Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

271–280 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#271

Earlier quoted context omitted.

The likelihood of being confused by rss among mullvad customers can't be very high.

You might be surprised! The Mullvad client is super well designed and usable for newbs, and I'll bet a lot of their business is from people whose more technical friends told them it was a good idea. There's a reason that Tor warns users that posting personal information or using accounts with their regular credentials compromises anonymity. I wish RSS had more surface area with general computer users, but I reckon ev…

Not being a Mullvad user myself, I wasn't sure if people tend to use a Mullvad client or a generic VPN stack built into their OS, but the Mullvad client could simply display news like this to the former set of users leaving only the latter set to configure a separate RSS client or whatever.

Re: Infrastructure audit completed by Radically Open Security

#272
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

What are legitimate use case to use port-forwarding behind a VPN IP? Genuinely curious, I'm not implying anything. The main use-case is hosting something for which you don't want to reveal your IP or circumvent some ISP that block hosting web servers on their residential IPs. I'm sure I'm missing many more use cases.

Can be used for hosting libgen/sci-hub.

Basically you have a thin proxy on some not so cheap but ‘anonymous’ Bitcoin payed VM, that then (http) links to your vpn endpoint.

You need the dual setup as using the btc vm for storage of terabytes of data as well as for TB of traffic is too expensive for a volunteer run project.

Re: Infrastructure audit completed by Radically Open Security

#273
post #219

Earlier quoted context omitted.

Sell what? Browsing data of VPN users? That would be easy to check.

How easy is the question. 1. Browsing habits would hardly have an affect on the vast array of data to have an effect on ads presented to you, unless you care about your privacy. Its all target auidence and marketing (look at ExpressVPN or Surfshark. They all offer privacy but never follow up) 2. Their algorithms can avoid showing you ads derived from the VPN if it detects the usage of your actual IP

If they sell data then it's possible to buy that data. So a security researcher could simply try buying that data and then expose that VPN provider.

Re: Infrastructure audit completed by Radically Open Security

#274
post #69

Earlier quoted context omitted.

> that's assuming that your ISP isn't doing some shady analytics Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?

It is my understanding that many ISPs and backbone providers sell or otherwise disclose full detailed packet metadata, including precision timestamps, and that there are companies that aggregate this data across the entire Internet. At which point your VPN becomes just another hop in the trace. VPNs, no matter how secure they themselves are, are effective for accessing lightly geo-locked content and defeating unsophi…

> VPNs, no matter how secure they themselves are, are effective for accessing lightly geo-locked content and defeating unsophisticated analytics and tracking

Circling back to this statement: aren't they also useful on public Wifi?

Re: Infrastructure audit completed by Radically Open Security

#275
post #264
post #253

Earlier quoted context omitted.

Because they have limited access to the Internet? That’s just silly.

and many other things

Like, what things? I'm a citizen of a heavily sanctioned country, even though I haven't lived there for years. If anything, sanctions only affect people in such a way that they hate the countries that imposed the sanctions on their country, but not their own government. That's a very naive point of view.

Re: Infrastructure audit completed by Radically Open Security

#276
post #275
post #264

Earlier quoted context omitted.

and many other things

Like, what things? I'm a citizen of a heavily sanctioned country, even though I haven't lived there for years. If anything, sanctions only affect people in such a way that they hate the countries that imposed the sanctions on their country, but not their own government. That's a very naive point of view.

Like we saw recentlly with Russia, the people were not upset when they invaded Ukraine. Then when McDonald's pulled out of Russia a fat guy chained itself to the doors. So internet, fast-food, clothes, cars, movies... water pumps... and so on.

Re: Infrastructure audit completed by Radically Open Security

#277
post #84

Earlier quoted context omitted.

>..a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet. ..where?

Literally every youtube ad spot for any vpn that advertises on youtube heavily. Which realize, is 100% of what most people think about VPN's, a nasty side effect of dishonest marketing.

But none of those YouTube ads are comments here.

Re: Infrastructure audit completed by Radically Open Security

#278

Earlier quoted context omitted.

Not that person but I've spinned a 1984 instance paid with bitcoin without KYC. Then setup nat+rdr rules that foward to my service through a wireguard tunnel.

Forgive my ignorance, but what’s a “1984 instance”? (Google could not help me.) Thanks!

Oh, I think that used to be 1984.is. Nice people, hydro powered, cooled by ice, strong privacy posture.

Re: Infrastructure audit completed by Radically Open Security

#279

Mullvad is THE ONLY mainstream VPN that doesn't have seriously questionable credibility. Not even Proton VPN is OK - sleuths have figured out that it's just a white-labeled version of NordVPN. I am thankful that Mullvad is doubling down on their commitment to integrity, because there isn't an alternative.

Do you have any sources for the NordVPN claim? Edit: I just had a look through your post history and you seem to have been claiming this for months, without providing any evidence. Shady.

I'm unaffiliated with either. But I can tell you that the allegations are true. At least, that was the state of things several years ago.

Re: Infrastructure audit completed by Radically Open Security

#280
post #276
post #275

Earlier quoted context omitted.

Like, what things? I'm a citizen of a heavily sanctioned country, even though I haven't lived there for years. If anything, sanctions only affect people in such a way that they hate the countries that imposed the sanctions on their country, but not their own government. That's a very naive point of view.

Like we saw recentlly with Russia, the people were not upset when they invaded Ukraine. Then when McDonald's pulled out of Russia a fat guy chained itself to the doors. So internet, fast-food, clothes, cars, movies... water pumps... and so on.

> the people were not upset

False. There's a lot (the majority) of people from my close circle who were and are "upset", if I can put it this way. I don't have the statistics, but let's say that's 80/20 ratio (supporters/non-supporters), even though I personally believe it's closer to 50/50.

> fast-food, clothes

So you really think that limited access to the Internet and the fact that McDonalds is gone would force these 20% to get on the streets and fight against the heavily armed government forces AND the rest 80% of the country population? I mean, among the other reasons that come to mind, sanctions (movies, cars, clothes - what??) are somewhere at the very bottom of my list, if matter at all.

Post reply on HN