Live data from Hacker News

Mullvad VPN was subject to a search warrant – customer data not compromised

mullvad.net

161–170 of 345 posts

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#161

Earlier quoted context omitted.

All standard British stamps now have unique Data Matrix codes on them, which means you also have to source your stamps anonymously.

Wait what? If you go to the post office and pay with your debit card, how exactly do they figure out who you are based on the stamp?

If they scan the stamp's code at time of purchase, and associate it with your debit card, that'd be an obvious way of tracking you.

If they don't do that, if they meet the stamp along the letter's journey, they can scan the code and check which batch it's from, and there could be a database of which post office got which batch, and then it's a matter of checking that post office's purchases/security cameras.

If all stamps are indistinguishable from each other, then you could've bought the stamp months ago on the Isle of Skye and used it in London, they wouldn't be able to tell the difference.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#162
post #88

Earlier quoted context omitted.

They also have vouchers you can buy from Amazon, which I find a nice alternative to sending cash in an envelope.

At that point, you can probably just pay by credit card: If your aim is to frustrate invasive ad trackers and profilers on the web (and you assume that Mullvad isn't outright colluding with these), that should be good enough to break any links. On the other hand, if you don't trust Mullvad's assertion that they delete the link between accounts and credit card payment records after 40 days [1], what makes you think yo…

I think it goes something like this:

If your worried about anything in a 40 day window the credit card account_id is a liability

Amazon doesn’t know the redemption code on the gift card. So Amazon knows that you purchased a Mullvad gift card, but can’t associate the transaction with a Mullvad account. Likewise Mullvad knows service was paid for with a gift card (possibly that the gift card is from a lot sold on Amazon). But they do not know which Amazon transaction the card is associated with.

Unless your behavior and the behavior of others deanonymizes the Amazon purchase redemption your account should be indistinguishable from any other that purchased a Mullvad gift card from Amazon in that window of time.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#163

Earlier quoted context omitted.

> there are plenty of vpn's who run on fake marketing that give the impression that they have certain values and do certain things while actually not doing it and they are way more successful than mullvad. Yes, but Mullvad also doesn’t whore themselves out to any YouTuber that will accept a sponsorship agreement. I’ve never seen an ad for them. I’ve only heard of them from people who tell me they’re the best. Of cour…

pretending you don't need trust when you actually do is a vulnerability. of course you need to trust that mullvad is doing what they actually say they are doing. there is literally no way for you to verify everything they claim.

And yet you trust WhatsApp and Facebook and Signal with their claims of end-to-end encryption. Why?

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#164
post #131

Earlier quoted context omitted.

That does not appear to be factual: https://www.riksdagen.se/sv/dokument-lagar/dokument/svensk-f...

What do you mean? Lag 2008:717 does not contain any provisions about forcing companies to log or store data. Rättegångsbalken does have a provision that a prosecutor can order you to preserve information you already have saved for a maximum of 180 days ( https://lagen.nu/1942:740#K27P16S1 ). I can't find anything about what the punishment for ignoring such an order would be, but to say a company could be forced to ke…

Try this one [1] which contains an obligation for operators to comply and maintain secrecy. I'm not a lawyer, and definitely not a swedish lawyer, but my point is, despite baked in protections, like most countries, Sweden seems to have a robust set of overlapping national security and surveillance laws.

[1] https://lagen.nu/prop/2006/07:63

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#165
I've been a Mullvad customer for some time and I'm quite satisfied. But the main issue I have is that many of its servers are blacklisted by Cloudflare and other services. Because Mullvad provides the strongest anonymity a VPN can provide, it attracts not only normal users, but also malicious users (scammers, hackers, or less malicious but more numerous scrappers).

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#167
post #75

Earlier quoted context omitted.

> Technically they could have been logging your traffic Of course they “could have” but their entire business depends on them not doing it.

mullvad has time and again shown itself to be one of if not the best actors in the entire vpn space, but you still have no real way of knowing if they are being honest. also their business definitely doesn't depend on being honest or standing for their values. there are plenty of vpn's who run on fake marketing that give the impression that they have certain values and do certain things while actually not doing it an…

> mullvad has time and again shown itself to be one of if not the best actors in the entire vpn space, but you still have no real way of knowing if they are being honest.

There are parallels to the now-defunct Crypto AG. Impeccable reputation, but no way of independently verifying it it did what it said on the can. It took decades for the truth about its links to the CIA to come out.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#168

"They intended to seize computers with customer data. In line with our policies such customer data did not exist" But please tell me again how hard it is to comply with the GDPR

the problem is, if this starts to become common, countries will move to make it illegal not to store data...

Would be a shame if those hard drives failed accidentally on a regular basis.

In unrelated news, Seagate stock rises to record high...

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#169
post #163

Earlier quoted context omitted.

pretending you don't need trust when you actually do is a vulnerability. of course you need to trust that mullvad is doing what they actually say they are doing. there is literally no way for you to verify everything they claim.

And yet you trust WhatsApp and Facebook and Signal with their claims of end-to-end encryption. Why?

I don't myself. If it isn't on my own infra, I won't trust it.

The idea that folk are keeping passwords in some cloud management portal owned by some company boggles my mind. But this is a very controversial opinion and offends many.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#170

Earlier quoted context omitted.

If your ISP suspects your IP address (can see your are connected to specific VPN server) they can just contact top websites, example: twitter, facebook or google and ask them if there are any users connected with the same IP at given specific time.

This is a confusing take to me. So my ISP which has my billing information is trying to find out who I am by calling Google? They know who I am. The inverse is what you're trying to prevent. Service ABC has malicious activity and calls Google to ask which accounts are accessing from that IP address. However this has two main problems. a) Why would Google give this info over willingly. b) Most VPN's assign the same ou…

a) This is why you go through the legal system instead of asking Google directly. Report malicious activity to a three-letter agency of your choice, and let them do the dirty work.

b) You can reduce the list of suspects significantly by correlating activity on multiple services from the same IP address around the same time.

c) You'd be wrong... especially since Google never really forgets who you are, even when you are not signed in.

Post reply on HN