Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

91–100 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#91
post #26

Earlier quoted context omitted.

I can easily pay for a VPN service with crypto anonymously. I can also use a VPN run by a company outside my country of residence and jurisdiction. Neither of those is possible with my ISP.

prepaid 5g sim cards and 5g modem.

Make it a “tourist eSIM” for a good measure. Your phone will be in one country, your exit IP in another (because there usually use roaming).

That said, you might still want to use a VPN on top of that, depending on what you’re doing.

Re: Mullvad exit IPs are surprisingly identifying

#92

The purpose of a VPN does not include anonymizing users with respect to the sites they visit,so it shouldn't be too surprising that Mullvad doesn't enforce unique exit IPs. Users who want anonymity should use networks like Tor.

Isn't Tor a us government project that has been shown to be deanonymizable?

Sort of. There are a bunch of timing attacks bug in general it still works fairly well.

Re: Mullvad exit IPs are surprisingly identifying

#93
post #87

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?

I don’t see how they couldn’t be. Either on purpose, secretly my coercion, or secretly without their own knowledge. It’s so valuable

Re: Mullvad exit IPs are surprisingly identifying

#94
post #80

The purpose of a VPN does not include anonymizing users with respect to the sites they visit,so it shouldn't be too surprising that Mullvad doesn't enforce unique exit IPs. Users who want anonymity should use networks like Tor.

That is exactly the point of public VPNs.. If I'm on a public VPN, I don't want anyone to know who is making the request, including the terminating IP. Think about it. By your logic, VPNs shouldn't be used for torrents because VPNs shouldn't anonymize you to the terminating IP. Whereas they work gangbusters for that. If you are talking about private VPNs.. Mullvad isn't one.

I think you are misreading his comment. He is saying that on a VPN it is standard behavior that if you visit site A and site B they will both see you connecting from the same IP and can infer you are potentially the same person.

Re: Mullvad exit IPs are surprisingly identifying

#95

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. I don't see how the author is arriving at this…

Say your forum is a big one and has 1000 active users, with 1 joining every day. Most will be a lot smaller/less active.

What are the chances that someone uses this vpn, joins your forum the day after someone was banned, and has an ip in a similar range?

For most small websites this would be strong evidence.

Re: Mullvad exit IPs are surprisingly identifying

#96
post #87

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?

> Wonder who can do those sudden attacks?

Anyone with a few crypto currencies in their wallet that can click a button on any of the booter services with botnets for hire.

Re: Mullvad exit IPs are surprisingly identifying

#97

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

Well there is still the small detail of them not storing any logs.

This is a massive issue in my view, it allows correlation across multiple VPNs exit nodes, but that’s it. It doesn’t allow to identify you automatically. It does significantly lower the bars for identifying you though, but the requirements are still high.

Hopefully they fix this soon.

I can’t believe this type of “let’s make it a hash or something sensitive” still happen, and at mullvad, of all places. Why not randomise it simply?

Re: Mullvad exit IPs are surprisingly identifying

#98

The purpose of a VPN does not include anonymizing users with respect to the sites they visit,so it shouldn't be too surprising that Mullvad doesn't enforce unique exit IPs. Users who want anonymity should use networks like Tor.

Why not? Why can’t it be the purpose of a given VPN service?

Re: Mullvad exit IPs are surprisingly identifying

#99
post #72
post #62

Earlier quoted context omitted.

Most of the big consumer VPNs include "privacy" with an implication of anonymity in their marketing, so it shouldn't really be surprising

But what privacy do you think majority of people who not doing something badly illegal expect from VPNs? Most likely these people just look to hide their torrenting, saying political shit on Twitter from employer and not share their choice of porn with local ISP. Also just adding one more layer between them and occasional scammer who can sometimes infer more broad geodata from their IP leaked from yet another databas…

Source? Why not “I don’t want to get profiled”?

Re: Mullvad exit IPs are surprisingly identifying

#100

I maintain a list of "23034 IPs to blocklist.txt" blocked IPs they contain all VPN providers. Often VPN providers seed Geofeeds with wrong data, this is why i use traceroute and ping network to locate their real location.

I have a script that logs IPs for any traffic coming in to my servers on ports that don't accept traffic. I then block those IPs from accessing ports behind which there are services. If they're checking my locked doors, I don't want them coming in my unlocked doors.

That’s nice, I need to implement this.
Post reply on HN