Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

251–260 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#251

Earlier quoted context omitted.

Discovering a bug that could put people's lives and/or freedom at risk if they don't do something about it makes it okay to go public immediately. That said, by all means notify the maintainer/vendor as well. It should always be assumed that someone else (if not several someone elses) have already discovered the same flaw and are currently taking advantage of it while users remain totally unaware of their actual risk…

> Discovering a bug that could put people's lives and/or freedom at risk if they don't do something about it makes it okay to go public immediately The flipside of course is ... does your disclosure increase the risk? > aiting to disclose something harmful when the users in danger could otherwise take steps to make themselves safe would be like not warning people entering a building not to go in because of a gas leak…

> The flipside of course is ... does your disclosure increase the risk?

When you've got that much on the line you have to assume that the risk is already present for all users. It's true that there's always a chance that some users won't find your disclosure in time and additional would-be attackers who weren't aware of it already will start taking advantage of the flaw, but the alternative is that no users are safe.

> The risk of a gas leak is not increased by telling people about it and can't be prevented after its occurred.

It's true that warning people not to enter wouldn't make the gas more dangerous, but it limits the death count of the impending explosion. It keeps at least some people from entering the building and walking into a death trap.

There's no way to shut off the gas supply when you can't control what's already running on user's devices and more users are downloading and installing the buggy code all the time. It's really not a perfect analogy. The point is that immediate action will save some people, while waiting around means that nobody has a chance of being saved.

Re: Mullvad exit IPs are surprisingly identifying

#252

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. I don't see how the author is arriving at this…

Say your forum is a big one and has 1000 active users, with 1 joining every day. Most will be a lot smaller/less active. What are the chances that someone uses this vpn, joins your forum the day after someone was banned, and has an ip in a similar range? For most small websites this would be strong evidence.

I think you are (informally and correctly) doing Bayes theorem here. The prior is combined with the conditional to give the posterior estimate; the conditional is not itself the estimate.

Re: Mullvad exit IPs are surprisingly identifying

#253

Earlier quoted context omitted.

> Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings How to report a bug or vulnerability ... we (currently) have no bug bounty program ... send an email to support@mullvadvpn.net https://mullvad.net/en/help/how-report-bug-or-vulnerability / https://archive.vn/BeHhr

Not having a bug bounty or dedicated email address does not make it OK to go public immediately

if they don't think it's OK, then they should have a bug bounty program.

why are companies so entitled to get free security research/audits?

Re: Mullvad exit IPs are surprisingly identifying

#254
post #241

Earlier quoted context omitted.

> Expecting people to hold off on disclosure of something harmful That's not what they said though. They said "please consider notifying the maintainer/vendor before publishing your findings, even if you intend to publish right away " (emphasis mine)

I do think hitting "send" on the email to the responsible party immediately before publishing (or at least notifying them as quickly as you can afterwards) is a smart thing to do. I mean, why wouldn't you? My concern was more about the "Not having a bug bounty or dedicated email address does not make it OK to go public immediately" comment. It can sometimes be difficult to track down the right person to notify and so…

Oh yeah fair enough

Re: Mullvad exit IPs are surprisingly identifying

#255
post #178

I work at Mullvad. (co-CEO, co-founder) Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post's findings you may get confusing results throughout the day. We will also re-evaluate wheth…

Can we have an Open Suse client.

Sorta odd you don't support one of Europe's most popular distros.

Re: Mullvad exit IPs are surprisingly identifying

#256
post #158

Earlier quoted context omitted.

I could just...lie.

One person can tell a lie, but a company consists of many people. You must ensure that only few people know of the logging or there will be a risk of a leak.

leakers and whistleblowers are extremely rare. History is filled with examples of conspiracies involving many people that went on for long periods of time before one person eventually risked everything and said something. The Tuskegee Experiment went on for like 40 years! If keeping secrets were all that hard none of them would have been allowed to go on as long as they did.

Re: Mullvad exit IPs are surprisingly identifying

#257

Earlier quoted context omitted.

my llm api traffic terminates tcp at cloudflare in lovely plain text :/ it does give better peering. reduces latency a bit for me.

I had no idea that this was a thing. How can you figure out where SSL turns into plain text on its route to the destination?

in this case it's my design to use cloudflare.

but you can also see from curl or traceroute, that the endpoint you talked to was a cloudflare ip and your ssl ended there. after that you can't see inside cloudflare.

Re: Mullvad exit IPs are surprisingly identifying

#258
post #178

I work at Mullvad. (co-CEO, co-founder) Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post's findings you may get confusing results throughout the day. We will also re-evaluate wheth…

Can we have an Open Suse client. Sorta odd you don't support one of Europe's most popular distros.

It already has official packaging for Tumbleweed, see https://github.com/mullvad/mullvadvpn-app/issues/2242 for the upstream issue. Leap can use the normal Linux application, you will just have to provide the dependencies yourself.

Re: Mullvad exit IPs are surprisingly identifying

#259
post #240

Earlier quoted context omitted.

Do people in government get bonuses linked to performance?

Government agencies get budgets linked to performance.

Well - do they? In my experience they get budgets for spending their current budget.

Re: Mullvad exit IPs are surprisingly identifying

#260
post #167

Earlier quoted context omitted.

It is of course inconceivable that the NSA do not have the private keys for dozens of browser trusted certificate authorities That nonetheless doesn't help them unless they are doing active MITM. In order to do that they'd have to have at least some physical presence at Cloudflare or on the path to Cloudflare.

My understanding is that they tapped communication nodes before. I would be surprised if they can't tap the pipes to cloudflare.

I mean, it is the CIA, but if you encrypt it before it leaves the box, and you're decent good with the key material, how are they going to get at it? Tapping the fiber then gets them encrypted flows, which isn't nothing, but, well, it would be surprising if they had access to the clear text.
Post reply on HN