Live data from Hacker News

Mullvad VPN was subject to a search warrant – customer data not compromised

mullvad.net

231–240 of 345 posts

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#231

Earlier quoted context omitted.

I was under the impression the socks feature no longer works, are you currently using it?

I am, through the mullvad add-on.

Take their wireguard config, change allowed IPs to include only the IP of their SOCKS gateway.

And then use the SOCKS proxy over Wireguard while nothing else on your system is routed through it.

That's the only way you'll get Mullvad "split tunnel" on OSX.

Edit: Should have replied to the sibling comment but I guess this will do.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#232

I don't understand why go after the VPN, I think most people don't use a VPN correctly. What good is a VPN when multiple apps on your computer are phoning home? If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP? To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to…

> What good is a VPN when multiple apps on your computer are phoning home? The point of a VPN is that whenever an app phone home, they will do so through the VPN. Standard VPN configuration (which I supose the Mullvad client performs?) is to entirely disallow any traffic that doesn't go through the VPN

[deleted]

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#233
post #113

Earlier quoted context omitted.

No, because at the same time x number of users have their apps phoning home with what appears to be the same IP

How can you be sure that you are the only one in your country not connected to the same IP address provided by a VPN server?

Well if they have ISP flow logs, that'll be trickier because it will enable very granular inspection of the traffic and the timings of that traffic.

However if they are trying to cast a wide net and inquire Google and other service providers for it, that will lead to a lot of collusions and they won't be able to tell it is from country A because it is from the VPN.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#234
post #200

Earlier quoted context omitted.

Have legal representation show up quickly means nothing. Consider the many, many scenarios where search warrants are served on companies with in house legal. Law firms. Individual lawyers. Literally happens every single day. Law enforcement has a warrant signed by a judge. Just because a lawyer of some sort is there doesn't mean they're going to stand around paralyzed saying "Oh there's a lawyer here, better stop wha…

This is quite silly. A warrant isn’t a magic bullet that ends all your rights and gives the police superpowers. A lawyer can very much say “no, this information isn’t responsive to the warrant”, where a lay person may not realise this, and volunteer information that they have no legal obligation to hand over. The police absolutely rely on the information and power asymmetry between them and the public. You honestly d…

Many cases the police don’t let you watch, they make you wait outside. Reason to have cameras in your place (pros and cons)

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#235

Earlier quoted context omitted.

Use the VPN from a VM. You can also configure Mullvad to use socks so that it can only be accessed from Firefox (which has OS independent socks settings)

I was under the impression the socks feature no longer works, are you currently using it?

It works the same as always for me on Linux with SSH port forwards.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#236

I've been a Mullvad customer for some time and I'm quite satisfied. But the main issue I have is that many of its servers are blacklisted by Cloudflare and other services. Because Mullvad provides the strongest anonymity a VPN can provide, it attracts not only normal users, but also malicious users (scammers, hackers, or less malicious but more numerous scrappers).

I've run into this as well, but for what it's worth, this is a problem every VPN provider struggles with. The most colorful example I have is receiving an email from my bank telling me they've blocked access to online banking because someone tried to log into my account from a suspicious IP — yes, it was me. Luckily I use a fairly small local bank who cuts through issues like this swiftly with a short phone call.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#237

Earlier quoted context omitted.

Wait what? If you go to the post office and pay with your debit card, how exactly do they figure out who you are based on the stamp?

It's all metadata correlation. The UK will know with certainty that a specific stamp was used to send a specific envelope to Mullvad. (e.g., America has been logging images of every envelope that passes through its postal service for over two decades). It would also be trivial for the UK to know: - When and where that stamp was initially sold (and to whom, if buying online!) - When and where an envelope bearing that…

> Not really very realistic is it though? I can only imagine this sort of thing is only done if the suspect is someone like Bin Laden, not the average Joe using a VPN for pirating Photoshop.

This is a misconception caused by the scale of surveillance today. In the old days you were right. To do this kind of tracing they'd have to assign someone to do it which takes human resources and is not infinitely scalable. So they'd only do it to people deemed interesting enough, so average Joe was safe.

Today the scope has changed completely. Everything can be correlated all the time, so it is. No suspicion or probable cause needed.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#238

Earlier quoted context omitted.

> service provider may claim to not store any user data, but they could be lying. As someone who ran a VPN in the past, this blog post is extremely strange as well as the purported described sequence of events. Police in any jurisdiction aren’t jokes - especially not Sweden where they can absolutely walk in and take your stuff according to mullvads website [1]. It’s 2023 - if a VPN is how you’re doing your privacy yo…

I'm satisfied with the transparency Mullvad has shown by publishing its 9 audits[1] and with their efforts to ask for as little information from users as possible. I also appreciate how Mullvad releases up-to-date source code for all of its software clients, which I consider a bare minimum for any VPN to even be considered.[2] Private Internet Access, on the other hand, does not release up-to-date source code for its…

commoner - Thank you for this comment, and I think it's definitely fair to trust in Mullvad given these transparencies. The sequence of events are simply peculiar to me, and doesn't seem like a professional police operation. That said, I've been keenly watching Mullvad and agree with you that it's rock-solid in transparency which is the number one reason to use/not use a VPN service, if for privacy.

I salute Mullvad and consider it to be the top VPN in the world today, and specifically, the only one I would recommend to anyone looking for a VPN.

In terms of PIA, I am no longer affiliated with the company, but I agree that getting the source out for the clients out on time is something they should try to address quickly.

gerbilly (another poster in parallel) - In 2023, I don't think a VPN is not private, but, for sure this cannot be the only tool in one's arsenal to secure their privacy. Depending on your threat-levels, there are different things you may want to do. To be clear, if you're being targeted, you cannot maintain privacy.

For the absolutist:

1. Get cash but not from an ATM (traceable)

2. Go buy a computer (must be Purism or something with trustworthy hardware) with said cash but wear a disguise when buying it. Disable all the location/etc. stuff at store parking lot.

3. Purchase a T-Mobile Prepaid Hotspot with cash.

4. Purchase mullvad, but wear gloves, mask and a hairnet when working with the envelope to send cash.

5. Never login to any service of any kind that would leak your identity.

For everyone else:

1. Assume you're not private.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#239
post #95
post #75

Earlier quoted context omitted.

> Technically they could have been logging your traffic Of course they “could have” but their entire business depends on them not doing it.

That's a specious argument, because the choice could be between logging your traffic and being forced to shutdown under some kind of Swedish NSL, or forced to keep operating and logging even if they want to shut down. Not saying this is what happened, just that your reasoning doesn't really hold. Hell it's entirely possible Mullvad is a honeypot operated by some foreign intelligence service.

Law enforcements could force Mullvad to start logging some specific account if they manage to indentify the account.

Service might not collect data but they could be forced with warrant to start doing so for specific entities.

This has happened in Finland, for example.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#240

Earlier quoted context omitted.

I’ve got no real insight, but my guess would be that a) the goons have both technical and legal competence and b) Mullvad had legal representation show up quickly.

Have legal representation show up quickly means nothing. Consider the many, many scenarios where search warrants are served on companies with in house legal. Law firms. Individual lawyers. Literally happens every single day. Law enforcement has a warrant signed by a judge. Just because a lawyer of some sort is there doesn't mean they're going to stand around paralyzed saying "Oh there's a lawyer here, better stop wha…

This feels like a very American-centric perspective, this happened in Sweden.

For a bunch of reasons policing outside the US is very different to policing in the US.

Post reply on HN