Infrastructure audit completed by Radically Open Security
#206any competent opinions on protonvpn vs mullvad vpn?
Mullvad is THE ONLY mainstream VPN that doesn't have seriously questionable credibility. Proton VPN is very questionable - sleuths have figured out that it's just a white-labeled version of NordVPN. But the trail is a rabbithole, and you might not be personally satisfied with the standard of evidence. Here is a start for you: https://news.ycombinator.com/item?id=23571653 And since the link to [2] in what I linked abo…
The only piece of evidence in your linked comment is the now defunct blog post: https://web.archive.org/web/20200629163107/https://vpnscam.c...
In addition to reading like it was written by an angry 12 year old, it makes some enormous logical leaps. The facts given are that Proton has an official legal entity in Lithuania called PROTONVPN LT, UAB, and another company called Tesonet shared Lithuanian offices and apparently some business services with them. The article claims that Tesonet is a "data mining company" based on the following evidence:
> Tesonet has its hands in “Machine Learning Solution, cybersecurity, and collection of business intelligence data” in efforts to create algorithms, that best suit their client business needs. If you read their about page, the company openly states it employs many different technologies to structure data, which is run on various services like MySQL, Anisble, collectd, StatsD, ElasticSearch, Grafana, Influx DB, Python, and Couchbase.
> ALL of these names rely on HEAVY USER INFORMATION, which makes sense, considering that Tesonet is a DATA MINING company. Now, let us not forget that Lithuania itself is a NATO member that regularly holds NAZI marches.
Let's just say that I'm not immediately convinced that Tesonet is in the business of selling user data.
The article also claims that in one online Lithuanian business services directory, the CEO of Tesonet was listed as the head of PROTONVPN LT, UAB. I have no idea of the legitimacy of this claim, but it stretches plausibility to claim that Proton is secretly not a Swiss company and secretly has a Lithuanian data mining company CEO as its head.
The article then goes on to make some completely unsupported allegations: "the real question is not whether ProtonVPN is working with Tesonet, but if the provider is owned by the data mining company" and "Under the name of a FREE VPN service, they’ve been collecting USER DATA all along."
Furthermore, the original source of most of this information actually comes from a Hacker News comment. The article links to a comment by the head of Private Internet Access! https://news.ycombinator.com/item?id=17258203
Unfortunately this gives the game away, because the comment is "retracted and removed by author's request". Dang comments:
> In addition to the redacting the above comment, we deleted several comments below by request of their authors. My understanding is that the dispute has been resolved and that the allegations are retracted.
In other words, it appears to me that the true source of these rumors has retracted them and no longer believes that Proton has the claimed ties to Tesonet.
Ironically, as a result of looking into this, I feel slightly more confident about ProtonVPN than I did previously.
Edited to add: you're also stretching even the blog post's unsupported allegations in your comment, when you say that ProtonVPN is "white-labeled" Nord. The article makes the unsupported insinuation that ProtonVPN and Nord are both owned by Tesonet, but this is different from the claim that ProtonVPN is just Nord repackaged as a different product, as you claim here.
Re: Infrastructure audit completed by Radically Open Security
#207Re: Infrastructure audit completed by Radically Open Security
#208It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convin…
I believe it is relevant to the threat model of an attacker gaining (partial) access to a production server (eg no accidental logging), not to the threat model of mullvad deploying malicious code.
I feel like this is a meaningful audit but would have liked if they had stated this more explicitly
Re: Infrastructure audit completed by Radically Open Security
#209Earlier quoted context omitted.
if you want privacy on the internet you have options. VPNs give you privacy from your local network and ISP and a little bit from the destination service, and that's it. there are options to have privacy from additional kinds of parties. i2p, tor. whonix distribution of linux, tails…
What if your VPN is the true adversary here? Edit: Also, questioning trustworthiness of VPNs and them putting them forward as a solution is... a bit unorthodox.
They're not. Spectrum is my true adversary. My VPN may also be an adversary but that's a possibility, whereas Spectrum is a certainty.
Re: Infrastructure audit completed by Radically Open Security
#210I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…
I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…