Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

171–180 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#171

any competent opinions on protonvpn vs mullvad vpn?

Mullvad is THE ONLY mainstream VPN that doesn't have seriously questionable credibility.

Proton VPN is very questionable - sleuths have figured out that it's just a white-labeled version of NordVPN. But the trail is a rabbithole, and you might not be personally satisfied with the standard of evidence. Here is a start for you: https://news.ycombinator.com/item?id=23571653

And since the link to [2] in what I linked above is broken, here is the archived version: https://archive.is/iZ2l2

Re: Infrastructure audit completed by Radically Open Security

#172
post #95

Earlier quoted context omitted.

To achieve true privacy, first you must create the universe.

Let me get my big-bang kit, manufactured by looks to the underside ... I don't know whether I can trust the company which made it.

For the people who don't have a kit yet, they can always take the cloud approach and use Google Online Development simulator (G.O.D. simulator) and follow their tutorial for Hello Universe[1].

[1]: https://youtu.be/tmGMd2bqh6o

Re: Infrastructure audit completed by Radically Open Security

#173
post #165

Earlier quoted context omitted.

What sort of abuses you have encountered when dealing with port forwarding? Was it DMCA'd content hosting or were there other major issues with it? Also how does other VPNs that offer port forwarding (like Proton) function against those sort of abuses?

They give some examples of things bad actors used port forwarding for in the blog post[1] announcing the removal of the feature. [1]: https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...

Reading between the lines, I'd be very surprised if it wasn't highly undesirable content, i.e. child porn or fraud. This came about a month after a very publicised raid by the Swedish police -- after which they left with nothing [1].

[1] https://www.pcmag.com/news/mullvad-vpn-hit-with-search-warra...

Re: Infrastructure audit completed by Radically Open Security

#174

any competent opinions on protonvpn vs mullvad vpn?

I think those two are the most reputable VPNs. I’ve used ProtonVPN for years just since I wasn’t aware of Mullvad at the time and can’t be bothered to switch. I believe ProtonVPN hasn’t had infrastructure audits, which Mullvad has had.

[deleted]

Re: Infrastructure audit completed by Radically Open Security

#175

As an occasional mullvad customer im glad to hear. That being said, I wonder why we arent hearing about any cases involving them and cybercrime. Letter soup agency smear campaigns or actual cybercrime. They operate totally in the clear as opposed to Tor and other overlay networks, but unlike with Tor, there are no "opinion articles" or biased news articles slamming them as pedophile enablers. I just find this odd. /P…

There was one recently involving Swedish police, I think.

I expect VPN usage is easy enough to unmask by state level actors with timing attacks.

Re: Infrastructure audit completed by Radically Open Security

#176
post #135

Earlier quoted context omitted.

> their total budget is a fraction of Big Tech's The NSA was getting $10.5bn to spend in 2013[0]. I can only imagine it's gone up since then year on year. That's not a bad fraction when your whole goal is signals intelligence. [0] https://www.washingtonpost.com/world/national-security/black...

Volkswagen's research budget was $21 billion in 2022. $10.5bn is nothing in the big picture, and certainly not enough to "control the world" or whatever grand claims are commonly made about the NSA.

No one said control the world. Just that a VPN provider is probably compromised by the NSA.

Re: Infrastructure audit completed by Radically Open Security

#177
post #99

Earlier quoted context omitted.

Have you found a replacement? I did some light investigation but nothing really felt as solid as Mullvad so I haven't jumped ship yet.

None as solid, no. My needs are fairly specific (exit node in a specific country, torrent-friendly, good speed, not too expensive, not too shady, first-party support for my OS'es, doesn't have to be government-proof), so you'll need to do your own research. For what's worth, I eventually went with Proton VPN, but it's more expensive and gives a used-car-salesman feeling.

> gives a used-car-salesman feeling.

I really don't like the aesthetic direction Proton's been taking in the last few years, from top to bottom. I'm finding their mail apps, both in desktop web browser and on mobile, less and less usable. In addition I get this feeling from their design choices as well. I know their mission is to grow enough to challenge predatory providers like gmail, but it makes me wary and makes me feel as if I won't be using them in 5 more years.

Re: Infrastructure audit completed by Radically Open Security

#178

Earlier quoted context omitted.

Yup. As a Cuban, sometimes it is annoying and sometimes go beyond that. Some cloud providers are totally off limits for us, some are fine with us (the minority and less known), some let us use some services but no others, some even have valid OFAC licenses but still deny access (because ACL complexities, I suppose)... it's all over the place. That's why I'm 95% of the time on crappy VPNs both to escape/evade US sanct…

Funny how everyone talks about the Chinese "great firewall" that blocks access towards some western platforms from China, and no one talks about "USA great firewall" that blocks Cuban citizen from acceding to a lot of services

Besides the technical differences brought up by other commenters, I'm a Canadian and I hear about USA sanctions toward Cuba on regular TV news and newspapers, never mind more specific news sources, every USA election cycle. It's a massive topic of public debate, and from what I can see it hugely influences outcomes of key seats in state and federal elections. Sometimes these claims of "nobody talks" or "mainstream media doesn't want you to know" are just... incorrect?

Re: Infrastructure audit completed by Radically Open Security

#179
post #148
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…

Port forwarding doesn't seem to be a problem for long-established independent VPNs like AirVPN (based in Italy but very ingeniously without exit servers in Italy) or AzireVPN (Swedish; added port forwarding -- all mappings in memory, no static records -- just recently [1]). What makes Mullvad's situation different? Is it a question of margins for high traffic port forwarding users (Mullvad is branching out in browsers and search while these two are not) or something else? I used to be a long time user and a huge fan and proponent of Mullvad's but the communication here has been very much opaque. This is especially so as port forwarding removal was announced straight after a raid where police, after Mullvad's explanations, didn't take anything [2].

[1] https://blog.azirevpn.com/port-forwarding/ [2] https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec...

Re: Infrastructure audit completed by Radically Open Security

#180

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

I'm not worried about my government as it currently stands. I'm squicked out by the fact that every single private company I interact with seems to be falling over themselves to collect as much data about me as possible, and resell it to anyone who will pay. There are no protections against this in the US.

I am worried, at least a little bit, about an authoritarian government coming to power and basically weaponizing past data collected against it's citizens. I've seen the inferences facebook and google can make with privately collected data. I don't think it's too outlandish that governments would be able to quickly and easily create detailed dossiers on everyone that protested against x or voted for opposition candidate y.

Post reply on HN