Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

211–220 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#211

Earlier quoted context omitted.

Is this your service? Since you've made seven posts to HN about it and also your username shows up in the commits on their GitHub. Because I'm quite curious on where the IPs are from. Usually residential IPs is a fancy wording for malware infested devices from regular people.

> Is this your service? Since you've made seven posts to HN about it and also your username shows up in the commits on their GitHub. Ohh, that makes sense haha. @m00dy: please disclose when you’re talking about your own projects! It’s okay to plug your stuff sometimes, just be honest about it :-)

I’m not hiding anything :-)

Re: Mullvad exit IPs are surprisingly identifying

#212
post #80

Earlier quoted context omitted.

That is exactly the point of public VPNs.. If I'm on a public VPN, I don't want anyone to know who is making the request, including the terminating IP. Think about it. By your logic, VPNs shouldn't be used for torrents because VPNs shouldn't anonymize you to the terminating IP. Whereas they work gangbusters for that. If you are talking about private VPNs.. Mullvad isn't one.

Public VPNs only protect you from your ISP

And, arguably more importantly, from the service you're using.

Re: Mullvad exit IPs are surprisingly identifying

#213

Earlier quoted context omitted.

Isn't Tor a us government project that has been shown to be deanonymizable?

It has been successfully deanonymized, and resistance to NSA-level capabilities is explicitly not a stated goal.

Do you have a source for this?

Re: Mullvad exit IPs are surprisingly identifying

#214

I work for IPinfo. Even though we are in the VPN detection business, I will give Mullvad the benefit of the doubt, to be honest. They were one of the three VPN providers we found that did not attempt to submit inaccurate geolocation information to IP geolocation providers like us. I am sure they will fix the issue.

Who else ?

Re: Mullvad exit IPs are surprisingly identifying

#215
post #90

Earlier quoted context omitted.

This might be a good idea, but consider banning them for, say, a couple hours at a time. It’s easy to rotate IP, especially if you’re using a residential proxy service, and there’s a good chance you’ll end up blocking real users using the same ISP.

yeah, I'm using https://proxybase.xyz for this. It's like Mullvad but for proxies. No kyc, no email but supports xmr.

You should put your business (https://proxybase.xyz) in your HN profile. It might help to find more customers.

Re: Mullvad exit IPs are surprisingly identifying

#216
post #90

Earlier quoted context omitted.

yeah, I'm using https://proxybase.xyz for this. It's like Mullvad but for proxies. No kyc, no email but supports xmr.

Is this your service? Since you've made seven posts to HN about it and also your username shows up in the commits on their GitHub. Because I'm quite curious on where the IPs are from. Usually residential IPs is a fancy wording for malware infested devices from regular people.

    > Since you've made seven posts to HN about it
Do you have a tool to text search a user's comment history? Your comment is very specific: "seven"!

Re: Mullvad exit IPs are surprisingly identifying

#217
post #90

Earlier quoted context omitted.

yeah, I'm using https://proxybase.xyz for this. It's like Mullvad but for proxies. No kyc, no email but supports xmr.

You should put your business ( https://proxybase.xyz ) in your HN profile. It might help to find more customers.

I’m not here to promote anything just wanted to share a valid use case in the right context.

Re: Mullvad exit IPs are surprisingly identifying

#218
post #178

I work at Mullvad. (co-CEO, co-founder) Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post's findings you may get confusing results throughout the day. We will also re-evaluate wheth…

> Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings How to report a bug or vulnerability ... we (currently) have no bug bounty program ... send an email to support@mullvadvpn.net https://mullvad.net/en/help/how-report-bug-or-vulnerability / https://archive.vn/BeHhr

Not having a bug bounty or dedicated email address does not make it OK to go public immediately

Re: Mullvad exit IPs are surprisingly identifying

#219

Earlier quoted context omitted.

It has been successfully deanonymized, and resistance to NSA-level capabilities is explicitly not a stated goal.

Do you have a source for this?

No, because I don't keep a list of every article I've read over the past decade or so, but there were multiple busts where a regular law enforcement agency (FBI and their international counterparts) were able to prove the identity of a user simply by timing attacks.

The fact that Tor does not intend to tackle the timing problem is plainly stated on the Tor website.

Re: Mullvad exit IPs are surprisingly identifying

#220
post #203

Earlier quoted context omitted.

We're talking on website with one of highest concentration of tech savvy IT professionals, programmers, cyber security experts, etc. What percent on people on Hacker News who say they care about privacy live without Google, Apple, Microsoft and Facebook accounts? How many people outside of HN do you think care about privacy for real? Like about adtech surveillance and not about their naked photos leaking? I doubt eit…

I mean, there’s a lot of products out there marketed around privacy. I really doubt the HN readers are the sole source of income for all these products… I do agree, it’s a minority, but within the VPN using population, I don’t think it’s a minority. Average Joe watching porn doesn’t give a shit about someone knowing about this (except, and that’s new, if you’re lucky enough to live in a place where VPN has become man…

VPN market is huge, but in my opinion majority of people who buy it "for privacy" dont really care about privacy and just use the same Google services or other accounts registered using a mobile phone number.

You really cant blame VPN providers for selling on "privacy" hype and not delivering because most people dont care either way.

Might be I wrong, but I feel in west for most normal people use VPNs for torrents, watching porn and hidding activity from school or employeer. Small subsets are also sport fans who bypass geo blocking and people scheming for cheaper regional prices on netflix / steam / consoles.

Post reply on HN