Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

261–270 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#261

As ivpn's gateway in Brussels is more often than not 100% [0] during the evenings, I'm looking for an alternative. This wasn't the case until some 6-12 month. Anyone experience with mullvad's [1] throughput in Belgium? [0] https://www.ivpn.net/status/ [1] https://mullvad.net/en/servers

I'm a little hesitant to say the following, since I don't collect metrics, and thus it's maybe a bit unfair on Mullvad, but: sometimes the Belgian Mullvad locations can be a bit slow. I've had that feeling from time to time, and on a few occasions when switching to their Netherlands locations I get better speed. Right now for instance I get close to full theoretical speed as promised by my ISP while going through Mullvad Netherlands, and only a quarter of that speed through the Belgian locations.

Re: Infrastructure audit completed by Radically Open Security

#262

It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convin…

At some point of paranoia people should really look into selfhosting a VPN service. Sure, your VPS provider can see one side of the traffic so its not bullet proof, but that can be mitigated. Mullvad is a nice middle ground for those who don't see that as worth their time or don't know how. Its good to see they're at the very least trying to keep up appearances.

Self hosting isn’t private at all. You will replace home IP with VPS IP, both of which linked to you. Also, VPS provider probably logs the traffic.

Re: Infrastructure audit completed by Radically Open Security

#263
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

Becoming well known for always trying to put customers first is a good strategy and probably makes business sense in the long run. I have used mullvad for years. I have no intention of shifting provider. Mainly because the evidence is starting to stack up that they are one of the few good actors in a cess pit of shitty/shady competition. (Though it's a shane mullvad gets blocked by netflix, well the last time I tried it wasn't working).

The only other service I have any brand loyalty to gog.com. For some reason I feel the same about them.

Re: Infrastructure audit completed by Radically Open Security

#265
post #254

Earlier quoted context omitted.

Whether the people considered themselves to be "Russian" or not, in 1991 54% of voters in Crimea came out in favor of independence: https://en.wikipedia.org/wiki/1991_Ukrainian_independence_re... Even though you have the results of "demographics" survey of 1989 that put "Russian" populace at 67%.

Thanks for this. I'm glad people have good, evidence-based responses to my comment. This gives us a great idea of how likely a Crimean who considers themselves Russian would actually vote between the two and that while the correlation is strong, it might not be strong enough to suggest Crimeans would favor Russia and while Crimea is still clearly, the most Russian-friendly Ukrainian state, the decision between the tw…

What it probably shows, is that while the fraction of inhabitants of Russian ethnicity stayed roughly the same in there, the supporters for joining Russia, at the very least, are not the same exact set of people. And we don't really know their number because the vote didn't have any independent observers.

> but they say the outcome of a vote would very likely be pro-Russia, even before they started shipping Russians in and pre-occupation

I heard similar opinions too, but it might vary on who you ask. E.g. we talk about information bubbles on the Internet, but they exist IRL too. That is to say, hearsay is not proof. And even if it were true, one might keep in mind that the reasons for that might not be obvious. E.g. there had been a fair amount of anti-Ukrainian propaganda on the Russian state TV (which broadcasted in Crimea as well) starting with 2000s or so.

Or here's a thought exercise, from another perspective: would you say if US made a poll in Monterrey (Mexico) about whether the people in there wanted to join US, and >50% of them said yes, it would have been justifiable (in at least some practical sense) to annex it? Or Montreal/Canada, for example. It's close enough to the border.

Re: Infrastructure audit completed by Radically Open Security

#266
post #179

Earlier quoted context omitted.

Port forwarding doesn't seem to be a problem for long-established independent VPNs like AirVPN (based in Italy but very ingeniously without exit servers in Italy) or AzireVPN (Swedish; added port forwarding -- all mappings in memory, no static records -- just recently [1]). What makes Mullvad's situation different? Is it a question of margins for high traffic port forwarding users (Mullvad is branching out in browser…

Mullvad is probably the VPN with the longest track record of not keeping logs. I find it likely that the vast majority of people who hosted immoral content using Mullvad's port forwarding feature solely used Mullvad for this purpose because of their reputation. After Mullvad discontinued port forwarding, IVPN (probably the second most trusted VPN provider) came out a month later and announced that they were also disc…

So basically no companies wish to provide anonymous unrestricted uncensored information exchange.

Re: Infrastructure audit completed by Radically Open Security

#267
post #99

Earlier quoted context omitted.

Have you found a replacement? I did some light investigation but nothing really felt as solid as Mullvad so I haven't jumped ship yet.

Not that person but I've spinned a 1984 instance paid with bitcoin without KYC. Then setup nat+rdr rules that foward to my service through a wireguard tunnel.

Why use wireguard? It is trivially to detect by the ISP or government. Every decent VPN should masquerade as HTTP/2 or HTTP/3.

Re: Infrastructure audit completed by Radically Open Security

#268

Earlier quoted context omitted.

What are legitimate use case to use port-forwarding behind a VPN IP? Genuinely curious, I'm not implying anything. The main use-case is hosting something for which you don't want to reveal your IP or circumvent some ISP that block hosting web servers on their residential IPs. I'm sure I'm missing many more use cases.

I have been out of the loop for a while on this, but doesn't BitTorrent require you to set up a port forward? Otherwise you can only connect to peers that do, but not other peers that don't.

I think it is possible to connect using STUN even if both users are behind NAT.

Re: Infrastructure audit completed by Radically Open Security

#269
post #84

Up front, I believe Mullvad is the best commercial VPN solution and is doing a great job at making good privacy more accessible. However, a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet. I would like to remind people that VPNs only really protect you against two things: your ISP and the endpoint. And that's assuming that your ISP isn't doing some shady analytic…

>..a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet. ..where?

Literally every youtube ad spot for any vpn that advertises on youtube heavily.

Which realize, is 100% of what most people think about VPN's, a nasty side effect of dishonest marketing.

Re: Infrastructure audit completed by Radically Open Security

#270
post #165

Earlier quoted context omitted.

They give some examples of things bad actors used port forwarding for in the blog post[1] announcing the removal of the feature. [1]: https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...

Reading between the lines, I'd be very surprised if it wasn't highly undesirable content, i.e. child porn or fraud. This came about a month after a very publicised raid by the Swedish police -- after which they left with nothing [1]. [1] https://www.pcmag.com/news/mullvad-vpn-hit-with-search-warra...

I am highly certain it involved both and more.

For example, say someone wanted to run their botnet distribution server. Now, unless you’re a state actor working for North Korea or some such, that generally gets a rather angry knock on your door in a rather short period of time.

Being able to hide your IP/traffic for $5/mo is going to save you a significant amount of trouble.

I’m certain AWS and other hosting providers keep track of any activity that’s too strange, and the authorities will have your hosting provider give you the boot even if they can’t figure out who you are exactly.

Developing a reputation for allowing, if not quite condoning such behavior will quite quickly get you shut down as a business. Even if they can’t “prove” anything, you’ll get hassled, harassed, and investigated to death because your existence goes from being a nuisance to being a problem.

Some guy torrented a few movies on your VPN? Whatever. Some guy used your VPN to break into their local government’s servers? If they can’t find him, they’ll take it out on you.

Post reply on HN