Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

221–230 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#221
post #135

Earlier quoted context omitted.

> their total budget is a fraction of Big Tech's The NSA was getting $10.5bn to spend in 2013[0]. I can only imagine it's gone up since then year on year. That's not a bad fraction when your whole goal is signals intelligence. [0] https://www.washingtonpost.com/world/national-security/black...

Volkswagen's research budget was $21 billion in 2022. $10.5bn is nothing in the big picture, and certainly not enough to "control the world" or whatever grand claims are commonly made about the NSA.

Do you think Volkswagen could compromise or secretly own a VPN service?

You're the one making grand claims about the NSA controlling the world. It's a lot easier to argue with claims you made up.

Re: Infrastructure audit completed by Radically Open Security

#222

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

Bro, you’re too simple. Are you even printing your own chip wafers? Do you ever key your passwords outside places where you have total physical control? On that note, do you let your love person stay over for the night (have physical access to your flat)? Your incompetent and flabby security posture makes me want to puke. At the very least, admit that your security posture is „typical educated HN reader“ and you’re n…

Yes, realizing that you can't trust the ownership of a company to stay consistent for eternity is basically like thinking your mate is working for the government to steal your passwords.

What investment do you have in people trusting VPN providers that would cause you to make an argument like that? I bet none, it's just a bad instinct.

Re: Infrastructure audit completed by Radically Open Security

#223

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

Bro, you’re too simple. Are you even printing your own chip wafers? Do you ever key your passwords outside places where you have total physical control? On that note, do you let your love person stay over for the night (have physical access to your flat)? Your incompetent and flabby security posture makes me want to puke. At the very least, admit that your security posture is „typical educated HN reader“ and you’re n…

i2p, tor. whonix distribution of linux, tails… but ok

I didnt expect the sarcastic tone of responses but I also dont understand why people act like sports team fans of VPN providers. there are other solution, easily accessible, that do more than VPNs can do, depending on your threat model

a VPN user that supposedly just wants to avoid adtech tracking doesnt need annual audits about how little data one VPN stores over the other

Re: Infrastructure audit completed by Radically Open Security

#224

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

You can't trust anything you have not built, incl. your laptop, keyboard, mouse, phone, car, even your teabag (what happens if they're randomly drugging your tea to test some pathogens, with a request from your government). Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible. So, the hole has no bottom.

You're right. We're actually wasting our time ever thinking about our security or privacy, or taking any measures to protect it. You've convinced me that some security is an illusion, and that the real answer is trust.

Re: Infrastructure audit completed by Radically Open Security

#225
post #63
post #26

Earlier quoted context omitted.

Yup - there's no "multi". You either live in a country that's aligned with the USA. Or you live in some sort of authoritarian hellhole. There's no democratic and prosperous country that isn't aligned with the USA somehow. Russia had the chance to become a country like that in the 90s, but they chose to have another tsar instead.

At some point, we thought it would be the BRICS. All of them have moved away from that in the last decade.

Brazil - high crime and corruption, but at least there is some democracy Russia - totalitarian regime with no democracy and no rule of law. India - lots of poverty and corruption, but at least there is some democracy China - authoritarian regime with no democracy whatsoever. South Africa - poverty and corruption.

Not very great choices. Also only Russia and China would be safe for people like Snowden or Assange.

Re: Infrastructure audit completed by Radically Open Security

#226
post #99

Earlier quoted context omitted.

Have you found a replacement? I did some light investigation but nothing really felt as solid as Mullvad so I haven't jumped ship yet.

Not that person but I've spinned a 1984 instance paid with bitcoin without KYC. Then setup nat+rdr rules that foward to my service through a wireguard tunnel.

Forgive my ignorance, but what’s a “1984 instance”? (Google could not help me.) Thanks!

Re: Infrastructure audit completed by Radically Open Security

#227

Earlier quoted context omitted.

if you want privacy on the internet you have options. VPNs give you privacy from your local network and ISP and a little bit from the destination service, and that's it. there are options to have privacy from additional kinds of parties. i2p, tor. whonix distribution of linux, tails…

What if your VPN is the true adversary here? Edit: Also, questioning trustworthiness of VPNs and them putting them forward as a solution is... a bit unorthodox.

This thread is reacting to someone pointing out the weaknesses in VPNs. It's the people who were triggered by that to defend VPN usage against the pointing out of this reality, and to imply everyone aware of the drawbacks are paranoiacs; it's those people who have committed themselves in advance to a solution.

Re: Infrastructure audit completed by Radically Open Security

#228

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

I'm not worried about my government as it currently stands. I'm squicked out by the fact that every single private company I interact with seems to be falling over themselves to collect as much data about me as possible, and resell it to anyone who will pay. There are no protections against this in the US. I am worried, at least a little bit, about an authoritarian government coming to power and basically weaponizing…

The Nazis used the census to find Jews. A huge amount of people had no idea that they had matrilineal Jewish descent until the Nazis and IBM told them.

https://en.wikipedia.org/wiki/IBM_and_the_Holocaust

Re: Infrastructure audit completed by Radically Open Security

#229
post #86

Earlier quoted context omitted.

Yet, if you lived there you would be issued a Russian passport, your official documents would be from the Russian state; your police would be Russian. And; if you lived in Laos, Cuba, Cambodia or Afganistan: you would currently be taking the opposite stance. We owe it to ourselves to not permit the affectations of propaganda to convince us that we are consistently right, the truth on the ground is much more complicat…

[flagged]

> And then you are trying to legitimise the Russian invasion.

In this conflict, I agree with you 100% - fuck Putin.

On the other hand, many international organisations don't recognise Taiwan as a country, whereas in my mind it's clearly a country for obvious reasons. So I don't consider international recognition to be the be-all-and-end-all of which borders lie where.

Re: Infrastructure audit completed by Radically Open Security

#230

As an occasional mullvad customer im glad to hear. That being said, I wonder why we arent hearing about any cases involving them and cybercrime. Letter soup agency smear campaigns or actual cybercrime. They operate totally in the clear as opposed to Tor and other overlay networks, but unlike with Tor, there are no "opinion articles" or biased news articles slamming them as pedophile enablers. I just find this odd. /P…

If the VPN is hosted in America or Europe it's without a doubt logging, otherwise they would not be able to operate legally. Full Spectrum Awareness logically means VPNs should be a prime targets for the surveillance state that we're in.
Post reply on HN