Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

201–210 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#201

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

> how I'd design a VPN if I were an intelligence agency

I think its safe to assume that intelligence agencies have other options available to them, such as country-wide timing attacks.

Re: Mullvad exit IPs are surprisingly identifying

#202

Earlier quoted context omitted.

Why? If I was an intelligence agency and designing a VPN I would simply log all the IPs connecting to my VPN and not rely on statistics on exit nodes to identify the users, even more so because they rely on the users to pick different servers.

How would you claim it's a no log VPN?

> How would you claim it's a no log VPN?

Mullvad have been taken to court over this in relation to a copyright infringement case.

TL;DR The judge permitted people to take a fine-tooth comb to Mullvad's infrastructure and no logging was found[1].

[1] https://mullvad.net/en/blog/mullvad-vpn-was-subject-to-a-sea...

Re: Mullvad exit IPs are surprisingly identifying

#203
post #72

Earlier quoted context omitted.

But what privacy do you think majority of people who not doing something badly illegal expect from VPNs? Most likely these people just look to hide their torrenting, saying political shit on Twitter from employer and not share their choice of porn with local ISP. Also just adding one more layer between them and occasional scammer who can sometimes infer more broad geodata from their IP leaked from yet another databas…

Source? Why not “I don’t want to get profiled”?

We're talking on website with one of highest concentration of tech savvy IT professionals, programmers, cyber security experts, etc.

What percent on people on Hacker News who say they care about privacy live without Google, Apple, Microsoft and Facebook accounts?

How many people outside of HN do you think care about privacy for real? Like about adtech surveillance and not about their naked photos leaking?

I doubt either % is very high sadly. We tend to say we care, but very few people actually do anything or use self hosted solutions or not tied to Apple or Google ecosystems.

Re: Mullvad exit IPs are surprisingly identifying

#204

Earlier quoted context omitted.

VPNs are not snake oil. They transfer the trust of your internet activity from a place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad, IVPN, or Proton. Among other benefits. If you don't like your ISP creating a profile of you and selling it to target ads to you, you should use a VPN. >Should I use a VPN? Yes, almost certainly. A VPN has many advantages, including: 1. Hiding…

> 4. Allowing you to bypass geo-restrictions on certain content. In theory, but as someone who uses Mullvad in the UK on a day-to-day basis on my personal laptops (not my phone) - I'm using it now, I'm afraid there's quite an additional downside I've found, in that because Mullvad's (at least UK, but also French and Dutch ones I've tried) exit IPs are known, many companies (Cloudflare, Akamai) at the very least know…

>Santander bank for example, I can't always (sometimes I can) connect to when using Mullvad, and sometimes have to turn it off, as I get 403 responses from the bank otherwise

Rotating your VPN endpoint will resolve the issue. It might take two or three tries.

Re: Mullvad exit IPs are surprisingly identifying

#205

The purpose of a VPN does not include anonymizing users with respect to the sites they visit,so it shouldn't be too surprising that Mullvad doesn't enforce unique exit IPs. Users who want anonymity should use networks like Tor.

Isn't Tor a us government project that has been shown to be deanonymizable?

It has been successfully deanonymized, and resistance to NSA-level capabilities is explicitly not a stated goal.

Re: Mullvad exit IPs are surprisingly identifying

#206
post #203

Earlier quoted context omitted.

Source? Why not “I don’t want to get profiled”?

We're talking on website with one of highest concentration of tech savvy IT professionals, programmers, cyber security experts, etc. What percent on people on Hacker News who say they care about privacy live without Google, Apple, Microsoft and Facebook accounts? How many people outside of HN do you think care about privacy for real? Like about adtech surveillance and not about their naked photos leaking? I doubt eit…

I mean, there’s a lot of products out there marketed around privacy. I really doubt the HN readers are the sole source of income for all these products… I do agree, it’s a minority, but within the VPN using population, I don’t think it’s a minority. Average Joe watching porn doesn’t give a shit about someone knowing about this (except, and that’s new, if you’re lucky enough to live in a place where VPN has become mandatory for this).

Re: Mullvad exit IPs are surprisingly identifying

#207
post #178

I work at Mullvad. (co-CEO, co-founder) Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post's findings you may get confusing results throughout the day. We will also re-evaluate wheth…

I just want to say I absolutely love Mullvad! You guys did a fantastic job at designing a genuinely good and trustworthy (as much as possible) VPN vendor. You communicating here is just another data point towards this.

Re: Mullvad exit IPs are surprisingly identifying

#208
post #158

Earlier quoted context omitted.

I could just...lie.

One person can tell a lie, but a company consists of many people. You must ensure that only few people know of the logging or there will be a risk of a leak.

Companies can lie at large too. Enron, theranos, and many others come to mind.

Re: Mullvad exit IPs are surprisingly identifying

#209
post #107

Earlier quoted context omitted.

That slide was about the NSA sitting inside Google data centers without Google's knowledge. That doesn't mean collusion

That's the thing though: We can't know that.

Well, we kind of can, given that "SSL added and removed here :-)" was a pretty explicit workaround to the issue of encrypted communications in Google's infrastructure, just not between sites (IIRC).

Either way, if they were directly colluding with Google, they would have had a much simpler time siphoning off that data.

Re: Mullvad exit IPs are surprisingly identifying

#210
post #90

Earlier quoted context omitted.

yeah, I'm using https://proxybase.xyz for this. It's like Mullvad but for proxies. No kyc, no email but supports xmr.

Do they say how do they have access to those IPs? Most residential IPs are malware-infected devices.

That’s part of our value proposition. It’s same as when you go to a bank and ask where the yield comes for your account or asking OpenAI where they get data to train their models.
Post reply on HN