Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

231–240 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#231
post #93

Given that it's in the West I still think it's probably NSA compromised, but I'm not nearly important enough for the government to blow their cover about.

That's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's. If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.

> That's tinfoil hat nonsense.

Understand that direct contradiction is not terribly helpful, but this seems important so: no it isn't. (supported by years of public evidence, and also some personal experiences that I can't go into due to ).

Re: Infrastructure audit completed by Radically Open Security

#232
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

I’m a network newbie so I have no idea about the importance of this. I have done port forwarding in my router before, mainly so I can access my Plex system outside of my house. I used to setup port forwarding when torrenting but I have realized that I can still get my Linux ISOs without it. I never cared even though I’m a heavy user of their product. When will it start to affect me, or in other words, what use cases…

Your torrent client probably uses UPnP to have your router selectively open ports to your machine for the duration of the session.

Re: Infrastructure audit completed by Radically Open Security

#233

Earlier quoted context omitted.

Not that person but I've spinned a 1984 instance paid with bitcoin without KYC. Then setup nat+rdr rules that foward to my service through a wireguard tunnel.

Forgive my ignorance, but what’s a “1984 instance”? (Google could not help me.) Thanks!

I googled "1984 vps" and came up with http://1984.hosting/. I have no idea if this is what GP is referring to.

Re: Infrastructure audit completed by Radically Open Security

#234
post #179
post #148

Earlier quoted context omitted.

I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…

Port forwarding doesn't seem to be a problem for long-established independent VPNs like AirVPN (based in Italy but very ingeniously without exit servers in Italy) or AzireVPN (Swedish; added port forwarding -- all mappings in memory, no static records -- just recently [1]). What makes Mullvad's situation different? Is it a question of margins for high traffic port forwarding users (Mullvad is branching out in browser…

I'm sorry we haven't been more clear in our communication.

Our decision to remove port forwarding was not a question of margins - it was a moral and practical decision.

Port forwarding is a feature with many legitimate use cases. This year it became clear that we had become popular for use cases we didn't want to support. Undesirable content and malicious services is a good summary. I'm not privy to more details than that as my main focus is research.

Technology is often a double-edged sword, but thankfully it is often also a net benefit to its users and society in general. Privacy online is exactly that kind of technology. Enabling anyone to host any service anonymously on the open Internet is another matter.

I hope AirVPN and AzireVPN somehow succeed with providing that feature while steering clear of its downsides. That would be awesome.

Nitpick: Mullvad is older than both Air and Azire. :)

Re: Infrastructure audit completed by Radically Open Security

#235
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

What are legitimate use case to use port-forwarding behind a VPN IP? Genuinely curious, I'm not implying anything. The main use-case is hosting something for which you don't want to reveal your IP or circumvent some ISP that block hosting web servers on their residential IPs. I'm sure I'm missing many more use cases.

Re: Infrastructure audit completed by Radically Open Security

#236

As an occasional mullvad customer im glad to hear. That being said, I wonder why we arent hearing about any cases involving them and cybercrime. Letter soup agency smear campaigns or actual cybercrime. They operate totally in the clear as opposed to Tor and other overlay networks, but unlike with Tor, there are no "opinion articles" or biased news articles slamming them as pedophile enablers. I just find this odd. /P…

If the VPN is hosted in America or Europe it's without a doubt logging, otherwise they would not be able to operate legally. Full Spectrum Awareness logically means VPNs should be a prime targets for the surveillance state that we're in.

What law would require an American VPN host to log the activities of their subscribers? CALEA only applies to telecoms and ISPs (legal common carriers), a VPN provider is neither.

Re: Infrastructure audit completed by Radically Open Security

#237
post #115
post #90

Earlier quoted context omitted.

Source? They've always been logless. I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0]. [0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

And how does Mullvad deals with court orders? I guess it's handled by this finding in the audit: “VPN servers accept remote logins from administrators, who technically have the ability to tap into production users' VPN traffic”

Here you go:

https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec...

In short, they immediately and helpfully complied with police... by letting them know they did not store any data about customers whatsoever.

Re: Infrastructure audit completed by Radically Open Security

#238
post #93

Given that it's in the West I still think it's probably NSA compromised, but I'm not nearly important enough for the government to blow their cover about.

That's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's. If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.

It's not about the NSA so much in my view, it's about the west simply most likely going completely along with America as long as it doesn't involve going to war (e.g. Iraq) which could cost them an election. And a number of European countries are clamoring for draconian surveillance themselves.

And the Best People aren't at FAANG. They are at hedge firms.

Re: Infrastructure audit completed by Radically Open Security

#239

It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convin…

Mullvad has been chopping away at system transparency for a little while: https://mullvad.net/en/blog/2019/6/3/system-transparency-fut... -- Effectively, a mechanism by which their servers can perform attestation to their server really being what is says it is.

I think they might have even spun this out into a separate project. With this, you can "trust" Mullvad that what's audited is really what you're using.

Re: Infrastructure audit completed by Radically Open Security

#240

Earlier quoted context omitted.

Note that Mullvad's WireGuard settings offer a "multihop" feature, meaning the VPN destination your ISP sees and the VPN endpoint the end service sees differ.

I'm not sure how that protects you though. ISP sees your traffic going into WG1. They know all of Mulvad's IPs, so isn't it just as easy to correlate that traffic when you exit through WG2? /question from ignorance

Assuming the ISP monitors the entire network graph (your computer, the VPN server's activity, and the end service's server), you wouldn't. At that point, it's game over unless you're using mixnets or something.

If they merely monitor your computer and the end service, the correlation weakens a little with plausible deniability.

The real win is when the ISP adversary is monitoring your computer and the WG servers and NOT the end service. In that case, say they see you go to WG1, and then they see WG1 going to an end service. This is also correlation, and pretty undeniable. But say they see you go to WG1, then they see WG1 go to WG2, and they have no visibility of WG2's traffic. Then the tracking's broken; the footprints run off into the surf.

So multiple hops buy you defense in depth assuming it eventually gets you outside your adversary's monitoring range.

Post reply on HN