Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

231–240 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#231
post #220

Earlier quoted context omitted.

I mean, there’s a lot of products out there marketed around privacy. I really doubt the HN readers are the sole source of income for all these products… I do agree, it’s a minority, but within the VPN using population, I don’t think it’s a minority. Average Joe watching porn doesn’t give a shit about someone knowing about this (except, and that’s new, if you’re lucky enough to live in a place where VPN has become man…

VPN market is huge, but in my opinion majority of people who buy it "for privacy" dont really care about privacy and just use the same Google services or other accounts registered using a mobile phone number. You really cant blame VPN providers for selling on "privacy" hype and not delivering because most people dont care either way. Might be I wrong, but I feel in west for most normal people use VPNs for torrents, w…

I would definitely blame a VPN provider if: 1. Only a minority of users care about privacy 2. VPN provider still advertise for “privacy”, even though it only target a minority of users that care about it 3. VPN provider doesn’t deliver on said privacy.

I blame mullvad for messing up, but I do not suspect them of working with some state sponsored surveillance programme at the moment.

Re: Mullvad exit IPs are surprisingly identifying

#232
post #210

Earlier quoted context omitted.

That’s part of our value proposition. It’s same as when you go to a bank and ask where the yield comes for your account or asking OpenAI where they get data to train their models.

> or asking OpenAI where they get data to train their models Yes I know it comes from pirating/torrenting/scrapping. Are you saying you acknowledge your IPs come from malware, and that is OK because OpenAI is shady too?

For the context, I have the right not to tell you anything about how we operate our business but we're not shady, we don't take any action without user consent. The other thing is that we don't use "source" keyword in our business context. I think when you use that essentially you inherently accept some part of your business is shady as hell. Instead, we use "providers". That's a lot better.

Re: Mullvad exit IPs are surprisingly identifying

#233
post #36

Earlier quoted context omitted.

How is private company (VPN) is more trustworthy than an other private company (ISP) and how do you expect them to protect your identity in face of determined state actors that are afer you? What power is in $2.99/month that it offers so much security? Why is that at least 40% of sponsorship to YouTube Creators seem to be from VPN industry? What is that they know and we don't know?

In many countries, a VPN provider can be significantly more trustworthy than an ISP. In Germany, for example, you can have your home searched simply for insulting a politician. The ISP will then immediately hand over the data to the authorities, which most VPN providers do not do. The same goes for torrents. If some random law firm sends a letter to Telekom saying, “Hey, your customer downloaded a movie please give u…

That's very simplistic assumption. If the German state machinery is determined to get you, ISP and VPN provider have a threshold beyond which they'll give up.

Many many examples out there. "We don't keep logs" is not good enough neither realistic because how else a VPN provider is supposed to protect itself if it doesn't keep a log of what's happening inside and through its own systems.

Re: Mullvad exit IPs are surprisingly identifying

#234

Earlier quoted context omitted.

> Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings How to report a bug or vulnerability ... we (currently) have no bug bounty program ... send an email to support@mullvadvpn.net https://mullvad.net/en/help/how-report-bug-or-vulnerability / https://archive.vn/BeHhr

Not having a bug bounty or dedicated email address does not make it OK to go public immediately

Yes it does actually.

Re: Mullvad exit IPs are surprisingly identifying

#235

Earlier quoted context omitted.

it really isn’t.

Examples?

IP addresses are metadata - and don't require search warrants, meaning they are fair game for dragnet surveillance. Tapping into a backbone, a la Room 641A, can be used to cross-reference timestamped public posts on an anonymous message board to other data sources (e.g. subpoena Netflix for payer based of Netflix's access logs from VPN exit IPs)

Re: Mullvad exit IPs are surprisingly identifying

#236
post #177

Earlier quoted context omitted.

> The advantages for the user are, if they find a server that works for accessing some service they can connect to that server again and it will work again because they get the same IP. On the flip side, if they’re getting banned by a service because of a noisy neighbor on the same IP, they’d have no way to work around that, no?

You mean if the neighbor somehow burned every VPN location?

Doesn’t even need to be every location. Some services are only accessible from a single country, and Mullvad has at most a handful of locations per country.

All things considered, there are just an incredibly small number of IPs shared among all users, no matter the allocation strategy.

Re: Mullvad exit IPs are surprisingly identifying

#237
post #103
post #87

Earlier quoted context omitted.

Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?

That’s been my pet theory from day 1, and not because of DDoS. Simply because they are the SSL terminator for most of the internet and can see anything going on in cleartext (and I’ve seen them protecting some shady stuff) I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)” If NSA aren’t installed at Cloudflare, I wonde…

To add: apparently that PRISM slide got its own Knowyourmeme entry: https://knowyourmeme.com/memes/ssl-added-and-removed-here

Re: Mullvad exit IPs are surprisingly identifying

#238

Earlier quoted context omitted.

> Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings How to report a bug or vulnerability ... we (currently) have no bug bounty program ... send an email to support@mullvadvpn.net https://mullvad.net/en/help/how-report-bug-or-vulnerability / https://archive.vn/BeHhr

Not having a bug bounty or dedicated email address does not make it OK to go public immediately

Discovering a bug that could put people's lives and/or freedom at risk if they don't do something about it makes it okay to go public immediately. That said, by all means notify the maintainer/vendor as well.

It should always be assumed that someone else (if not several someone elses) have already discovered the same flaw and are currently taking advantage of it while users remain totally unaware of their actual risk. By going public immediately, you give as many of those users as possible a chance to protect themselves.

Waiting to disclose something harmful when the users in danger could otherwise take steps to make themselves safe would be like not warning people entering a building not to go in because of a gas leak until after you've contacted the building owner and the fire department has shown up.

Re: Mullvad exit IPs are surprisingly identifying

#239
post #180

Missing from the story: did they reach out to Mullvad? Would have been interesting to see how their security team responded.

As far as I can tell they did not, and I've asked both our operations and support teams. I will update this post if I am mistaken. Edit: In hindsight I regret making this comment. It was unnecessary, but removing it now would look weird.

Seems fine. You didn’t exactly demand a 90 day embargo or something.

Re: Mullvad exit IPs are surprisingly identifying

#240
post #154

Earlier quoted context omitted.

Within the realm of possibility? Let's be honest, if you are a top NSA executive and you couldn't find a way to get your hands on Cloudflare's private keys (bribing or threatening the right person), you are not getting your Christmas bonus.

Do people in government get bonuses linked to performance?

Government agencies get budgets linked to performance.
Post reply on HN