Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

201–210 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#201

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

Always critics but never providing a viable alternative. So please tell us your model, yank the cable out of the wall and pitch your phone in the lake? I'm mostly concerned about advertisers, corps, and my ISP. I know that in my country (the USA) that if they want something out of me they'll take me to a back room and beat it out of me, so generally I don't do illegal stuff.

i2p, tor. whonix distribution of linux, tails…

Re: Infrastructure audit completed by Radically Open Security

#202

You’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation.…

VPNs are for escaping private adtech firms, not governments. I don't know where you got this impression from.

perhaps the annual audits, a bit of theatre if its just for escaping private adtech firms

this attracts people that want a subpoena to yield nothing

Re: Infrastructure audit completed by Radically Open Security

#203
post #148

Earlier quoted context omitted.

I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…

Thanks for the reply. I'm sorry my negative comment got to first spot on what should have been a positive post. I understand why the decision was made, and I think I'd have done the same. I really hope you guys stick around, Mullvad has exactly the posture that we need from security services.

Thank you. There is no need to be sorry. I'm grateful for the opportunity to clarify things.

Re: Infrastructure audit completed by Radically Open Security

#204

Earlier quoted context omitted.

What sort of abuses you have encountered when dealing with port forwarding? Was it DMCA'd content hosting or were there other major issues with it? Also how does other VPNs that offer port forwarding (like Proton) function against those sort of abuses?

VPN port forwarding is, by and large, used for BitTorrent because you can't seed without it. VPNs are used for BitTorrent in general because it's well-known that IPs participating in BitTorrent are monitored and logged by anyone who wants to[0]. I bet it's at least 100 BitTorrent users for every 1 user using port forwarding for any other purpose. [0] https://iknowwhatyoudownload.com/

You can still seed/download without port forwarding setup, however the other person you're connected to needs to have port forwarding. Basically either side of the P2P connection needs to be reachable from the open internet, but not both.

So you can still seed, it just won't be as usable.

Re: Infrastructure audit completed by Radically Open Security

#205
post #132

Earlier quoted context omitted.

That's honestly a great idea for an alternative to newsletters... it would be nice if there was better first-party RSS support (what about in the email client?) since I don't think any OSs have it, because right now that would probably confuse most customers

The likelihood of being confused by rss among mullvad customers can't be very high.

You might be surprised! The Mullvad client is super well designed and usable for newbs, and I'll bet a lot of their business is from people whose more technical friends told them it was a good idea. There's a reason that Tor warns users that posting personal information or using accounts with their regular credentials compromises anonymity.

I wish RSS had more surface area with general computer users, but I reckon even being called RSS makes it unlikely. Folks in tech often forget how intimidating opaque names can be for nontechnical users.

Re: Infrastructure audit completed by Radically Open Security

#206

any competent opinions on protonvpn vs mullvad vpn?

Mullvad is THE ONLY mainstream VPN that doesn't have seriously questionable credibility. Proton VPN is very questionable - sleuths have figured out that it's just a white-labeled version of NordVPN. But the trail is a rabbithole, and you might not be personally satisfied with the standard of evidence. Here is a start for you: https://news.ycombinator.com/item?id=23571653 And since the link to [2] in what I linked abo…

I don't find this credible whatsoever, and I think you should stop making this claim.

The only piece of evidence in your linked comment is the now defunct blog post: https://web.archive.org/web/20200629163107/https://vpnscam.c...

In addition to reading like it was written by an angry 12 year old, it makes some enormous logical leaps. The facts given are that Proton has an official legal entity in Lithuania called PROTONVPN LT, UAB, and another company called Tesonet shared Lithuanian offices and apparently some business services with them. The article claims that Tesonet is a "data mining company" based on the following evidence:

> Tesonet has its hands in “Machine Learning Solution, cybersecurity, and collection of business intelligence data” in efforts to create algorithms, that best suit their client business needs. If you read their about page, the company openly states it employs many different technologies to structure data, which is run on various services like MySQL, Anisble, collectd, StatsD, ElasticSearch, Grafana, Influx DB, Python, and Couchbase.

> ALL of these names rely on HEAVY USER INFORMATION, which makes sense, considering that Tesonet is a DATA MINING company. Now, let us not forget that Lithuania itself is a NATO member that regularly holds NAZI marches.

Let's just say that I'm not immediately convinced that Tesonet is in the business of selling user data.

The article also claims that in one online Lithuanian business services directory, the CEO of Tesonet was listed as the head of PROTONVPN LT, UAB. I have no idea of the legitimacy of this claim, but it stretches plausibility to claim that Proton is secretly not a Swiss company and secretly has a Lithuanian data mining company CEO as its head.

The article then goes on to make some completely unsupported allegations: "the real question is not whether ProtonVPN is working with Tesonet, but if the provider is owned by the data mining company" and "Under the name of a FREE VPN service, they’ve been collecting USER DATA all along."

Furthermore, the original source of most of this information actually comes from a Hacker News comment. The article links to a comment by the head of Private Internet Access! https://news.ycombinator.com/item?id=17258203

Unfortunately this gives the game away, because the comment is "retracted and removed by author's request". Dang comments:

> In addition to the redacting the above comment, we deleted several comments below by request of their authors. My understanding is that the dispute has been resolved and that the allegations are retracted.

In other words, it appears to me that the true source of these rumors has retracted them and no longer believes that Proton has the claimed ties to Tesonet.

Ironically, as a result of looking into this, I feel slightly more confident about ProtonVPN than I did previously.

Edited to add: you're also stretching even the blog post's unsupported allegations in your comment, when you say that ProtonVPN is "white-labeled" Nord. The article makes the unsupported insinuation that ProtonVPN and Nord are both owned by Tesonet, but this is different from the claim that ProtonVPN is just Nord repackaged as a different product, as you claim here.

Re: Infrastructure audit completed by Radically Open Security

#208

It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convin…

They don't state it clearly but this was a "we are capable not to mess up" audit rather than a "we are keeping your promises" audit.

I believe it is relevant to the threat model of an attacker gaining (partial) access to a production server (eg no accidental logging), not to the threat model of mullvad deploying malicious code.

I feel like this is a meaningful audit but would have liked if they had stated this more explicitly

Re: Infrastructure audit completed by Radically Open Security

#209

Earlier quoted context omitted.

if you want privacy on the internet you have options. VPNs give you privacy from your local network and ISP and a little bit from the destination service, and that's it. there are options to have privacy from additional kinds of parties. i2p, tor. whonix distribution of linux, tails…

What if your VPN is the true adversary here? Edit: Also, questioning trustworthiness of VPNs and them putting them forward as a solution is... a bit unorthodox.

> What if your VPN is the true adversary here?

They're not. Spectrum is my true adversary. My VPN may also be an adversary but that's a possibility, whereas Spectrum is a certainty.

Re: Infrastructure audit completed by Radically Open Security

#210
post #148
post #59

I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…

I sincerely apologize for the inconvenience we have caused you. Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done. Nevertheless it was the right thing to do. The manner and extent in which it came to…

It is wild how good of a company and team you’ve proven to be. The world would be a much better place if everyone operated this way
Post reply on HN