Earlier quoted context omitted.
Makes you wonder...
Every now and then there are articles like this one about something that Mullvad may or may not be able to do better, and there are always comments about whether they're an intelligence front. I don't know the answer, but there are two ways to take it: 1. Submarining to destroy confidence in an actually trustworthy, decent VPN company 2. They're an intelligence front. For me, Mullvad have the appearance of the greate…
Mullvad exit IPs are surprisingly identifying
111–120 of 408 posts
Re: Mullvad exit IPs are surprisingly identifying
#112The purpose of a VPN does not include anonymizing users with respect to the sites they visit,so it shouldn't be too surprising that Mullvad doesn't enforce unique exit IPs. Users who want anonymity should use networks like Tor.
Isn't Tor a us government project that has been shown to be deanonymizable?
Re: Mullvad exit IPs are surprisingly identifying
#113Earlier quoted context omitted.
@ notpushkin, yes, it's a bit more expensive because it's for different use cases. You can't use VPNs or Mullvad for anything mission critical. Just try to log in to your bank in US, it will increase your risk score on their end because VPNs by nature are very easy to detect whereas "residential proxies" much harder.
> You can't use VPNs or Mullvad for anything mission critical. Just try to log in to your bank in US, it will increase your risk score on their end because VPNs by nature is very easy to detect whereas "residential proxies" much harder. Naturally! I’m just saying there’s residential proxy providers that are a LOT cheaper than that. (IIRC, you can usually reply to fresh comments if you click on the “n minutes ago” – t…
Re: Mullvad exit IPs are surprisingly identifying
#114Earlier quoted context omitted.
But what privacy do you think majority of people who not doing something badly illegal expect from VPNs? Most likely these people just look to hide their torrenting, saying political shit on Twitter from employer and not share their choice of porn with local ISP. Also just adding one more layer between them and occasional scammer who can sometimes infer more broad geodata from their IP leaked from yet another databas…
Source? Why not “I don’t want to get profiled”?
Re: Mullvad exit IPs are surprisingly identifying
#115Earlier quoted context omitted.
the counterpoint is that making your traffic cross out of the US gives the NSA (by their ass backwards reading) permission to spy on you
Fair point, but I'm not sure if that was ever a boundary they wouldn't cross, but for 'a little while now' I'd say it doesn't matter. From outside the US I should be using a VPN end-point within the US, so that my browsing traffic doesn't hit the NSA - only my encrypted VPN traffic does.
I mean, let's be real.
All known US VPN servers and Tor exit nodes--and probably all US Tor relays regardless of exit policy--are going to be considered a totally legitimate "communications facility" target for the warrantless wiretapping system due to exactly the scenario you just posited.
From that perspective you'd be better off using US residential proxies. Of course, while they'll never admit it in court, NSA just does whatever they want, laws be damned, and are almost certainly logging everything. So while such a scheme might theoretically hinder the introduction of evidence in a court case, it doesn't really matter; NSA is still gonna see your traffic and they're still gonna either drone strike you or "parallel construction" your ass, anyway.
Re: Mullvad exit IPs are surprisingly identifying
#116Re: Mullvad exit IPs are surprisingly identifying
#117> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…
Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?
The funny thing about that era is you knew they started using Cloudflare because they went from stable with constant uptime to going down and showing a Cloudflare banner randomly all the time for a good year or so. They ran worse with Cloudflare than they did while they were allegedly getting DDoSed. The whole company glows, as the late great HN commenter Terry Davis would've said.
Re: Mullvad exit IPs are surprisingly identifying
#118Earlier quoted context omitted.
VPNs are not snake oil. They transfer the trust of your internet activity from a place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad, IVPN, or Proton. Among other benefits. If you don't like your ISP creating a profile of you and selling it to target ads to you, you should use a VPN. >Should I use a VPN? Yes, almost certainly. A VPN has many advantages, including: 1. Hiding…
Unfortunately, the largest and most well-marketed VPNs are, in fact, less trustworthy than your average ISP.
Re: Mullvad exit IPs are surprisingly identifying
#119Earlier quoted context omitted.
You know that people use VPNs for perfectly legitimate reasons, right? Like when I was travelling, sites would routinely use the language of my IP address location, not the language preference as I set it in my browser. So I would be served a site that I couldn't read. My only option was to use a VPN to spoof my location so that it would serve me a site in a language I understand.
I use aVPN when I’m traveling and want to order food delivery for my 93 year old mother in NY. UberEats and InstaCart will stop me from ordering when logged in my mom’s NY account if I’m in China, Saudi Arabia, India, Vietnam, etc.
Re: Mullvad exit IPs are surprisingly identifying
#120Earlier quoted context omitted.
Well there is still the small detail of them not storing any logs. This is a massive issue in my view, it allows correlation across multiple VPNs exit nodes, but that’s it. It doesn’t allow to identify you automatically. It does significantly lower the bars for identifying you though, but the requirements are still high. Hopefully they fix this soon. I can’t believe this type of “let’s make it a hash or something sen…
> It does significantly lower the bars for identifying you though, but the requirements are still high If you squint a bit, it looks a lot like a "Nobody But US" (NOBUS[1]) scheme. A few more identifying bits could tip the scale for party that has a whole host of other bits on a list of suspects, without being useful to most other people. 1. https://en.wikipedia.org/wiki/NOBUS
Their ads on San Francisco's public transit are good.