Live data from Hacker News

WireGuard multihop available in the Mullvad app

mullvad.net

21–30 of 141 posts

Re: WireGuard multihop available in the Mullvad app

#21
Tangentially related:

Users can use Mullvad’s TOR address: http://o54hon2e2vj6c7m3aqqu6uyece65by3vgoxxhlqlsvkmacw6a7m7k... to generate their account ID and make their payment with Bitcoin seamlessly.

I have never experienced such a smooth way to purchase from a provider, this was brilliant.

+1 to Mullvad

Re: WireGuard multihop available in the Mullvad app

#22

10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly…

I would think you'd do the exact opposite. If you leave a computer running anyone (Well "anyone" being a skilled adversary) can simply pull out the RAM and grab encryption keys in clear text. Law enforcement does this so often, it's practically routine. The only "safe" system is one that has been long powered off and is using tried and true cryptography, ideally open-source FDE that's been fully audited.

Mullvad is fully open source, with the source code provided here [1], which has also undergone multiple rounds of audits with the reports available to the public [2][3].

[1] https://github.com/mullvad

[2] https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leak...

[3] https://cure53.de/pentest-report_mullvad_2021_v1.pdf

Re: WireGuard multihop available in the Mullvad app

#23

10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly…

I would think you'd do the exact opposite. If you leave a computer running anyone (Well "anyone" being a skilled adversary) can simply pull out the RAM and grab encryption keys in clear text. Law enforcement does this so often, it's practically routine. The only "safe" system is one that has been long powered off and is using tried and true cryptography, ideally open-source FDE that's been fully audited.

FDE is not enough against physical access, see the evil maid attack.

Re: WireGuard multihop available in the Mullvad app

#24

10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly…

What is the coffee paper trick?

It must be attached such it tears when opened, tamper-evident- similar techniques are common fro doors, either across the frame or more stealthily near the hinge. You want it to be a little stealth because an informed adversary could break the seal, remove it, and be prepared to replace/recreate it when they're done (like faking a new wax seal)

Re: WireGuard multihop available in the Mullvad app

#26

10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly…

[deleted]

Re: WireGuard multihop available in the Mullvad app

#27

Earlier quoted context omitted.

I would think you'd do the exact opposite. If you leave a computer running anyone (Well "anyone" being a skilled adversary) can simply pull out the RAM and grab encryption keys in clear text. Law enforcement does this so often, it's practically routine. The only "safe" system is one that has been long powered off and is using tried and true cryptography, ideally open-source FDE that's been fully audited.

FDE is not enough against physical access, see the evil maid attack.

Well obviously, FDE also doesn't protect you if someone is standing over your shoulder reading you type the password. The point is that leaving a machine turned on, while not in your physical possession puts all of your data at risk. My company would freak if I did this and I don't even work in the security space.

Re: WireGuard multihop available in the Mullvad app

#28

10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly…

  > "They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security."
I don't get it

Re: WireGuard multihop available in the Mullvad app

#29

10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly…

I would think you'd do the exact opposite. If you leave a computer running anyone (Well "anyone" being a skilled adversary) can simply pull out the RAM and grab encryption keys in clear text. Law enforcement does this so often, it's practically routine. The only "safe" system is one that has been long powered off and is using tried and true cryptography, ideally open-source FDE that's been fully audited.

Full disk encryption won't prevent "evil maid" attacks where keylogging hardware is interposed between the keyboard and the main board, or the entire board is swapped with one with firmware enabling remote "management".

Re: WireGuard multihop available in the Mullvad app

#30

Earlier quoted context omitted.

What is the coffee paper trick?

It must be attached such it tears when opened, tamper-evident- similar techniques are common fro doors, either across the frame or more stealthily near the hinge. You want it to be a little stealth because an informed adversary could break the seal, remove it, and be prepared to replace/recreate it when they're done (like faking a new wax seal)

Maybe overspray some spraypaint on the paper first and take a picture of the droplet pattern, so it can't be replaced easily.
Post reply on HN