Earlier quoted context omitted.
That's a specious argument, because the choice could be between logging your traffic and being forced to shutdown under some kind of Swedish NSL, or forced to keep operating and logging even if they want to shut down. Not saying this is what happened, just that your reasoning doesn't really hold. Hell it's entirely possible Mullvad is a honeypot operated by some foreign intelligence service.
There is no such laws in Sweden.
Mullvad VPN was subject to a search warrant – customer data not compromised
131–140 of 345 posts
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#132> After demonstrating that this is indeed how our service works and them consulting the prosecutor they left without taking anything Setting aside impacts on customers, I wonder how common seizures would need to be to support a purely financial case that businesses that are known to not store identifying information are therefore less likely to incur the cost and effort of scrambling to replace seized hardware.
I did notice that phrase doing a lot of work there. I'm actually super curious: when a bunch of goons turn up on your doorstep fully expecting to cart away boxes of electronics, /how on earth/ do you "demonstrate that this is indeed how our service works", there and then on the spot, in a sufficiently convincing manner that they leave again empty-handed?
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#133I don't understand why go after the VPN, I think most people don't use a VPN correctly. What good is a VPN when multiple apps on your computer are phoning home? If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP? To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to…
Even then fingerprinting would still present an issue, even without explicitly logging in, with most browsers.
For example: https://coveryourtracks.eff.org/
Also have a look at this: https://www.amiunique.org/
So you might need to have a browser that lies and presents configuration information that is common enough not to be unique, probably an OS inside of a VM might be one of the possible starting points. Outright denying access to some of that might actually help identify you, but pretending to be a common setup might not even work that well.
I'm frankly not sure whether privacy on the web is even truly possible nowadays, at least without a lot of effort. Even with a VPN, I treat the web as something that is more or less "spying" on me regardless, in the metadata collection and storage sense.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#134I don't understand why go after the VPN, I think most people don't use a VPN correctly. What good is a VPN when multiple apps on your computer are phoning home? If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP? To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to…
And yes, a lot of people use VPNs but don't use them correctly. But I'd rather help them to use them more effectively, rather than shout down that VPNs "don't work". And even when they're not used correctly, most people don't have particularly omniscient threats. And even imperfect use still helps everyone else by creating cover traffic, a fluid market for VPN services, and more evidence to websites that (IP-based) nagwalls hurt legitimate visitors.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#135Its funny, how the VPN providers basically become the avatars of the old anarchic web and the constant buisness and government overreach makes them ever stronger. Its basically a old "freedom" tax.
Tor exists though fwiw
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#136Earlier quoted context omitted.
mullvad is working on a fireware attestation system that can allow clients to verify the exact version of the software running on the server. But I think this is not fully deployed. https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur...
This is also one of the very few uses of remote attestation that I support as a consumer.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#137Earlier quoted context omitted.
Still waiting for someone to convert an international waters oil rig to a lawless data center. Or like that submarine base that Microsoft did.
Your a bit more than 20 years late with the oil rig idea https://en.m.wikipedia.org/wiki/Principality_of_Sealand
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#138Earlier quoted context omitted.
Can bet 99.99% that Mullvad throws the envelope in the trash and just forgets about it. So, yes, there is a theory that someone may go in the trash in Sweden, finds the envelope, the stamp (and it has to be a british one), investigate who bought the stamp, get the assistance of the shopkeeper in UK (without raising suspicions), successfully reviews tons of security cameras footage to find who bought, etc. And still d…
> Can bet 99.99% that Mullvad throws the envelope in the trash and just forgets about it. Better yet, they shred it: https://mullvad.net/en/help/no-logging-data-policy/#payments .
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#139> After demonstrating that this is indeed how our service works and them consulting the prosecutor they left without taking anything Setting aside impacts on customers, I wonder how common seizures would need to be to support a purely financial case that businesses that are known to not store identifying information are therefore less likely to incur the cost and effort of scrambling to replace seized hardware.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#140I don't understand why go after the VPN, I think most people don't use a VPN correctly. What good is a VPN when multiple apps on your computer are phoning home? If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP? To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to…
If your ISP suspects your IP address (can see your are connected to specific VPN server) they can just contact top websites, example: twitter, facebook or google and ask them if there are any users connected with the same IP at given specific time.
The inverse is what you're trying to prevent. Service ABC has malicious activity and calls Google to ask which accounts are accessing from that IP address. However this has two main problems.
a) Why would Google give this info over willingly.
b) Most VPN's assign the same outbound IP address to multiple users. So it's not a 1-1 mapping.
c) People who are using a VPN for something malicious are not also signed into Google.. I'd think.