Live data from Hacker News

Mullvad VPN was subject to a search warrant – customer data not compromised

mullvad.net

281–290 of 345 posts

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#281
post #256

Earlier quoted context omitted.

I believe the "a fresh OS" makes fingerprinting useless.

Not really. Modern web browsers expose a lot of information, such as your language, time zone, screen resolution, CPU and GPU details (number of cores, vendor, model...), etc. There's even fingerprint which depends on your GPU driver version. If you use a custom built desktop computer, you're going to have a pretty unique browser fingerprint because few people will use the same exact hardware configuration. On the ot…

So, one could think a solution would be to not use modern browsers. But then this alone makes you stand out again I guess.

Maybe VPNs should start to offer “browser anonymization” as a service.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#282
post #130

Earlier quoted context omitted.

Briefly, non-US jurisdictions are not US jurisdictions and have different standards and procedures.

I think the comment was made under the assumption the user lives in a place with a reasonably fair legal system. Of course all bets are off if you don't.

[dead]

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#283

Earlier quoted context omitted.

HotPlug allows hot seizure and removal of computers from the field https://news.ycombinator.com/item?id=982930 (2009) https://wiebetech.com/products/hotplug-field-kit/

yes but requires the Police to have the right warrants and tools and the server to not detect it due to e.g. network disconnect, or you not giving it the latest versions of rooling keys etc.

I’d go with something MEMS based. Always safely shutdown your hardware if you sense an earthquake!

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#284
post #254

Earlier quoted context omitted.

Have legal representation show up quickly means nothing. Consider the many, many scenarios where search warrants are served on companies with in house legal. Law firms. Individual lawyers. Literally happens every single day. Law enforcement has a warrant signed by a judge. Just because a lawyer of some sort is there doesn't mean they're going to stand around paralyzed saying "Oh there's a lawyer here, better stop wha…

Maybe in Sweden, telling and proving to the prosecutor "I simply do not have what you want, and I can show you" works better than elsewhere.

I don't know where this perspective of "Sweden has so many rights and protections the legal system is parallel to general practice in the rest of the world" comes from.

See Julian Assange[0].

[0] - https://en.wikipedia.org/wiki/Assange_v_Swedish_Prosecution_...

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#286

Earlier quoted context omitted.

I’ve got no real insight, but my guess would be that a) the goons have both technical and legal competence and b) Mullvad had legal representation show up quickly.

Have legal representation show up quickly means nothing. Consider the many, many scenarios where search warrants are served on companies with in house legal. Law firms. Individual lawyers. Literally happens every single day. Law enforcement has a warrant signed by a judge. Just because a lawyer of some sort is there doesn't mean they're going to stand around paralyzed saying "Oh there's a lawyer here, better stop wha…

I don't know how things work in Sweden, but I wouldn't be surprised if this process was more reasonable than in the US.

It's funny how much we talk about the 4th amendment and due process, when our level of due process is actually not that great. If police come knocking at your door in the US, they are likely to trend toward the most extreme actions they can get away with. That doesn't need to be how things work, and I wouldn't be surprised to learn that law enforcement behaves better somewhere like Sweden.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#287

I don't understand why go after the VPN, I think most people don't use a VPN correctly. What good is a VPN when multiple apps on your computer are phoning home? If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP? To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to…

I personally use a bunch of VMs for web browsing, all with different exit IPs. And yes, a lot of people use VPNs but don't use them correctly. But I'd rather help them to use them more effectively, rather than shout down that VPNs "don't work". And even when they're not used correctly, most people don't have particularly omniscient threats. And even imperfect use still helps everyone else by creating cover traffic, a…

You use Qubes OS?

Otherwise, a lot of ram, CPU and storage might be needed.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#288
post #285

What if the law enforcement, instead of saying give me your logs, rephrase it slightly and says, start logging this IP address and then give me your logs? They can do whatever they want.

A warrant can compel the seizure of existing evidence, but I don't know if it legally can compel the creation of new evidence by a 3rd party. At least in the US. I'm sure there are exceptions under various anti-terrorism laws, but in general it seems like the government can't compel corporations or individuals to assist in it's investigations.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#289

Earlier quoted context omitted.

> Mullvad could have been, and maybe even still is, lying about how they operate Could they? Sure. Do they have anything on me? * One BTC transfer * IPs where I'm connecting from (if they are lying and storing them) * My traffic (if they are lying and storing it) * My unencrypted traffic (if they are lying and storing it) Do they have ... on me? * Email? - nope * Phone number? - nope * Credit card? - nope * My first…

Unless you're using another VPN/proxy/Tor/... to connect to the VPN, the IP where you're connecting from (respectively the full 4-tuple including source/destination port) likely does identify your address.

Of course. It doesn't help what I'm getting pretty much the same IPs from my provider.

Double (triple|quad) hop, tied to different entities is necessary if you want at least plausible deniability. Thankfully I don't do things what may be of the interest of someone who can raid Mullvad offices.

But I recently discovered a VPS provider who only needs an email address to confirm an order, so it can be used as a bootstrap for a something pretty anonymous. Still needs an email, but as I said in some other comment recently, you can do that (if you are okay with leaving some traces) with a Google device with WiFi only capability.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#290

Earlier quoted context omitted.

> What good is a VPN when multiple apps on your computer are phoning home? The point of a VPN is that whenever an app phone home, they will do so through the VPN. Standard VPN configuration (which I supose the Mullvad client performs?) is to entirely disallow any traffic that doesn't go through the VPN

You're missing the reason this is important - the companies that run those apps (spotify, facebook, steam, discord, etc.) will be able to correlate your VPN connection with your non-VPN connection, and tie those both to an app account that identifies you. It means unless you've got a dedicated download/seed box running your torrent downloads, one that doesn't have anything else on it and never connects to anything wi…

Another easier option is to run the VPN client and torrent client in a Docker container, with networking separate from the host machine. Then the only thing using the VPN is the torrent client.
Post reply on HN