Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

241–250 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#241

Earlier quoted context omitted.

Not having a bug bounty or dedicated email address does not make it OK to go public immediately

Discovering a bug that could put people's lives and/or freedom at risk if they don't do something about it makes it okay to go public immediately. That said, by all means notify the maintainer/vendor as well. It should always be assumed that someone else (if not several someone elses) have already discovered the same flaw and are currently taking advantage of it while users remain totally unaware of their actual risk…

> Expecting people to hold off on disclosure of something harmful

That's not what they said though. They said "please consider notifying the maintainer/vendor before publishing your findings, even if you intend to publish right away" (emphasis mine)

Re: Mullvad exit IPs are surprisingly identifying

#242
post #241

Earlier quoted context omitted.

Discovering a bug that could put people's lives and/or freedom at risk if they don't do something about it makes it okay to go public immediately. That said, by all means notify the maintainer/vendor as well. It should always be assumed that someone else (if not several someone elses) have already discovered the same flaw and are currently taking advantage of it while users remain totally unaware of their actual risk…

> Expecting people to hold off on disclosure of something harmful That's not what they said though. They said "please consider notifying the maintainer/vendor before publishing your findings, even if you intend to publish right away " (emphasis mine)

I do think hitting "send" on the email to the responsible party immediately before publishing (or at least notifying them as quickly as you can afterwards) is a smart thing to do. I mean, why wouldn't you? My concern was more about the "Not having a bug bounty or dedicated email address does not make it OK to go public immediately" comment. It can sometimes be difficult to track down the right person to notify and so when the risks to people are high enough whichever one you can accomplish the soonest is probably where I'd start.

Re: Mullvad exit IPs are surprisingly identifying

#243
post #234

Earlier quoted context omitted.

Not having a bug bounty or dedicated email address does not make it OK to go public immediately

Yes it does actually.

I don't feel like its hard to come up with examples where (I would say) its ethically wrong to disclose immediately. If you spotted a company's mistake that might endanger their user's lives or safety, would you put those users at risk simply because there was no obvious financial reward?

If so, I guess we just have different opinions on the ethics involved here.

Re: Mullvad exit IPs are surprisingly identifying

#244
post #87

Earlier quoted context omitted.

Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?

Yeah, their origin is a story of absolute incredible luck. Cloudflare came out of nowhere and suddenly massive sites with huge user bases around the world, including places like 4chan, were getting DDoSed. Then they immediately announce that they transitioned to Cloudflare. Hell of a lucky time to make a company that the entire internet suddenly became absolutely dependent on. The funny thing about that era is you kn…

> as the late great HN commenter Terry Davis would've said.

Oh my god, this is how & when I realize that Terry Davis (Rest in peace) used to use Hackernews too: https://news.ycombinator.com/threads?id=TerryADavis

https://news.ycombinator.com/item?id=10061171 (From this comment written by terry):

"I wrote all the code from scratch, including a 20,000 line of code compiler that makes x86_64 machine code from HolyC or Asm and operates AOT and JIT.

My JIT mode is not interpreted. It optimizes and compiles to x86_64 machine code.

I was chosen by God because I am the best programmer on the planet and God boosted my IQ with divine intellect." -Terry A Davis.

Re: Mullvad exit IPs are surprisingly identifying

#245

Earlier quoted context omitted.

Is this your service? Since you've made seven posts to HN about it and also your username shows up in the commits on their GitHub. Because I'm quite curious on where the IPs are from. Usually residential IPs is a fancy wording for malware infested devices from regular people.

> Since you've made seven posts to HN about it Do you have a tool to text search a user's comment history? Your comment is very specific: "seven"!

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

(Seems to have some weird cache issues though, had to play around with the ?querystring part to get more results)

Re: Mullvad exit IPs are surprisingly identifying

#246

Earlier quoted context omitted.

Not having a bug bounty or dedicated email address does not make it OK to go public immediately

Discovering a bug that could put people's lives and/or freedom at risk if they don't do something about it makes it okay to go public immediately. That said, by all means notify the maintainer/vendor as well. It should always be assumed that someone else (if not several someone elses) have already discovered the same flaw and are currently taking advantage of it while users remain totally unaware of their actual risk…

> Discovering a bug that could put people's lives and/or freedom at risk if they don't do something about it makes it okay to go public immediately

The flipside of course is ... does your disclosure increase the risk?

> aiting to disclose something harmful when the users in danger could otherwise take steps to make themselves safe would be like not warning people entering a building not to go in because of a gas leak until after you've contacted the building owner and the fire department has shown up

I don't think it's like this at all. The risk of a gas leak is not increased by telling people about it and can't be prevented after its occurred. To stretch your analogy, I'd say its more like you've found the gas leak and instead of turning off the gas supply are instead running around outside the building shouting about how there's a gas leak.

Re: Mullvad exit IPs are surprisingly identifying

#247
post #211

Earlier quoted context omitted.

> Is this your service? Since you've made seven posts to HN about it and also your username shows up in the commits on their GitHub. Ohh, that makes sense haha. @m00dy: please disclose when you’re talking about your own projects! It’s okay to plug your stuff sometimes, just be honest about it :-)

I’m not hiding anything :-)

No, but you weren’t upfront about it either. I’ve suspected it looked like your own project but checked your comments in the profile and didn’t see any other, so I didn’t dig any deeper.

> I’m not here to promote anything just wanted to share a valid use case in the right context.

There’s a small difference: if one of your users did this it would be totally fair, but when a founder does this I think it’s a polite thing to disclose it. That’s what I’ve been doing when talking about my own project on HN [1], and I think in most cases other legit founders just say that upfront, too. I’m not sure if that breaks any rules, but it feels juuuuust a bit shady not to :-)

[1]: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

Re: Mullvad exit IPs are surprisingly identifying

#248
"identifying" is the wrong word here--that's only possible if Mullvad stores a mapping between IP addresses and people, which according to them, a 3rd party audit, and a law enforcement raid they do not. It's also worth saying it's possible to use Mullvad entirely anonymously by mailing them cash, which I do.

Also if the threat model you're addressing w/ VPN usage is anything other than "I don't want my ISP to know what I'm doing" you need to use/do something else.

Re: Mullvad exit IPs are surprisingly identifying

#249

Earlier quoted context omitted.

I think you are misreading his comment. He is saying that on a VPN it is standard behavior that if you visit site A and site B they will both see you connecting from the same IP and can infer you are potentially the same person.

Site A and B have to collude in order to make that inference. Outside of Cloudflare, no one is colluding at that level.

Plenty of people own more than one website. You're also forgetting about random site assets like web fonts, CSS, JavaScript CDNs, etc. etc.

Re: Mullvad exit IPs are surprisingly identifying

#250
post #103
post #87

Earlier quoted context omitted.

Yeah I'm sure one day it will transpire Cloudflare is affliated with intelligence agencies too. The solution to a "sudden DDoS" is to put their website behind Cloudflare. Wonder who can do those sudden attacks?

That’s been my pet theory from day 1, and not because of DDoS. Simply because they are the SSL terminator for most of the internet and can see anything going on in cleartext (and I’ve seen them protecting some shady stuff) I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)” If NSA aren’t installed at Cloudflare, I wonde…

> I’ve seen them protecting some shady stuff

Hmm do we want them to decide what stuff is shady and what isn't?

We're already allowing payment processors to do that and it's not good.

Post reply on HN