Live data from Hacker News

Mullvad VPN was subject to a search warrant – customer data not compromised

mullvad.net

131–140 of 345 posts

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#131
post #124
post #95

Earlier quoted context omitted.

That's a specious argument, because the choice could be between logging your traffic and being forced to shutdown under some kind of Swedish NSL, or forced to keep operating and logging even if they want to shut down. Not saying this is what happened, just that your reasoning doesn't really hold. Hell it's entirely possible Mullvad is a honeypot operated by some foreign intelligence service.

There is no such laws in Sweden.

That does not appear to be factual: https://www.riksdagen.se/sv/dokument-lagar/dokument/svensk-f...

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#132
post #97

> After demonstrating that this is indeed how our service works and them consulting the prosecutor they left without taking anything Setting aside impacts on customers, I wonder how common seizures would need to be to support a purely financial case that businesses that are known to not store identifying information are therefore less likely to incur the cost and effort of scrambling to replace seized hardware.

I did notice that phrase doing a lot of work there. I'm actually super curious: when a bunch of goons turn up on your doorstep fully expecting to cart away boxes of electronics, /how on earth/ do you "demonstrate that this is indeed how our service works", there and then on the spot, in a sufficiently convincing manner that they leave again empty-handed?

I'm wondering this as well and I haven't seen a sufficiently good explanation yet. I know they've done audits of different kinds over the years, I've read up about their infrastructure and the way they run their services, but I don't realistically see any of that being enough of an argument, right there on the spot, when the police turn up with a warrant. What could they possibly have demonstrated and how?

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#133

I don't understand why go after the VPN, I think most people don't use a VPN correctly. What good is a VPN when multiple apps on your computer are phoning home? If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP? To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to…

> To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to hide?

Even then fingerprinting would still present an issue, even without explicitly logging in, with most browsers.

For example: https://coveryourtracks.eff.org/

Also have a look at this: https://www.amiunique.org/

So you might need to have a browser that lies and presents configuration information that is common enough not to be unique, probably an OS inside of a VM might be one of the possible starting points. Outright denying access to some of that might actually help identify you, but pretending to be a common setup might not even work that well.

I'm frankly not sure whether privacy on the web is even truly possible nowadays, at least without a lot of effort. Even with a VPN, I treat the web as something that is more or less "spying" on me regardless, in the metadata collection and storage sense.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#134

I don't understand why go after the VPN, I think most people don't use a VPN correctly. What good is a VPN when multiple apps on your computer are phoning home? If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP? To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to…

I personally use a bunch of VMs for web browsing, all with different exit IPs.

And yes, a lot of people use VPNs but don't use them correctly. But I'd rather help them to use them more effectively, rather than shout down that VPNs "don't work". And even when they're not used correctly, most people don't have particularly omniscient threats. And even imperfect use still helps everyone else by creating cover traffic, a fluid market for VPN services, and more evidence to websites that (IP-based) nagwalls hurt legitimate visitors.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#135

Its funny, how the VPN providers basically become the avatars of the old anarchic web and the constant buisness and government overreach makes them ever stronger. Its basically a old "freedom" tax.

Tor exists though fwiw

Tor exists, but realistically the overhead of using Tor is not acceptable to the general public. As long as Tor is sufficiently slow compared to everyday traffic it will remain a niche use case. A good VPN on the other hand gives you at least a little bit of privacy without much of a cost.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#136

Earlier quoted context omitted.

mullvad is working on a fireware attestation system that can allow clients to verify the exact version of the software running on the server. But I think this is not fully deployed. https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur...

This is also one of the very few uses of remote attestation that I support as a consumer.

Some places passed laws during the pandemic allowing for the execution of a will using witnesses connected via video link. How does that sit with you

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#137

Earlier quoted context omitted.

Still waiting for someone to convert an international waters oil rig to a lawless data center. Or like that submarine base that Microsoft did.

Your a bit more than 20 years late with the oil rig idea https://en.m.wikipedia.org/wiki/Principality_of_Sealand

[deleted]

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#138
post #112
post #90

Earlier quoted context omitted.

Can bet 99.99% that Mullvad throws the envelope in the trash and just forgets about it. So, yes, there is a theory that someone may go in the trash in Sweden, finds the envelope, the stamp (and it has to be a british one), investigate who bought the stamp, get the assistance of the shopkeeper in UK (without raising suspicions), successfully reviews tons of security cameras footage to find who bought, etc. And still d…

> Can bet 99.99% that Mullvad throws the envelope in the trash and just forgets about it. Better yet, they shred it: https://mullvad.net/en/help/no-logging-data-policy/#payments .

It would be better to burn those envelopes than shred them, IMO.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#139
post #97

> After demonstrating that this is indeed how our service works and them consulting the prosecutor they left without taking anything Setting aside impacts on customers, I wonder how common seizures would need to be to support a purely financial case that businesses that are known to not store identifying information are therefore less likely to incur the cost and effort of scrambling to replace seized hardware.

After getting a call from the CIA to leave their honeypot alone, they left without taking anything ;-)

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#140

I don't understand why go after the VPN, I think most people don't use a VPN correctly. What good is a VPN when multiple apps on your computer are phoning home? If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP? To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to…

If your ISP suspects your IP address (can see your are connected to specific VPN server) they can just contact top websites, example: twitter, facebook or google and ask them if there are any users connected with the same IP at given specific time.

This is a confusing take to me. So my ISP which has my billing information is trying to find out who I am by calling Google? They know who I am.

The inverse is what you're trying to prevent. Service ABC has malicious activity and calls Google to ask which accounts are accessing from that IP address. However this has two main problems.

a) Why would Google give this info over willingly.

b) Most VPN's assign the same outbound IP address to multiple users. So it's not a 1-1 mapping.

c) People who are using a VPN for something malicious are not also signed into Google.. I'd think.

Post reply on HN