Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

121–130 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#121
post #96

Earlier quoted context omitted.

> Wonder who can do those sudden attacks? Anyone with a few crypto currencies in their wallet that can click a button on any of the booter services with botnets for hire.

You are right, they don't have to do it themselves, but guess who's protecting the booters from other booters?

Primarily specialist bulletproof ddos protection services like ddos-guard.ru, not "Cloudflare" as is the popular meme among clueless commenters.

Re: Mullvad exit IPs are surprisingly identifying

#123

Earlier quoted context omitted.

> It does significantly lower the bars for identifying you though, but the requirements are still high If you squint a bit, it looks a lot like a "Nobody But US" (NOBUS[1]) scheme. A few more identifying bits could tip the scale for party that has a whole host of other bits on a list of suspects, without being useful to most other people. 1. https://en.wikipedia.org/wiki/NOBUS

You definitely need glasses then. Let me specify: The user must have entered his data on one site which the attacker has control of. That is a high bar still.

it really isn’t.

Re: Mullvad exit IPs are surprisingly identifying

#124
post #103
post #87

Earlier quoted context omitted.

Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?

That’s been my pet theory from day 1, and not because of DDoS. Simply because they are the SSL terminator for most of the internet and can see anything going on in cleartext (and I’ve seen them protecting some shady stuff) I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)” If NSA aren’t installed at Cloudflare, I wonde…

It's within the realm of possibility that NSA is collecting data with Cloudflare's consent. It seems unlikely that Cloudflare would jeopardize their entire business model over it. Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers. Their entire value proposition is being an unobtrusive traffic intermediary.

Re: Mullvad exit IPs are surprisingly identifying

#125
post #90

Earlier quoted context omitted.

This might be a good idea, but consider banning them for, say, a couple hours at a time. It’s easy to rotate IP, especially if you’re using a residential proxy service, and there’s a good chance you’ll end up blocking real users using the same ISP.

yeah, I'm using https://proxybase.xyz for this. It's like Mullvad but for proxies. No kyc, no email but supports xmr.

Do they say how do they have access to those IPs? Most residential IPs are malware-infected devices.

Re: Mullvad exit IPs are surprisingly identifying

#126
post #103
post #87

Earlier quoted context omitted.

Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?

That’s been my pet theory from day 1, and not because of DDoS. Simply because they are the SSL terminator for most of the internet and can see anything going on in cleartext (and I’ve seen them protecting some shady stuff) I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)” If NSA aren’t installed at Cloudflare, I wonde…

DDoS is just one of the impetuses for a service provider be MiTM'd

Re: Mullvad exit IPs are surprisingly identifying

#127
post #3

VPNs are snake oil. Exit IPs are a public information.

I was just talking to a friend who believes that the feds poison privacy communities by spewing nonsense like this. I don't think wg0 is a fed, and my friend didn't have any proof for his claim. My feeling is that it is probably people acting like regular humans. They hear things, they have opinions and they don't provide proof or adhere to community norms. Eternal september or something. Regardless of if it's federa…

VPNs as marketed to "normies" is absolutely snake oil. It won't improve anyone's "privacy" in any meaningful way to simply proxy all their regular traffic through a VPN.

VPNs are a technical tool for technical people. You need to know exactly why you need it in order for it to be useful.

Re: Mullvad exit IPs are surprisingly identifying

#128
post #96

Earlier quoted context omitted.

> Wonder who can do those sudden attacks? Anyone with a few crypto currencies in their wallet that can click a button on any of the booter services with botnets for hire.

You are right, they don't have to do it themselves, but guess who's protecting the booters from other booters?

Most modern booters are not maintaining public websites that could be the object of DDoS attacks. They're renting residential IP addresses from free VPN users.

Re: Mullvad exit IPs are surprisingly identifying

#129
post #87

Earlier quoted context omitted.

Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?

Yeah, their origin is a story of absolute incredible luck. Cloudflare came out of nowhere and suddenly massive sites with huge user bases around the world, including places like 4chan, were getting DDoSed. Then they immediately announce that they transitioned to Cloudflare. Hell of a lucky time to make a company that the entire internet suddenly became absolutely dependent on. The funny thing about that era is you kn…

Am i the only one that actually remembers this time period? It wasn’t that long ago. The confidence of your assertion is completely misplaced. I remember exactly where i was when I first read about CF, on launch day. DDoS attacks were CERTAINLY a big issue before Cloudflare came along. A whole lot of script kiddie energy was poured into them. LHC? Slowloris? IRC C2? This wasn’t niche stuff. That’s why I remember the CF launch, because I and everyone else knew that it was a big deal, given what the landscape had been for quite some time. Sorry if you personally didn’t have your finger on the pulse for whatever reason, but this was far from a niche issue, even for big sites / usual targets like 4chan.

Re: Mullvad exit IPs are surprisingly identifying

#130
post #103

Earlier quoted context omitted.

That’s been my pet theory from day 1, and not because of DDoS. Simply because they are the SSL terminator for most of the internet and can see anything going on in cleartext (and I’ve seen them protecting some shady stuff) I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)” If NSA aren’t installed at Cloudflare, I wonde…

It's within the realm of possibility that NSA is collecting data with Cloudflare's consent. It seems unlikely that Cloudflare would jeopardize their entire business model over it. Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers. Their entire value proposition is being an unobtrusive traffic intermediary.

> Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers

People didn’t care when they learned about PRISM, why would they care now when it’s a known fact? The sane stance would be to assume Cloudflare is in cahoots with NSA.

Post reply on HN