Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

221–230 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#221
post #181

Earlier quoted context omitted.

An intelligence agency already consists of more people than you need to run a VPN service.

Still I think it's easier to avoid the need for more people than necessary. "Just lie" sounds like the easiest solution but on closer inspection maybe it is not?

Lying is almost always the most cost-efficient answer to anything, if you’re not concerned about your trustworthiness, morality, ethics, etc.

Re: Mullvad exit IPs are surprisingly identifying

#222
post #195

Earlier quoted context omitted.

Good VPNs tout the fact that they had nothing to give in response to a subpoena, or that there was nothing a law enforcement agency to find when they seized a server. For mullvad to be effective as a honey pot it needs to survive these events with its reputation in tact.

If it were a true honeypot by a state agency, they'd be able to just lie about having nothing too.

Not when people get arrested and the investigative techniques, sources, etc are made public. They would have to intervene in the legal process to make sure mullvad's role was kept secret. Presumably this isn't always feasible across jurisdictions.

Re: Mullvad exit IPs are surprisingly identifying

#223

Earlier quoted context omitted.

> my browsing traffic doesn't hit the NSA - only my encrypted VPN traffic does I mean, let's be real. All known US VPN servers and Tor exit nodes--and probably all US Tor relays regardless of exit policy--are going to be considered a totally legitimate "communications facility" target for the warrantless wiretapping system due to exactly the scenario you just posited. From that perspective you'd be better off using U…

> NSA just does whatever they want, laws be damned, and are almost certainly logging everything When you share the evidence for this, it will be international news.

Did you miss Snowden or something?

Re: Mullvad exit IPs are surprisingly identifying

#224
post #200

Earlier quoted context omitted.

To support ? Oof.

I'm not sure what you mean by "Oof". We don't have a dedicated security team because security and privacy are integral to all aspects of our service. It doesn't make sense to centralise it. As for our support team they are responsive and experienced. Several of them have worked with us for many years and do offensive security research in their free time. Unlike many organisations we don't see customer support as a co…

> I'm not sure what you mean by "Oof".

I second this.

Clearly the person who wrote "Oof" has never emailed Mullvad support.

Whenever I have emailed Mullvad support I have received a prompt reply from a human being who clearly actually cares about taking ownership of the question and seeing it through to resolution.

I have also witnessed first-hand the support person taking the question to an internal team member where it requires additional input. So there are clear paths for escalation if circumstances require it.

Finally the support mail allows for PGP encryption of communications too.

(I am not a Mullvad shill. Not a Mullvad employee. Just a satisfied customer)

Re: Mullvad exit IPs are surprisingly identifying

#225

Earlier quoted context omitted.

Why not? Why can’t it be the purpose of a given VPN service?

If you use the VPN for the Web, browser fingerprinting is a major threat outside of specialized scenarios

In other words: a VPN service can't by itself solve all problems which potentially lead to deanonymization, it can only provide anonymous networking.

Why can't it aim to solve what it can do? TOR is a great example: the TOR network itself can't perfectly anonymize you due to browser fingerprinting, but users of the TOR Browser get both the TOR network resisting deanonymization on a network level and a browser with plenty of anti-fingerprinting measures built in. A VPN could aim to prevent deanonymization on a network level so that users who want to stay anonymous can use the VPN in combination with fingerprinting-resistant software.

Re: Mullvad exit IPs are surprisingly identifying

#226
post #210

Earlier quoted context omitted.

Do they say how do they have access to those IPs? Most residential IPs are malware-infected devices.

That’s part of our value proposition. It’s same as when you go to a bank and ask where the yield comes for your account or asking OpenAI where they get data to train their models.

> or asking OpenAI where they get data to train their models

Yes I know it comes from pirating/torrenting/scrapping. Are you saying you acknowledge your IPs come from malware, and that is OK because OpenAI is shady too?

Re: Mullvad exit IPs are surprisingly identifying

#227
post #200

Earlier quoted context omitted.

To support ? Oof.

I'm not sure what you mean by "Oof". We don't have a dedicated security team because security and privacy are integral to all aspects of our service. It doesn't make sense to centralise it. As for our support team they are responsive and experienced. Several of them have worked with us for many years and do offensive security research in their free time. Unlike many organisations we don't see customer support as a co…

Human psychology is weird and some things are just cultural. If you have the ops team make the security@ email alias just forward to support, you could avoid having to go into all that.

"Just email support@" feels like you don't care. That you do, and that your support team is awesome, doesn't change the fact that there are other companies out there who's aren't. Security people are human with human egos, and they want to feel special, so giving them a special way to reach you, even if it's the same thing behind the scene, makes a world of difference.

Re: Mullvad exit IPs are surprisingly identifying

#228
post #154

Earlier quoted context omitted.

It's within the realm of possibility that NSA is collecting data with Cloudflare's consent. It seems unlikely that Cloudflare would jeopardize their entire business model over it. Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers. Their entire value proposition is being an unobtrusive traffic intermediary.

Within the realm of possibility? Let's be honest, if you are a top NSA executive and you couldn't find a way to get your hands on Cloudflare's private keys (bribing or threatening the right person), you are not getting your Christmas bonus.

Do people in government get bonuses linked to performance?

Re: Mullvad exit IPs are surprisingly identifying

#229

Earlier quoted context omitted.

What gives you confidence that they aren't? I have confidence my VPN doesn't sell my traffic not because I implicitly trust what they say, but because if they had logs the courts would have found them when trying to seize data themselves. What makes you trust your ISP so much? Faith in the human goodness of businesses to look out for the best interests of their customers, even if it means passing up an opportunity to…

"What gives you confidence that they aren't?" What gives you the confidence that Bigfoot does not exist? What gives you the confidence we're not ruled by Reptile overlords? What gives you the confidence we're not just in the Matrix and nothing matters? What gives you the confidence you're not just a dream by a dog in Sicily? What gives you the confidence I even exist and you're not talking to yourself? You're entitle…

[flagged]

Re: Mullvad exit IPs are surprisingly identifying

#230
post #200

Earlier quoted context omitted.

To support ? Oof.

I'm not sure what you mean by "Oof". We don't have a dedicated security team because security and privacy are integral to all aspects of our service. It doesn't make sense to centralise it. As for our support team they are responsive and experienced. Several of them have worked with us for many years and do offensive security research in their free time. Unlike many organisations we don't see customer support as a co…

It still probably makes sense to alias it to security@mullvadvpn.net for privacy/security concerns.

I'm not familiar with how you run your company -- without the context you gave most people would hesitate emailing support@ for security issues.

Post reply on HN