Live data from Hacker News

WireGuard multihop available in the Mullvad app

mullvad.net

131–140 of 141 posts

Re: WireGuard multihop available in the Mullvad app

#131

Earlier quoted context omitted.

> pull out the RAM and grab encryption keys in clear text How to defend against this?

there are methods to store keys in RAM in encrypted form and decrypt them only on the cache and CPU registers

Talked about a bit here: https://youtu.be/pKeiKYA03eE?t=963

Using debug registers to hold an AES key purely in the CPU is genius.

Re: WireGuard multihop available in the Mullvad app

#132
post #22

Earlier quoted context omitted.

I would think you'd do the exact opposite. If you leave a computer running anyone (Well "anyone" being a skilled adversary) can simply pull out the RAM and grab encryption keys in clear text. Law enforcement does this so often, it's practically routine. The only "safe" system is one that has been long powered off and is using tried and true cryptography, ideally open-source FDE that's been fully audited.

Mullvad is fully open source, with the source code provided here [1], which has also undergone multiple rounds of audits with the reports available to the public [2][3]. [1] https://github.com/mullvad [2] https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leak... [3] https://cure53.de/pentest-report_mullvad_2021_v1.pdf

It's a shame the API isn't open though. I maintain a Terraform provider for it, but it has to come with a fat warning that it can break due to (reversed) API changes, and that fixing it may require breaking changes or even not be feasible etc.

Re: WireGuard multihop available in the Mullvad app

#133

Earlier quoted context omitted.

I would think you'd do the exact opposite. If you leave a computer running anyone (Well "anyone" being a skilled adversary) can simply pull out the RAM and grab encryption keys in clear text. Law enforcement does this so often, it's practically routine. The only "safe" system is one that has been long powered off and is using tried and true cryptography, ideally open-source FDE that's been fully audited.

> can simply pull out the RAM and grab encryption keys in clear text Leaving aside the leg work "simply" does here, especially in a coffee shop environment: would AMD's "encrypted memory" help against these kinds of attacks? I have a laptop with an AMD Zen 3 Pro CPU that has this option in the BIOS and was wondering whether it actually did any good, as opposed to being just some marketing shtick.

Interesting, I didn't know this was a thing, but after some cursory research it does seem like part of its use case is to stop this attack vector.

Re: WireGuard multihop available in the Mullvad app

#134
post #91
post #68

Earlier quoted context omitted.

Here's the latest Mullvad security audit (June 2020). https://cure53.de/pentest-report_mullvad_2020_v2.pdf

Unless I'm mistaken that's just a security audit of their client applications, which would not in any way prove that they aren't logging.

You are correct. I don't use Mullvad and had assumed this was an audit of their infrastructure, not their app. Thanks for pointing that out.

Re: WireGuard multihop available in the Mullvad app

#135

I'm a happy Mullvad user. But I have one concern. Recently, Instagram "tagged" my account as either based in Russia or using Russian currency. I'm based in Western EU and set up the VPN to connect to the same country or neighboring ones. I'm trying to figure out if some endpoints belonging to Mullvad have been shadowbanned by Meta/Instagram. Is there someone else who uses Mullvad to surf on Meta products whose accoun…

I use Mullvad and I constantly run into things like ASN bans etc. For example, cloudflare often bans whole ASN making many websites not accessible through Mullvad. Seems like mullvad is being used by a lot of bad actors and they're not really doing anything about it. I like their software and monetization but their IPs are probably the lowest quality IPs in the VPN market.

It's a bit odd to indict Mullvad for not doing anything about nefarious actors using their service, as the whole selling point of their service is that they don't keep track of who is up to what. If they start policing user traffic, I will cancel my service, and I'm sure many others would to.

FWIW I run my own VPN server on a common cloud provider, and I actually encounter more trouble there than when I'm logged into Mullvad. I think the services who can't think of more creative solutions than blanket IP bans are the real problem here.

Re: WireGuard multihop available in the Mullvad app

#136
IVPN has wireguard multihop since a while I believe: https://www.ivpn.net/knowledgebase/general/what-is-a-multiho...

The iOS app has been more reliable than the mullvad app so far, which is the reason I switched. Additionally, it allows to configure "trusted" and "untrusted" networks, which is quite useful as well. (And yes, this is not a secure feature, as a network can easily be spoofed, but I use IVPN mostly for data privacy and not for safety/security reasons)

Re: WireGuard multihop available in the Mullvad app

#137

Earlier quoted context omitted.

Hey I’m curious about the terminology you guys are using here. Is there a manual or a page which I can read to learn more about wireguard profiles and what mullvad has done for them perhaps?

Search HN re Wireguard. It's a much more secure, efficient, and very widely respected. Linus has integrated it into the kernel, for example.

Linus has integrated more than a few questionable things into the kernel so that’s not a ringing endorsement for me. Perhaps it’s a good implementation for the new standard, perhaps not. Regardless, I want to say to you that I appreciate your comment and I’m going to go off and do some further research before I begin to have an opinion.

Re: WireGuard multihop available in the Mullvad app

#138

Earlier quoted context omitted.

Yes, indeed, if there is identifiable traffic coming from the OS, you're screwed. This is why I said "not all traffic is indeed personally identifiable". If you are doing things where you have to be anonymous, there are plenty of OSes you can run to not have all those things giving away your identity. If you think just adding a VPN on top of the OS you use for other things, you're screwed. I think you're missing the…

The point was exactly that – you are already screwed, irrespective of being able to pay anonymously. If you are the kind of actor who will (or needs to) take all the countermeasures needed to be truly anonymous at a whole machine traffic level, then you are likely not going to be using mullvad. To a typical customer of mullvad who also reads hn I would say this – you aren't going to gain any additional privacy by usi…

> If you are the kind of actor who will (or needs to) take all the countermeasures needed to be truly anonymous at a whole machine traffic level, then you are likely not going to be using mullvad.

That's the wrong conclusion. The right one is: if you're the kind of actor who needs 100% privacy, mullvad is likely a part of solution (because of their track record), together with many other services and tooling. No one relies on one part to remain anonymous, as again, privacy and security depends on layers, not just a single layer.

> either you believe Sweden is a safe haven for user data privacy or not.

Even if Sweden is "a safe haven for user data privacy" or not, the government is not the only threat against mullvad. Mullvad themselves, the location they have their servers, their payment processors and many else can also be compromised. Paying Mullvad in cash (and protecting yourself in more ways) helps more than paying with a credit card attached to your full name, as any middleman can be compromised (and not just by a government).

> For truly high-risk people (journalists/whistleblowers against powerful entities, not regular geeks who want to block ad tracking), I'm not sure if any vpn service like this is a net help or does it actually cause more harm.

High-risk people don't rely on a single VPN service but again, layers of them in order to facilitate things like proxy chaining and multi-hop.

But, talking with you back and forward, makes it clear that you haven't actually engaged with any of these "high-risk people" you feel so sure to proclaim how things work for. I urge to actually talk to some of them and see what kind of setup they can tell you about, as you'll learn some more about how you can protect yourself and remain anonymous, if you really want to.

Re: WireGuard multihop available in the Mullvad app

#139
post #38
post #21

Tangentially related: Users can use Mullvad’s TOR address: http://o54hon2e2vj6c7m3aqqu6uyece65by3vgoxxhlqlsvkmacw6a7m7k... to generate their account ID and make their payment with Bitcoin seamlessly. I have never experienced such a smooth way to purchase from a provider, this was brilliant. +1 to Mullvad

The ease with which you can pay anonymously makes me feel that its more likely a genuine privacy provider rather than a CIA run honeypot like Crypto AG.

Bitcoin is not private but many people don't know this, and they refuse to accept Monero, so I follow the same logic but come to the opposite conclusion.

Re: WireGuard multihop available in the Mullvad app

#140

This isn't Tor-like multi-hop (but is similar to other multi-hop VPN providers out there). A proper multi-hop would happen across two different vendors in control of two different networks, as it were. The iCloud Relay paper outlined a pretty private and secure design [0] (and the intention to standardize it via IETF would probably make it simpler to self-host such a solution [1][2]). Among the VPNs, orchid.com's dis…

For what its worth I have used the open source Tinc VPN [1] for mesh multihop routing for ages. It is nowhere near as fast as Wireguard but I could envision Tinc incorporating support for Wireguard if the author were so inclined. Like you mentioned Tinc does not mesh directly with other VPN's AFAIK. I've had to use route statements to join it with Strongswan and other VPN networks.

[1] - https://tinc-vpn.org/

Post reply on HN