Its funny, how the VPN providers basically become the avatars of the old anarchic web and the constant buisness and government overreach makes them ever stronger. Its basically a old "freedom" tax.
That’s incredibly generous. The VPN industry is deserving of its bad reputation. Collecting user data in clear contravention of their TOS. Using hacked boxes as VPN endpoints to get people onto residential IP ranges. And whatever else. I’m very confident in my completely baseless assertion that most people that use a “public” VPN are either bypassing geographical restrictions on a streaming service, or doing somethin…
Mullvad VPN was subject to a search warrant – customer data not compromised
111–120 of 345 posts
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#112Earlier quoted context omitted.
All standard British stamps now have unique Data Matrix codes on them, which means you also have to source your stamps anonymously.
Can bet 99.99% that Mullvad throws the envelope in the trash and just forgets about it. So, yes, there is a theory that someone may go in the trash in Sweden, finds the envelope, the stamp (and it has to be a british one), investigate who bought the stamp, get the assistance of the shopkeeper in UK (without raising suspicions), successfully reviews tons of security cameras footage to find who bought, etc. And still d…
Better yet, they shred it: https://mullvad.net/en/help/no-logging-data-policy/#payments.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#113Earlier quoted context omitted.
Briefly, law requires establishing probable cause, that _one_ specific person has done specific things, to underwrite search warrant. VPN IPs are shared between users, meaning any one of the ~X00 users sharing a single ip could be doing any number of things at the same time.
If an app phones home at 11:00 AM and the illegal act is at 11:01 AM wouldn't it narrow down the list of suspects considerably?
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#114Earlier quoted context omitted.
They also have vouchers you can buy from Amazon, which I find a nice alternative to sending cash in an envelope.
At that point, you can probably just pay by credit card: If your aim is to frustrate invasive ad trackers and profilers on the web (and you assume that Mullvad isn't outright colluding with these), that should be good enough to break any links. On the other hand, if you don't trust Mullvad's assertion that they delete the link between accounts and credit card payment records after 40 days [1], what makes you think yo…
By the end of the day I agree, if you have any "real" reason for using VPN you pretty much have to implicitly trust your provider to not keep any traffic flows and connections that could correlate traffic to your IP, but not even sending money in envelope saves your from that.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#115> After demonstrating that this is indeed how our service works and them consulting the prosecutor they left without taking anything Setting aside impacts on customers, I wonder how common seizures would need to be to support a purely financial case that businesses that are known to not store identifying information are therefore less likely to incur the cost and effort of scrambling to replace seized hardware.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#116I don't understand why go after the VPN, I think most people don't use a VPN correctly. What good is a VPN when multiple apps on your computer are phoning home? If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP? To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to…
I can use VPN to access the web freely and while VPN provider can also log my traffic, I trust it MUCH MORE than my country's government.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#117OR ... something more fishy is going on behind the scene.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#118Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#119> After demonstrating that this is indeed how our service works and them consulting the prosecutor they left without taking anything Setting aside impacts on customers, I wonder how common seizures would need to be to support a purely financial case that businesses that are known to not store identifying information are therefore less likely to incur the cost and effort of scrambling to replace seized hardware.
I did notice that phrase doing a lot of work there. I'm actually super curious: when a bunch of goons turn up on your doorstep fully expecting to cart away boxes of electronics, /how on earth/ do you "demonstrate that this is indeed how our service works", there and then on the spot, in a sufficiently convincing manner that they leave again empty-handed?
I presume it wouldn't be difficult to argue that as soon as you shut off a server to transfer it away, things they're looking for would be lost.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#120Earlier quoted context omitted.
All standard British stamps now have unique Data Matrix codes on them, which means you also have to source your stamps anonymously.
Can bet 99.99% that Mullvad throws the envelope in the trash and just forgets about it. So, yes, there is a theory that someone may go in the trash in Sweden, finds the envelope, the stamp (and it has to be a british one), investigate who bought the stamp, get the assistance of the shopkeeper in UK (without raising suspicions), successfully reviews tons of security cameras footage to find who bought, etc. And still d…
Presumably the theory is more like [1] - that the postal service, when they scan the envelope to read the address, save the scanned image and give it to the cops.
I agree that the NSA would be better off just running their own VPN services - or indeed intercepting everything on major backbones and just seeing what source IPs connect to Mullvad's servers.
[1] https://arstechnica.com/tech-policy/2013/07/us-postal-servic...