Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

131–140 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#131

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

Why? If I was an intelligence agency and designing a VPN I would simply log all the IPs connecting to my VPN and not rely on statistics on exit nodes to identify the users, even more so because they rely on the users to pick different servers.

How would you claim it's a no log VPN?

Re: Mullvad exit IPs are surprisingly identifying

#132
post #50

Given that Mullvad is basically a bulletproof VPN host[1], it would be great if site operators could rely on this property to enact bans. Given that the solution is simple (add a pseudorandom seed), Mullvad will likely push out a fix within a couple days. 1. It's the preferred VPN of TeamPCP.

Source? Been googling for this but I don’t see any relevant info

oopsie, has someone burned their proprietary intel for internet points?

Re: Mullvad exit IPs are surprisingly identifying

#133

Earlier quoted context omitted.

Why? If I was an intelligence agency and designing a VPN I would simply log all the IPs connecting to my VPN and not rely on statistics on exit nodes to identify the users, even more so because they rely on the users to pick different servers.

How would you claim it's a no log VPN?

I could just...lie.

Re: Mullvad exit IPs are surprisingly identifying

#134

Earlier quoted context omitted.

You definitely need glasses then. Let me specify: The user must have entered his data on one site which the attacker has control of. That is a high bar still.

it really isn’t.

Examples?

Re: Mullvad exit IPs are surprisingly identifying

#135

Earlier quoted context omitted.

Source? Why not “I don’t want to get profiled”?

The mass surveillance industry doesn’t rely on ips or even cookies to track you.

That seems like a huge bet. I don’t bet on this, I am careful about cookies and my source IPs.

Do you have any facts? I know they really on _additional_ stuff, but do you have sources showing that they never use cookies or source IPs?

Re: Mullvad exit IPs are surprisingly identifying

#136

Earlier quoted context omitted.

> It does significantly lower the bars for identifying you though, but the requirements are still high If you squint a bit, it looks a lot like a "Nobody But US" (NOBUS[1]) scheme. A few more identifying bits could tip the scale for party that has a whole host of other bits on a list of suspects, without being useful to most other people. 1. https://en.wikipedia.org/wiki/NOBUS

Then why complicate it by being publicly insecure? If Mullvad were wanting to defeat anonymity, they could simply log the traffic metadata while falsely advertising they aren't. Their ads on San Francisco's public transit are good.

"public insecure" JFC

Security is always a balance. Always

AI is showing that everything has a weak spot (wondering where are the "I don't make mistakes with C" now people are - but that's for another discussion)

There's another commenter mentioning this makes sense because exactly it avoids them keeping information on which customer is matched to which server. You know, one of the things you don't want to log

Could it be done better? Probably.

Here's a better idea, logging off is 100% safe

Meanwhile 99% of the normies will go for NordVPN

Re: Mullvad exit IPs are surprisingly identifying

#137

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

In this particular case I'm quite sure it's not the case. Good arguments in the other comments (why not just log more if that's the case), but I also happen to know a little bit about the workings of Mullvad (I live in Gothenburg where they're from...)

Re: Mullvad exit IPs are surprisingly identifying

#138

Earlier quoted context omitted.

"EU explicitly required that ISPs retain your identifying data with the Data Retention Directive" And then sells it?

What gives you confidence that they aren't? I have confidence my VPN doesn't sell my traffic not because I implicitly trust what they say, but because if they had logs the courts would have found them when trying to seize data themselves. What makes you trust your ISP so much? Faith in the human goodness of businesses to look out for the best interests of their customers, even if it means passing up an opportunity to…

"What gives you confidence that they aren't?"

   What gives you the confidence that Bigfoot does not exist?
   What gives you the confidence we're not ruled by Reptile overlords?
   What gives you the confidence we're not just in the Matrix and nothing matters?
   What gives you the confidence you're not just a dream by a dog in Sicily?
   What gives you the confidence I even exist and you're not talking to yourself?
You're entitled to your conspiracy theories and paranoia of course, but it's not an argument.

Re: Mullvad exit IPs are surprisingly identifying

#139
post #80

The purpose of a VPN does not include anonymizing users with respect to the sites they visit,so it shouldn't be too surprising that Mullvad doesn't enforce unique exit IPs. Users who want anonymity should use networks like Tor.

That is exactly the point of public VPNs.. If I'm on a public VPN, I don't want anyone to know who is making the request, including the terminating IP. Think about it. By your logic, VPNs shouldn't be used for torrents because VPNs shouldn't anonymize you to the terminating IP. Whereas they work gangbusters for that. If you are talking about private VPNs.. Mullvad isn't one.

Public VPNs only protect you from your ISP

Re: Mullvad exit IPs are surprisingly identifying

#140

The purpose of a VPN does not include anonymizing users with respect to the sites they visit,so it shouldn't be too surprising that Mullvad doesn't enforce unique exit IPs. Users who want anonymity should use networks like Tor.

Why not? Why can’t it be the purpose of a given VPN service?

If you use the VPN for the Web, browser fingerprinting is a major threat outside of specialized scenarios
Post reply on HN