Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

261–270 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#261
post #258

Earlier quoted context omitted.

Can we have an Open Suse client. Sorta odd you don't support one of Europe's most popular distros.

It already has official packaging for Tumbleweed, see https://github.com/mullvad/mullvadvpn-app/issues/2242 for the upstream issue. Leap can use the normal Linux application, you will just have to provide the dependencies yourself.

https://mullvad.net/en/help/install-mullvad-app-linux

>The Mullvad VPN app is available in our repository for the following supported Linux distributions:

Ubuntu (24.04+) Debian (12+) Fedora (42+)

The only thing I see on the issue you linked is a way to jerry-rig the fedora package. When I tried that I kept getting untrusted key warnings. You can skip them of course, but it kind of undermines any type of trust here

Re: Mullvad exit IPs are surprisingly identifying

#262
I'm a long-time Mullvad user. I will continue to buy and use Mullvad VPN services (with my credit card that has my name on it) so long as it is legal to do so in my country.

VPNs are not 100% anonymous. They are not meant to be. Instead, they are meant to provide some level of privacy to law-abiding adults.

Most people would be embarrassed if their co-workers and neighbors knew the intimate personal details of their lives. Things they like, things they buy, things they do, etc. So, most people should use a VPN to protect their privacy.

By definition, 'most people' don't want or expect 100% anonymity online. They just want a bit of privacy in their personal life and their relationships. That's it.

VPNs don't protect (and are not intended to protect) criminals who want 100% anonymity from governments while committing online crimes. This is an important distinction. 'Most people' are not criminals and do not have this unrealistic expectation from Mullvad and other VPN providers.

Re: Mullvad exit IPs are surprisingly identifying

#263

Earlier quoted context omitted.

I understand it's not up to your (or anyone's) level of belief, but I am in intimately familiar with their modus operandi. For everyone in the industry it is le secret de Polichinelle.

I think they don't sell their VPN data, because if that ever came out, that would destroy their business. Selling the data would be far too risky for them.

Thats like saying there is no corruption in government because it would undermine public trust in it.

Of course there is, and to huge extent. They know they canget away with it, so they do.

Re: Mullvad exit IPs are surprisingly identifying

#264

I work for IPinfo. Even though we are in the VPN detection business, I will give Mullvad the benefit of the doubt, to be honest. They were one of the three VPN providers we found that did not attempt to submit inaccurate geolocation information to IP geolocation providers like us. I am sure they will fix the issue.

Who else ?

Windsribe and iVPN.

https://ipinfo.io/vpnreport

Re: Mullvad exit IPs are surprisingly identifying

#265
post #178

I work at Mullvad. (co-CEO, co-founder) Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post's findings you may get confusing results throughout the day. We will also re-evaluate wheth…

> Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings How to report a bug or vulnerability ... we (currently) have no bug bounty program ... send an email to support@mullvadvpn.net https://mullvad.net/en/help/how-report-bug-or-vulnerability / https://archive.vn/BeHhr

Are you seriously suggesting people shouldn't operate with a bit of common decency unless they're going to get some money out of it?

Re: Mullvad exit IPs are surprisingly identifying

#266

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

Mullvad predates the Snowden leaks by several years and was not mentioned anywhere in them. Sure, there are other intelligence agencies, but that's the one I'd be the most worried about. Since either they run it, or they would know of it and want to emulate the idea, or know of it and have access to it from the partner agency running it. Or they are not a threat to me. There's also the issue of no publicly known case…

Intelligence agencies use parallel construction to disguise their real methods. Further, more sophisticated methods are reserved for bigger targets. Intelligence agencies aren't running around discussing their methods publicly, most intelligence agency work doesn't result in public criminal charges.

Re: Mullvad exit IPs are surprisingly identifying

#267

Earlier quoted context omitted.

> Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings How to report a bug or vulnerability ... we (currently) have no bug bounty program ... send an email to support@mullvadvpn.net https://mullvad.net/en/help/how-report-bug-or-vulnerability / https://archive.vn/BeHhr

Are you seriously suggesting people shouldn't operate with a bit of common decency unless they're going to get some money out of it?

Most of HN readers/writers are American, of course they won't do anything unless they personally profit off it, the entire culture is built around this mindset. Meanwhile, Mullvad is Swedish, and we tend to assume we all want to help build a better world together. Mix the two, and you get this conversation :)

Re: Mullvad exit IPs are surprisingly identifying

#268
post #178

I work at Mullvad. (co-CEO, co-founder) Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post's findings you may get confusing results throughout the day. We will also re-evaluate wheth…

Thanks for the reassurances. Love your product.

Re: Mullvad exit IPs are surprisingly identifying

#269

Earlier quoted context omitted.

All the companies involved in PRISM made public statements saying they ceased participation. Google undertook a costly initiative to add encrypted connections over their datacenter circuits. The NSA leaks were a forcing function that led to a massive uptake of encryption. Up until that point it was common for websites to support only HTTP. The NSA leaks dominated news cycles for the entirety of 2013.

> All the companies involved in PRISM made public statements saying they ceased participation. Google undertook a costly initiative to add encrypted connections over their datacenter circuits This is as helpful as Whatsapp's so called E2E encryption comms (that just happens to not be applicable by default in certain situations).

What are those certain situations?

Re: Mullvad exit IPs are surprisingly identifying

#270
post #195

Earlier quoted context omitted.

If it were a true honeypot by a state agency, they'd be able to just lie about having nothing too.

Not when people get arrested and the investigative techniques, sources, etc are made public. They would have to intervene in the legal process to make sure mullvad's role was kept secret. Presumably this isn't always feasible across jurisdictions.

Parallel construction
Post reply on HN