Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

241–250 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#241
post #234
post #179

Earlier quoted context omitted.

Port forwarding doesn't seem to be a problem for long-established independent VPNs like AirVPN (based in Italy but very ingeniously without exit servers in Italy) or AzireVPN (Swedish; added port forwarding -- all mappings in memory, no static records -- just recently [1]). What makes Mullvad's situation different? Is it a question of margins for high traffic port forwarding users (Mullvad is branching out in browser…

I'm sorry we haven't been more clear in our communication. Our decision to remove port forwarding was not a question of margins - it was a moral and practical decision. Port forwarding is a feature with many legitimate use cases. This year it became clear that we had become popular for use cases we didn't want to support. Undesirable content and malicious services is a good summary. I'm not privy to more details than…

Thank you! That clarifies :) I'm also glad for all the innovations Mullvad has invented/supported/etc in the VPN space -- anonymous account numbers, multi-server SOCKS proxies, Wireguard over TCP, post-quantum Wireguard, stboot, open APIs, the list goes on.

It feels like VPN for apps is very different than a VPN for browsing. While in both cases I want my traffic to be mixed in with a lot of other people's traffic (so service provider dealing with complaints about neighbors is part of the value proposition), browsing use case is tied to IP reputation (so don't want someone to run a Tor exit on the same IP), whereas the app use case is much less IP reputation-sensitive but definitely benefits from port forwarding (e.g. to anonymously run nodes that powers distributed infrastructure like crypto).

I'd definitely pay premium, with longer commitments up front for "this server might be useless for browsing but run all your anonymous crypto nodes behind forwarded ports" type of service. Maybe if port forwarding is active only if you have 6+ months of outstanding service commitment (and you forfeit the balance if your port gets used for C&C or whatnot) is enough of a deterrent. Some VPNs are doing some traffic segregation already, e.g. having dedicated servers for P2P, though nothing exactly like this.

Re: Infrastructure audit completed by Radically Open Security

#242

It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convin…

You're asking Mullvad to give outsiders access to their customer's connections. That's something they've promised to never do.

I work in a bank and wish it worked like that too. "Sorry ECB, sorry SEC, we don't allow auditors access to our customers money". :-) My work would be so much easier! Too bad we can't do it because we'd go to prison.

Re: Infrastructure audit completed by Radically Open Security

#243
post #179
post #148

Earlier quoted context omitted.

I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…

Port forwarding doesn't seem to be a problem for long-established independent VPNs like AirVPN (based in Italy but very ingeniously without exit servers in Italy) or AzireVPN (Swedish; added port forwarding -- all mappings in memory, no static records -- just recently [1]). What makes Mullvad's situation different? Is it a question of margins for high traffic port forwarding users (Mullvad is branching out in browser…

Mullvad is probably the VPN with the longest track record of not keeping logs. I find it likely that the vast majority of people who hosted immoral content using Mullvad's port forwarding feature solely used Mullvad for this purpose because of their reputation. After Mullvad discontinued port forwarding, IVPN (probably the second most trusted VPN provider) came out a month later and announced that they were also discontinuing port forwarding [1]. I think it is likely other VPN providers will follow suit.

According to Mullvads blog [2] the police raid was related to a blackmail attack in Germany.

[1]https://www.ivpn.net/blog/gradual-removal-of-port-forwarding

[2]https://mullvad.net/en/blog/2023/5/2/update-the-swedish-auth...

Re: Infrastructure audit completed by Radically Open Security

#244
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

What are legitimate use case to use port-forwarding behind a VPN IP? Genuinely curious, I'm not implying anything. The main use-case is hosting something for which you don't want to reveal your IP or circumvent some ISP that block hosting web servers on their residential IPs. I'm sure I'm missing many more use cases.

I have been out of the loop for a while on this, but doesn't BitTorrent require you to set up a port forward? Otherwise you can only connect to peers that do, but not other peers that don't.

Re: Infrastructure audit completed by Radically Open Security

#245

Earlier quoted context omitted.

That’s a very broad statement, almost automatically untrue. All countries, all situations, all financial sanctions?

It obviously isn't too broad, because instead of this comment you could have posted a single counterexample to disprove it.

The onus isn’t really on me, I’m not the one making blanket statements.

Re: Infrastructure audit completed by Radically Open Security

#246
post #219

Earlier quoted context omitted.

...why do that when you can simply sell though?

Sell what? Browsing data of VPN users? That would be easy to check.

How easy is the question.

1. Browsing habits would hardly have an affect on the vast array of data to have an effect on ads presented to you, unless you care about your privacy. Its all target auidence and marketing (look at ExpressVPN or Surfshark. They all offer privacy but never follow up)

2. Their algorithms can avoid showing you ads derived from the VPN if it detects the usage of your actual IP

Re: Infrastructure audit completed by Radically Open Security

#247

As ivpn's gateway in Brussels is more often than not 100% [0] during the evenings, I'm looking for an alternative. This wasn't the case until some 6-12 month. Anyone experience with mullvad's [1] throughput in Belgium? [0] https://www.ivpn.net/status/ [1] https://mullvad.net/en/servers

This is Viktor from IVPN. We have recently added more capacity to our Belgium server. I'm looking at our internal graphs and it has not been hitting 100% in the past couple of days. We are monitoring it closely and ready to add more bandwidth if necessary.

Re: Infrastructure audit completed by Radically Open Security

#248

I switched to Mullvad after teh last article i read here on HN about how they didn't log and couldn't offer logs to the authorities. I don't have the link but I was impressed and these audits are further proof that that decision was correct.

> I switched to Mullvad after teh last article i read here on HN about how they didn't log and couldn't offer logs to the authorities It should also be pointed out that OVPN[1] is an option as well. They were taken to court and won[2], so they demonstrated above all reasonable doubt that OVPN no-logging means no-logging. See the link for the detail, but I quote: "the Rights Alliance and their security experts have no…

OVPN was recently bought by the parent company of HotSpotShield. Make of that what you will.

https://www.ovpn.com/en/blog/next-chapter-for-ovpn

Re: Infrastructure audit completed by Radically Open Security

#249
I came across mullvad some time ago (apparently they struck a deal with Mozilla). Anyway, their service is great and it is such a rare thing to just pay for a service without all the nonsense around. Just; click here to get an account. Nothing else. Then just freaking press pay, in any of a huge array of methods, including cash in the mail!

Re: Infrastructure audit completed by Radically Open Security

#250
post #154

Earlier quoted context omitted.

Both are fine for vpn performance. However, Mullvad has won me over with their business practices. Mullvad accepts my payment for a month of use at a time, and I manually renew it (after I receive a reminder) each month. If I don’t need a vpn the following month, I don’t pay for another month. I also find Mullvad works a bit better on Linux too. I just got hit with a 2 year auto renewal charge from proton for my old…

Please note that Proton subscriptions are automatically renewed, as well as that if you are using multiple services under the same Proton account, the access to all of them will be suspended if an invoice has not been cleared for longer than 14 days: https://proton.me/support/delinquency . We cannot downgrade a subscription for you automatically, as only you can choose what data should be removed from your Proton acc…

This entire situation would have been avoided if you had sent me an an email saying, “Hey, we wanted to let you know that you are subscribed to an auto renewing plan that is set to charge your payment on file in two weeks.” Instead you have taken my money, and I have to spend my free time asking for it back.

> We cannot downgrade a subscription for you automatically, as only you can choose what data should be removed from your Proton account - it is impossible to downgrade the account to a Free subscription if it exceeds the limits of the Free subscription.

Add a button to delete all data in my account that appears when you tell me you can’t downgrade.

> The refund is automatically issued in the form of Proton credits which you can use for a Proton paid service in the future, or you can request the credits to be refunded back to your original payment method by contacting our support team

What is a proton credit? You chose to issue an unauthorized payment on my card in USD.

To summarize my experience, in order to cancel a subscription at the end of its period, one must:

- Set a reminder to cancel the subscription potentially years out because they cannot disable auto renew

Failing to cancel before being charged without a warning email, they must:

- Discover how to manually delete all of their files across various proton services to get their storage below a free tier threshold

- Email support to ask that their refund issued in proton credits be converted into their payment currency

- Respond to support’s email asking if they are sure they want a refund

Post reply on HN