Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

101–110 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#101
post #90

Earlier quoted context omitted.

This might be a good idea, but consider banning them for, say, a couple hours at a time. It’s easy to rotate IP, especially if you’re using a residential proxy service, and there’s a good chance you’ll end up blocking real users using the same ISP.

yeah, I'm using https://proxybase.xyz for this. It's like Mullvad but for proxies. No kyc, no email but supports xmr.

I like the API-centric nature of it. $10/GB seems a bit steep though, especially compared to Mullvad’s 5 €/mo.

Search for “mobile proxy” – those are usually cheap-ish monthly subscriptions, with unlimited traffic, and often an API to rotate the IP programmatically if you need it. No KYC, but you usually do have to sign up with an email.

Re: Mullvad exit IPs are surprisingly identifying

#102

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

Well there is still the small detail of them not storing any logs. This is a massive issue in my view, it allows correlation across multiple VPNs exit nodes, but that’s it. It doesn’t allow to identify you automatically. It does significantly lower the bars for identifying you though, but the requirements are still high. Hopefully they fix this soon. I can’t believe this type of “let’s make it a hash or something sen…

> It does significantly lower the bars for identifying you though, but the requirements are still high

If you squint a bit, it looks a lot like a "Nobody But US" (NOBUS[1]) scheme. A few more identifying bits could tip the scale for party that has a whole host of other bits on a list of suspects, without being useful to most other people.

1. https://en.wikipedia.org/wiki/NOBUS

Re: Mullvad exit IPs are surprisingly identifying

#103
post #87

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?

That’s been my pet theory from day 1, and not because of DDoS. Simply because they are the SSL terminator for most of the internet and can see anything going on in cleartext (and I’ve seen them protecting some shady stuff)

I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)”

If NSA aren’t installed at Cloudflare, I wonder what they are even doing.

Re: Mullvad exit IPs are surprisingly identifying

#104

Earlier quoted context omitted.

Well there is still the small detail of them not storing any logs. This is a massive issue in my view, it allows correlation across multiple VPNs exit nodes, but that’s it. It doesn’t allow to identify you automatically. It does significantly lower the bars for identifying you though, but the requirements are still high. Hopefully they fix this soon. I can’t believe this type of “let’s make it a hash or something sen…

> It does significantly lower the bars for identifying you though, but the requirements are still high If you squint a bit, it looks a lot like a "Nobody But US" (NOBUS[1]) scheme. A few more identifying bits could tip the scale for party that has a whole host of other bits on a list of suspects, without being useful to most other people. 1. https://en.wikipedia.org/wiki/NOBUS

You definitely need glasses then.

Let me specify: The user must have entered his data on one site which the attacker has control of. That is a high bar still.

Re: Mullvad exit IPs are surprisingly identifying

#105
post #96
post #87

Earlier quoted context omitted.

Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?

> Wonder who can do those sudden attacks? Anyone with a few crypto currencies in their wallet that can click a button on any of the booter services with botnets for hire.

You are right, they don't have to do it themselves, but guess who's protecting the booters from other booters?

Re: Mullvad exit IPs are surprisingly identifying

#106
post #90

Earlier quoted context omitted.

This might be a good idea, but consider banning them for, say, a couple hours at a time. It’s easy to rotate IP, especially if you’re using a residential proxy service, and there’s a good chance you’ll end up blocking real users using the same ISP.

yeah, I'm using https://proxybase.xyz for this. It's like Mullvad but for proxies. No kyc, no email but supports xmr.

@ notpushkin,

yes, it's a bit more expensive because it's for different use cases. You can't use VPNs or Mullvad for anything mission critical. Just try to log in to your bank in US, it will increase your risk score on their end because VPNs by nature are very easy to detect whereas "residential proxies" much harder.

Re: Mullvad exit IPs are surprisingly identifying

#107
post #103
post #87

Earlier quoted context omitted.

Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?

That’s been my pet theory from day 1, and not because of DDoS. Simply because they are the SSL terminator for most of the internet and can see anything going on in cleartext (and I’ve seen them protecting some shady stuff) I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)” If NSA aren’t installed at Cloudflare, I wonde…

That slide was about the NSA sitting inside Google data centers without Google's knowledge.

That doesn't mean collusion

Re: Mullvad exit IPs are surprisingly identifying

#108

Earlier quoted context omitted.

Isn't Tor a us government project that has been shown to be deanonymizable?

Sort of. There are a bunch of timing attacks bug in general it still works fairly well.

Also, a buch of conspiring entry-/exit-nodes will do the trick, if you have a budget for enough of them.

Re: Mullvad exit IPs are surprisingly identifying

#109
post #106
post #90

Earlier quoted context omitted.

yeah, I'm using https://proxybase.xyz for this. It's like Mullvad but for proxies. No kyc, no email but supports xmr.

@ notpushkin, yes, it's a bit more expensive because it's for different use cases. You can't use VPNs or Mullvad for anything mission critical. Just try to log in to your bank in US, it will increase your risk score on their end because VPNs by nature are very easy to detect whereas "residential proxies" much harder.

> You can't use VPNs or Mullvad for anything mission critical. Just try to log in to your bank in US, it will increase your risk score on their end because VPNs by nature is very easy to detect whereas "residential proxies" much harder.

Naturally! I’m just saying there’s residential proxy providers that are a LOT cheaper than that.

(IIRC, you can usually reply to fresh comments if you click on the “n minutes ago” – the reply link should be visible there even if it isn’t shown in the main comments tree)

Re: Mullvad exit IPs are surprisingly identifying

#110

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

Why? If I was an intelligence agency and designing a VPN I would simply log all the IPs connecting to my VPN and not rely on statistics on exit nodes to identify the users, even more so because they rely on the users to pick different servers.
Post reply on HN