Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

141–150 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#141

Earlier quoted context omitted.

Fair point, but I'm not sure if that was ever a boundary they wouldn't cross, but for 'a little while now' I'd say it doesn't matter. From outside the US I should be using a VPN end-point within the US, so that my browsing traffic doesn't hit the NSA - only my encrypted VPN traffic does.

> my browsing traffic doesn't hit the NSA - only my encrypted VPN traffic does I mean, let's be real. All known US VPN servers and Tor exit nodes--and probably all US Tor relays regardless of exit policy--are going to be considered a totally legitimate "communications facility" target for the warrantless wiretapping system due to exactly the scenario you just posited. From that perspective you'd be better off using U…

> NSA just does whatever they want, laws be damned, and are almost certainly logging everything

When you share the evidence for this, it will be international news.

Re: Mullvad exit IPs are surprisingly identifying

#142

Earlier quoted context omitted.

> I don't care if they know I use mullvad, I care they don't know I'm me That's exactly what the article is about, a side channel information leak that de-anonymises users, did you read it?

Can it get my IP? I'll go ahead and answer that it can't. It knows I'm mullvad user X, thus deanonimization, "it knows I use mullvad", but it doesn't know my original IP, so "it doesn't know I'm me".

I'm not sure what you're going for, your ISP-assigned IP doesn't tell them your legal name either.

But when you connect to the site from via server A and later via server B they can tell that you're the same person.

And they can deanonymise you through data brokers. All Mullvad IPs are traceable back to the same number (acting as a pseudo account identifier) so if you ever entered your PII on any website when using Mullvad, it can be linked to the same Mullvad account.

And if you ever visited any of those sites without using a VPN, your home IP can be linked to your Mullvad ID through browser fingerprinting.

And if you ever entered any PII on any website from your home IP, you can once again be deanonymised.

Now the existence of browser fingerprinting isn't Mullvad's fault, but this flaw makes it a lot easier to accidentally deanonymize yourself.

Re: Mullvad exit IPs are surprisingly identifying

#145
post #3

VPNs are snake oil. Exit IPs are a public information.

VPNs are not snake oil. They transfer the trust of your internet activity from a place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad, IVPN, or Proton. Among other benefits. If you don't like your ISP creating a profile of you and selling it to target ads to you, you should use a VPN. >Should I use a VPN? Yes, almost certainly. A VPN has many advantages, including: 1. Hiding…

Marcus Hitchens (security researcher who blackholed the WannaCry ransomware domain) made a post on LinkedIn today comparing VPNs to snake oil. With regard to the way they're advertised in internet ads, they are. VPNs will not protect ordinary users from ad tracking or commercial data mining. They're marketed as a privacy tool when their privacy value is very limited.

VPNs are useful for the reasons you mentioned.

Re: Mullvad exit IPs are surprisingly identifying

#146
post #3

VPNs are snake oil. Exit IPs are a public information.

VPNs are not snake oil. They transfer the trust of your internet activity from a place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad, IVPN, or Proton. Among other benefits. If you don't like your ISP creating a profile of you and selling it to target ads to you, you should use a VPN. >Should I use a VPN? Yes, almost certainly. A VPN has many advantages, including: 1. Hiding…

> 4. Allowing you to bypass geo-restrictions on certain content.

In theory, but as someone who uses Mullvad in the UK on a day-to-day basis on my personal laptops (not my phone) - I'm using it now, I'm afraid there's quite an additional downside I've found, in that because Mullvad's (at least UK, but also French and Dutch ones I've tried) exit IPs are known, many companies (Cloudflare, Akamai) at the very least know about them, and several sites block access when using Mullvad, returning 403s.

Santander bank for example, I can't always (sometimes I can) connect to when using Mullvad, and sometimes have to turn it off, as I get 403 responses from the bank otherwise (using Firefox).

Sometimes using IPv6 in the Mullvad settings gets around this, but more and more recently I've found it doesn't, so there sites where I'm having to stop using Mullvad to actually access sites.

(I'm still a happy customer, and 1 to 3 are still true and why I use it otherwise).

Re: Mullvad exit IPs are surprisingly identifying

#147

Earlier quoted context omitted.

Why? If I was an intelligence agency and designing a VPN I would simply log all the IPs connecting to my VPN and not rely on statistics on exit nodes to identify the users, even more so because they rely on the users to pick different servers.

How would you claim it's a no log VPN?

Their 3rd party audit didn’t catch this…

I guess we’ll see how they respond.

Re: Mullvad exit IPs are surprisingly identifying

#148
post #130

Earlier quoted context omitted.

It's within the realm of possibility that NSA is collecting data with Cloudflare's consent. It seems unlikely that Cloudflare would jeopardize their entire business model over it. Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers. Their entire value proposition is being an unobtrusive traffic intermediary.

> Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers People didn’t care when they learned about PRISM, why would they care now when it’s a known fact? The sane stance would be to assume Cloudflare is in cahoots with NSA.

All the companies involved in PRISM made public statements saying they ceased participation. Google undertook a costly initiative to add encrypted connections over their datacenter circuits. The NSA leaks were a forcing function that led to a massive uptake of encryption. Up until that point it was common for websites to support only HTTP.

The NSA leaks dominated news cycles for the entirety of 2013.

Re: Mullvad exit IPs are surprisingly identifying

#149
post #65

Earlier quoted context omitted.

Makes you wonder...

Every now and then there are articles like this one about something that Mullvad may or may not be able to do better, and there are always comments about whether they're an intelligence front. I don't know the answer, but there are two ways to take it: 1. Submarining to destroy confidence in an actually trustworthy, decent VPN company 2. They're an intelligence front. For me, Mullvad have the appearance of the greate…

You'll find comments accusing anything of being an intelligence front on internet message boards. I agree with you that public evidence is overwhelmingly in favor that Mullvad is earnestly trying to protect privacy.

Re: Mullvad exit IPs are surprisingly identifying

#150
post #113

Earlier quoted context omitted.

> You can't use VPNs or Mullvad for anything mission critical. Just try to log in to your bank in US, it will increase your risk score on their end because VPNs by nature is very easy to detect whereas "residential proxies" much harder. Naturally! I’m just saying there’s residential proxy providers that are a LOT cheaper than that. (IIRC, you can usually reply to fresh comments if you click on the “n minutes ago” – t…

I think when it comes to privacy or XMR, money is not really that important. Just give me a few names that support XMR payments + no KYC and providing mostly non-flagged residential IPs that you can use them for mission critical stuff.

That’s a good question! I haven’t been in this scene for a long long time now, so can’t say for sure.

I’ve been implementing an Instagram liker service back in... 2018 was it? So a stable pool of non-flagged residential proxies was important here, and it was my client who introduced me to the concept of “mobile proxies”. Basically, they use regular 3G/4G/5G modems with regular SIM cards, and expose that as a SOCKS proxy. You get a normal-looking IP from a pool of mobile operator’s IPs. Since mobile devices reconnect all the time (and are behind a CGNAT mostly nowadays), you can’t really flag an IP like that – and if it is flagged, you can get a fresh one in a moment.

I’m not using this mostly because I’m too lazy to research. Here’s a random one I found (so not an endorsement!) which is $1/GB, seems to only require email to sign up, and takes crypto (including XMR): https://floppydata.com/

Post reply on HN