Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

131–140 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#131
post #93

Given that it's in the West I still think it's probably NSA compromised, but I'm not nearly important enough for the government to blow their cover about.

That's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's. If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.

Perhaps for some indication on how much "they're not gods" is, its worth looking at the things the CIA did to try and assassinate Castro (as well as any of the shenanigans they did during the cold war, including trying to train cats with spy sensors in them to wander into a Soviet embassy - that one failed because it took too long to train and their one successful cat was driven over by a taxi when set loose on the street across the embassy).[0]

Its less "super top secret spy agency hires a hitman to take out Castro" and more "we're just going to throw whatever we can at the wall and see what works". Plans included literally mailing him exploding cigars (on the assumption that Castro liked smoking so mailing him one might just work), hiring his ex to try and kill him on a plane ride (which just resulted in the ex rebounding with Castro) and some campaigns to try and make him look weak that can only be described as "hilarious" like flying a plane over the country and dropping leaflets with a bounty of 0.02$ on his head with the idea that he was so weak that the bounty wasn't worth anything (although this one was rejected, they also attempted to make him look foolish by lacing a radio broadcast room with LSD).[1]

To pull a quote from Alan Moore: "If you are on a list targeted by the CIA, you really have nothing to worry about. If however, you have a name similar to somebody on a list targeted by the CIA, then you are dead."

[0]: https://en.m.wikipedia.org/wiki/Acoustic_Kitty

[1]: https://en.m.wikipedia.org/wiki/CIA_assassination_attempts_o...

Re: Infrastructure audit completed by Radically Open Security

#132
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

> They don't store any contact information that could be used to warn customers, so my connection mysteriously failed one day This situation seems avoidable: what if the payment/signup flow had a big loud warning that you need to configure your own polling of an RSS endpoint using a client capable of pinging you?

That's honestly a great idea for an alternative to newsletters... it would be nice if there was better first-party RSS support (what about in the email client?) since I don't think any OSs have it, because right now that would probably confuse most customers

Re: Infrastructure audit completed by Radically Open Security

#133
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

I’m a network newbie so I have no idea about the importance of this. I have done port forwarding in my router before, mainly so I can access my Plex system outside of my house. I used to setup port forwarding when torrenting but I have realized that I can still get my Linux ISOs without it. I never cared even though I’m a heavy user of their product. When will it start to affect me, or in other words, what use cases…

You'd need that feature if you desired to host an actual service (a webserver for example) behind the VPN

Re: Infrastructure audit completed by Radically Open Security

#134
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

I’m a network newbie so I have no idea about the importance of this. I have done port forwarding in my router before, mainly so I can access my Plex system outside of my house. I used to setup port forwarding when torrenting but I have realized that I can still get my Linux ISOs without it. I never cared even though I’m a heavy user of their product. When will it start to affect me, or in other words, what use cases…

[deleted]

Re: Infrastructure audit completed by Radically Open Security

#135
post #93

Earlier quoted context omitted.

That's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's. If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.

> their total budget is a fraction of Big Tech's The NSA was getting $10.5bn to spend in 2013[0]. I can only imagine it's gone up since then year on year. That's not a bad fraction when your whole goal is signals intelligence. [0] https://www.washingtonpost.com/world/national-security/black...

Volkswagen's research budget was $21 billion in 2022. $10.5bn is nothing in the big picture, and certainly not enough to "control the world" or whatever grand claims are commonly made about the NSA.

Re: Infrastructure audit completed by Radically Open Security

#136
post #2

My biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my profess…

FYI it seems they are still looking for people. They are advertising on buses here in Gothenburg.

Re: Infrastructure audit completed by Radically Open Security

#137
post #132

Earlier quoted context omitted.

> They don't store any contact information that could be used to warn customers, so my connection mysteriously failed one day This situation seems avoidable: what if the payment/signup flow had a big loud warning that you need to configure your own polling of an RSS endpoint using a client capable of pinging you?

That's honestly a great idea for an alternative to newsletters... it would be nice if there was better first-party RSS support (what about in the email client?) since I don't think any OSs have it, because right now that would probably confuse most customers

The likelihood of being confused by rss among mullvad customers can't be very high.

Re: Infrastructure audit completed by Radically Open Security

#138

Earlier quoted context omitted.

Yup. As a Cuban, sometimes it is annoying and sometimes go beyond that. Some cloud providers are totally off limits for us, some are fine with us (the minority and less known), some let us use some services but no others, some even have valid OFAC licenses but still deny access (because ACL complexities, I suppose)... it's all over the place. That's why I'm 95% of the time on crappy VPNs both to escape/evade US sanct…

> Anyway, and sadly, the sanctions affect "regular" people like me the most. The ruling elite? Not at all. This confirms my secondhand knowledge of financial sanctions. It seems to universally be this way and makes me wonder why we still tout them as if they were effective. They sure don’t seem to be.

That’s a very broad statement, almost automatically untrue. All countries, all situations, all financial sanctions?

Re: Infrastructure audit completed by Radically Open Security

#139
post #99
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

Have you found a replacement? I did some light investigation but nothing really felt as solid as Mullvad so I haven't jumped ship yet.

Not that person but I've spinned a 1984 instance paid with bitcoin without KYC. Then setup nat+rdr rules that foward to my service through a wireguard tunnel.

Re: Infrastructure audit completed by Radically Open Security

#140
post #99
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

Have you found a replacement? I did some light investigation but nothing really felt as solid as Mullvad so I haven't jumped ship yet.

None as solid, no. My needs are fairly specific (exit node in a specific country, torrent-friendly, good speed, not too expensive, not too shady, first-party support for my OS'es, doesn't have to be government-proof), so you'll need to do your own research.

For what's worth, I eventually went with Proton VPN, but it's more expensive and gives a used-car-salesman feeling.

Post reply on HN