Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

151–160 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#151
post #130

Earlier quoted context omitted.

> Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers People didn’t care when they learned about PRISM, why would they care now when it’s a known fact? The sane stance would be to assume Cloudflare is in cahoots with NSA.

All the companies involved in PRISM made public statements saying they ceased participation. Google undertook a costly initiative to add encrypted connections over their datacenter circuits. The NSA leaks were a forcing function that led to a massive uptake of encryption. Up until that point it was common for websites to support only HTTP. The NSA leaks dominated news cycles for the entirety of 2013.

my llm api traffic terminates tcp at cloudflare in lovely plain text :/

it does give better peering. reduces latency a bit for me.

Re: Mullvad exit IPs are surprisingly identifying

#153

Earlier quoted context omitted.

What gives you confidence that they aren't? I have confidence my VPN doesn't sell my traffic not because I implicitly trust what they say, but because if they had logs the courts would have found them when trying to seize data themselves. What makes you trust your ISP so much? Faith in the human goodness of businesses to look out for the best interests of their customers, even if it means passing up an opportunity to…

"What gives you confidence that they aren't?" What gives you the confidence that Bigfoot does not exist? What gives you the confidence we're not ruled by Reptile overlords? What gives you the confidence we're not just in the Matrix and nothing matters? What gives you the confidence you're not just a dream by a dog in Sicily? What gives you the confidence I even exist and you're not talking to yourself? You're entitle…

It's a conspiracy theory to observe reality now? It is a known factor that ISPs in general sell data, even if there isn't smoking gun proof for every single individual ISP (...just as there isn't smoking gun proof for every individual VPN). If you want to take the piss, at least get it right -- you're denying the existence of one individual Bigfoot after 100 other specimens of the Bigfeetian species have been found and conclusively proven to exist. Jesus, the complete disregard for common sense and privacy of even the tech-inclined members of the general public never ceases to amaze me.

Re: Mullvad exit IPs are surprisingly identifying

#154
post #103

Earlier quoted context omitted.

That’s been my pet theory from day 1, and not because of DDoS. Simply because they are the SSL terminator for most of the internet and can see anything going on in cleartext (and I’ve seen them protecting some shady stuff) I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)” If NSA aren’t installed at Cloudflare, I wonde…

It's within the realm of possibility that NSA is collecting data with Cloudflare's consent. It seems unlikely that Cloudflare would jeopardize their entire business model over it. Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers. Their entire value proposition is being an unobtrusive traffic intermediary.

Within the realm of possibility? Let's be honest, if you are a top NSA executive and you couldn't find a way to get your hands on Cloudflare's private keys (bribing or threatening the right person), you are not getting your Christmas bonus.

Re: Mullvad exit IPs are surprisingly identifying

#156
post #80

Earlier quoted context omitted.

That is exactly the point of public VPNs.. If I'm on a public VPN, I don't want anyone to know who is making the request, including the terminating IP. Think about it. By your logic, VPNs shouldn't be used for torrents because VPNs shouldn't anonymize you to the terminating IP. Whereas they work gangbusters for that. If you are talking about private VPNs.. Mullvad isn't one.

I think you are misreading his comment. He is saying that on a VPN it is standard behavior that if you visit site A and site B they will both see you connecting from the same IP and can infer you are potentially the same person.

Site A and B have to collude in order to make that inference. Outside of Cloudflare, no one is colluding at that level.

Re: Mullvad exit IPs are surprisingly identifying

#158

Earlier quoted context omitted.

How would you claim it's a no log VPN?

I could just...lie.

One person can tell a lie, but a company consists of many people. You must ensure that only few people know of the logging or there will be a risk of a leak.

Re: Mullvad exit IPs are surprisingly identifying

#159
post #90

Earlier quoted context omitted.

This might be a good idea, but consider banning them for, say, a couple hours at a time. It’s easy to rotate IP, especially if you’re using a residential proxy service, and there’s a good chance you’ll end up blocking real users using the same ISP.

yeah, I'm using https://proxybase.xyz for this. It's like Mullvad but for proxies. No kyc, no email but supports xmr.

Is this your service? Since you've made seven posts to HN about it and also your username shows up in the commits on their GitHub.

Because I'm quite curious on where the IPs are from. Usually residential IPs is a fancy wording for malware infested devices from regular people.

Re: Mullvad exit IPs are surprisingly identifying

#160

Earlier quoted context omitted.

> It does significantly lower the bars for identifying you though, but the requirements are still high If you squint a bit, it looks a lot like a "Nobody But US" (NOBUS[1]) scheme. A few more identifying bits could tip the scale for party that has a whole host of other bits on a list of suspects, without being useful to most other people. 1. https://en.wikipedia.org/wiki/NOBUS

Then why complicate it by being publicly insecure? If Mullvad were wanting to defeat anonymity, they could simply log the traffic metadata while falsely advertising they aren't. Their ads on San Francisco's public transit are good.

Good VPNs tout the fact that they had nothing to give in response to a subpoena, or that there was nothing a law enforcement agency to find when they seized a server. For mullvad to be effective as a honey pot it needs to survive these events with its reputation in tact.
Post reply on HN