Live data from Hacker News

Infrastructure audit completed by Radically Open Security

mullvad.net

211–220 of 290 posts

Re: Infrastructure audit completed by Radically Open Security

#211
post #110

Earlier quoted context omitted.

Correct, but the destination ISP chain (and of course the destination service itself) can equally see the traffic coming from the VPN, and if you have packet metadata (precise timing and packet sizes) from two sources on either side of the VPN, it is trivial to correlate those two streams.

Note that Mullvad's WireGuard settings offer a "multihop" feature, meaning the VPN destination your ISP sees and the VPN endpoint the end service sees differ.

I'm not sure how that protects you though. ISP sees your traffic going into WG1. They know all of Mulvad's IPs, so isn't it just as easy to correlate that traffic when you exit through WG2?

/question from ignorance

Re: Infrastructure audit completed by Radically Open Security

#212

Earlier quoted context omitted.

Mullvad is THE ONLY mainstream VPN that doesn't have seriously questionable credibility. Proton VPN is very questionable - sleuths have figured out that it's just a white-labeled version of NordVPN. But the trail is a rabbithole, and you might not be personally satisfied with the standard of evidence. Here is a start for you: https://news.ycombinator.com/item?id=23571653 And since the link to [2] in what I linked abo…

I don't find this credible whatsoever, and I think you should stop making this claim. The only piece of evidence in your linked comment is the now defunct blog post: https://web.archive.org/web/20200629163107/https://vpnscam.c... In addition to reading like it was written by an angry 12 year old, it makes some enormous logical leaps. The facts given are that Proton has an official legal entity in Lithuania called PRO…

> In other words, it appears to me that the true source of these rumors has retracted them and no longer believes that Proton has the claimed ties to Tesonet.

I was nodding along, until this.

Seeing someone retract a pretty specific claim like that by calling on the admins to delete, instead of leaving it up for posterity and/or and discussing how they made the error, feels more like a legal threat was received, and some pants were shat.

Re: Infrastructure audit completed by Radically Open Security

#213
post #95

Earlier quoted context omitted.

You can't trust anything you have not built, incl. your laptop, keyboard, mouse, phone, car, even your teabag (what happens if they're randomly drugging your tea to test some pathogens, with a request from your government). Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible. So, the hole has no bottom.

To achieve true privacy, first you must create the universe.

Given enough time in your own head, this is doable.

Re: Infrastructure audit completed by Radically Open Security

#214
post #93

Earlier quoted context omitted.

That's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's. If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.

> their total budget is a fraction of Big Tech's The NSA was getting $10.5bn to spend in 2013[0]. I can only imagine it's gone up since then year on year. That's not a bad fraction when your whole goal is signals intelligence. [0] https://www.washingtonpost.com/world/national-security/black...

...and that amounts to a lot of drivespace.

(Based on the available data, not spending their budget on FT talent; they apparently get that with their logo.)

Re: Infrastructure audit completed by Radically Open Security

#215

Earlier quoted context omitted.

> Anyway, and sadly, the sanctions affect "regular" people like me the most. The ruling elite? Not at all. This confirms my secondhand knowledge of financial sanctions. It seems to universally be this way and makes me wonder why we still tout them as if they were effective. They sure don’t seem to be.

That’s a very broad statement, almost automatically untrue. All countries, all situations, all financial sanctions?

It obviously isn't too broad, because instead of this comment you could have posted a single counterexample to disprove it.

Re: Infrastructure audit completed by Radically Open Security

#216

Earlier quoted context omitted.

Russian passport, your official documents would be from the Russian state; your police would be Russian And, most likely, your personal allegiance would be Russian.

While this is a provocative response and there is no excuse for the Russian invasion of Ukraine, the 2001 Ukrainian census[1] states 60.4% of the Crimean population considered themselves Russian and 24% of the Crimean population considered themselves Ukrainian. [1] https://en.wikipedia.org/wiki/Demographics_of_Crimea#Ethnici...

Obviously it's impossible to do a reasonably unskewed poll in Crimea right now. However in other parts of Ukraine the number of people who consider themselves Russian drastically decreased when Russia started shelling their homes. So it's not clear how informative 2001 polls would be. Russia has also deliberately encouraged Russians to move to Crimea recently which would also skew that statistic.

Re: Infrastructure audit completed by Radically Open Security

#217

Earlier quoted context omitted.

Note that Mullvad's WireGuard settings offer a "multihop" feature, meaning the VPN destination your ISP sees and the VPN endpoint the end service sees differ.

I'm not sure how that protects you though. ISP sees your traffic going into WG1. They know all of Mulvad's IPs, so isn't it just as easy to correlate that traffic when you exit through WG2? /question from ignorance

Equally ignorant response here :) How would they see that traffic? Why would the ISP be the same?

Re: Infrastructure audit completed by Radically Open Security

#218

Earlier quoted context omitted.

[flagged]

If you really want to fight about this, Ukraine’s military is accepting foreign volunteers.

Yes. Zelensky has made it clear that they have lots of equipment and arms (although they'd love to have more.) What they need is foreign volunteers to fight.

Re: Infrastructure audit completed by Radically Open Security

#219
post #55

Earlier quoted context omitted.

If you don't do any logging and don't want to know what your users are doing - it means that you won't have to deal with the cops as much. And there won't be any risk of those logs getting leaked or stolen . Unless you're de-facto part of the government like Google and Microsoft - I see no good reason to log anything more than what's legally required.

...why do that when you can simply sell though?

Sell what? Browsing data of VPN users? That would be easy to check.

Re: Infrastructure audit completed by Radically Open Security

#220
post #93

Given that it's in the West I still think it's probably NSA compromised, but I'm not nearly important enough for the government to blow their cover about.

That's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's. If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.

> the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else

Exactly what the hell kind of magical knowledge does it take to compromise a VPN? They could own the thing completely.

If you ever find yourself thinking that massive intelligence agencies with budgets in the tens or hundreds of billions of dollars aren't doing anything and have no function, you've been watching too much TV news. If you think that governments require the magical knowledge of gods, wizards and aliens to compromise a VPN service, you've completely retreated into fantasy.

Post reply on HN