Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

161–170 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#161

Earlier quoted context omitted.

Yeah, their origin is a story of absolute incredible luck. Cloudflare came out of nowhere and suddenly massive sites with huge user bases around the world, including places like 4chan, were getting DDoSed. Then they immediately announce that they transitioned to Cloudflare. Hell of a lucky time to make a company that the entire internet suddenly became absolutely dependent on. The funny thing about that era is you kn…

Am i the only one that actually remembers this time period? It wasn’t that long ago. The confidence of your assertion is completely misplaced. I remember exactly where i was when I first read about CF, on launch day. DDoS attacks were CERTAINLY a big issue before Cloudflare came along. A whole lot of script kiddie energy was poured into them. LHC? Slowloris? IRC C2? This wasn’t niche stuff. That’s why I remember the…

I was there and recalled there being occasional script kiddy DDoS attacks here and there. But the uptime when being attacked was still much, much better than the first 1-2 years of actually using Cloudflare.

Re: Mullvad exit IPs are surprisingly identifying

#162

Earlier quoted context omitted.

The mass surveillance industry doesn’t rely on ips or even cookies to track you.

That seems like a huge bet. I don’t bet on this, I am careful about cookies and my source IPs. Do you have any facts? I know they really on _additional_ stuff, but do you have sources showing that they never use cookies or source IPs?

He said they don't rely on it. They can use fingerprinting. Obviously they'll still use any other data you give them, including IP addresses or cookies.

Re: Mullvad exit IPs are surprisingly identifying

#163
post #158

Earlier quoted context omitted.

I could just...lie.

One person can tell a lie, but a company consists of many people. You must ensure that only few people know of the logging or there will be a risk of a leak.

An intelligence agency already consists of more people than you need to run a VPN service.

Re: Mullvad exit IPs are surprisingly identifying

#164
post #89

Earlier quoted context omitted.

> place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad This is highly subjective statement. Almost all commercial VPN services farm and sell your data. Just by that, my ISP is definitely high trust point while any commercial VPN is a low trust.

> Almost all commercial VPN services farm and sell your data. Citation needed.

I understand it's not up to your (or anyone's) level of belief, but I am in intimately familiar with their modus operandi.

For everyone in the industry it is le secret de Polichinelle.

Re: Mullvad exit IPs are surprisingly identifying

#165

Earlier quoted context omitted.

> place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad This is highly subjective statement. Almost all commercial VPN services farm and sell your data. Just by that, my ISP is definitely high trust point while any commercial VPN is a low trust.

I can easily pay for a VPN service with crypto anonymously. I can also use a VPN run by a company outside my country of residence and jurisdiction. Neither of those is possible with my ISP.

Paying with crypto does something to deindentify you, but does nothing about your traffic. It's still being watched.

Re: Mullvad exit IPs are surprisingly identifying

#166
post #158

Earlier quoted context omitted.

I could just...lie.

One person can tell a lie, but a company consists of many people. You must ensure that only few people know of the logging or there will be a risk of a leak.

Intelligence agencies... are generally pretty good at that.

Re: Mullvad exit IPs are surprisingly identifying

#167
post #154

Earlier quoted context omitted.

It's within the realm of possibility that NSA is collecting data with Cloudflare's consent. It seems unlikely that Cloudflare would jeopardize their entire business model over it. Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers. Their entire value proposition is being an unobtrusive traffic intermediary.

Within the realm of possibility? Let's be honest, if you are a top NSA executive and you couldn't find a way to get your hands on Cloudflare's private keys (bribing or threatening the right person), you are not getting your Christmas bonus.

It is of course inconceivable that the NSA do not have the private keys for dozens of browser trusted certificate authorities

That nonetheless doesn't help them unless they are doing active MITM. In order to do that they'd have to have at least some physical presence at Cloudflare or on the path to Cloudflare.

Re: Mullvad exit IPs are surprisingly identifying

#168
post #154

Earlier quoted context omitted.

It's within the realm of possibility that NSA is collecting data with Cloudflare's consent. It seems unlikely that Cloudflare would jeopardize their entire business model over it. Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers. Their entire value proposition is being an unobtrusive traffic intermediary.

Within the realm of possibility? Let's be honest, if you are a top NSA executive and you couldn't find a way to get your hands on Cloudflare's private keys (bribing or threatening the right person), you are not getting your Christmas bonus.

Is this information derived from Enemy of the State starring Will Smith and Gene Hackman? It was a great movie and the first DVD I ever bought.

Re: Mullvad exit IPs are surprisingly identifying

#169

Earlier quoted context omitted.

That seems like a huge bet. I don’t bet on this, I am careful about cookies and my source IPs. Do you have any facts? I know they really on _additional_ stuff, but do you have sources showing that they never use cookies or source IPs?

He said they don't rely on it. They can use fingerprinting. Obviously they'll still use any other data you give them, including IP addresses or cookies.

Ok, what was his point then? “They don’t rely on it, so it’s useless to obfuscate it”, or “but you should keep obfuscating it” or something else? I am missing the relation to my original comment then.
Post reply on HN