Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

281–290 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#281
post #258

Earlier quoted context omitted.

It already has official packaging for Tumbleweed, see https://github.com/mullvad/mullvadvpn-app/issues/2242 for the upstream issue. Leap can use the normal Linux application, you will just have to provide the dependencies yourself.

https://mullvad.net/en/help/install-mullvad-app-linux >The Mullvad VPN app is available in our repository for the following supported Linux distributions: Ubuntu (24.04+) Debian (12+) Fedora (42+) The only thing I see on the issue you linked is a way to jerry-rig the fedora package. When I tried that I kept getting untrusted key warnings. You can skip them of course, but it kind of undermines any type of trust here

> When I tried that I kept getting untrusted key warnings. You can skip them of course, but it kind of undermines any type of trust here

Yes, the expected procedure would be to trust those keys for that package instead of disabling integrity checks.

This is an issue between you and your package manager and not something Mullvad or any other packager (except OpenSUSE maintainers) can fix for you.

You complain about the packaging and support of mullvad maintainers when you are having skill issues with your distro.

https://github.com/mullvad/mullvadvpn-app/issues/2242#issuec...

Re: Mullvad exit IPs are surprisingly identifying

#282

Earlier quoted context omitted.

Are you seriously suggesting people shouldn't operate with a bit of common decency unless they're going to get some money out of it?

Most of HN readers/writers are American, of course they won't do anything unless they personally profit off it, the entire culture is built around this mindset. Meanwhile, Mullvad is Swedish, and we tend to assume we all want to help build a better world together. Mix the two, and you get this conversation :)

I would hesitate to make generalizations like that about a country with a population 35x larger than yours. There’s no US monoculture.

Re: Mullvad exit IPs are surprisingly identifying

#284

Earlier quoted context omitted.

> All the companies involved in PRISM made public statements saying they ceased participation. Google undertook a costly initiative to add encrypted connections over their datacenter circuits This is as helpful as Whatsapp's so called E2E encryption comms (that just happens to not be applicable by default in certain situations).

What are those certain situations?

Backups are not encrypted by default. It just takes a single person on the other side of the chat not enabling e2e for your messages to be readable.

Meta data is also not encrypted. Your messaging graph is known to Whatsapp including message timestamps.

Also, IIRC, they (Meta) could also partially bypass the e2e (they can't access past messages but they can receive future messages) without you noticing (unless you have certain settings on whatsapp enabled, settings most people don't even know they exist).

The new feature of sharing past messages with new arrivals to a group also further widens the potential scope of messages leaking.

Re: Mullvad exit IPs are surprisingly identifying

#285

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

Why? If I was an intelligence agency and designing a VPN I would simply log all the IPs connecting to my VPN and not rely on statistics on exit nodes to identify the users, even more so because they rely on the users to pick different servers.

It's not even a hypothetical, this has already happened at least once: https://en.wikipedia.org/wiki/Operation_Trojan_Shield

Re: Mullvad exit IPs are surprisingly identifying

#286

Earlier quoted context omitted.

Are you seriously suggesting people shouldn't operate with a bit of common decency unless they're going to get some money out of it?

This ought not be considered anything close to common courtesy. This is work. Mullvad is engaged in the business of making money. They should show how serious they are with your money. Since when do you have professionals giving you examinations out of common courtesy? Out of courtesy can I get a free cancer screening?

If I doctor performed a cancer screening on me, for free and without me asking, then yes — as a matter of courtesy I would still expect that doctor to tell me if he found cancer, rather than reading about it on his blog later.

Re: Mullvad exit IPs are surprisingly identifying

#287

Earlier quoted context omitted.

My understanding is that they tapped communication nodes before. I would be surprised if they can't tap the pipes to cloudflare.

I mean, it is the CIA, but if you encrypt it before it leaves the box, and you're decent good with the key material, how are they going to get at it? Tapping the fiber then gets them encrypted flows, which isn't nothing, but, well, it would be surprising if they had access to the clear text.

Room 641A [1] would be an example of just renting a room in the DC, making it look as boring and nondescript as possible, tap the fiber lines and send a copy of all data to that room

That requires cooperation from a couple people at the company. People that could do it for "patriotic duty", be payed off, simply be coerced, or be replaced by NSA agents (I wonder how many cloudflare employees are NSA plants?). If you want to go even more low-profile, tap the fiber lines a block further down outside the cloudflare PoP and use one of the above techniques to get the key material

Even if it takes the NSA a decade to get an NSA agent hired and moved up in the organization until they have a vector to extract private keys that's still an incredible return on investment

1: https://en.wikipedia.org/wiki/Room_641A

Re: Mullvad exit IPs are surprisingly identifying

#288

Earlier quoted context omitted.

Are you seriously suggesting people shouldn't operate with a bit of common decency unless they're going to get some money out of it?

This ought not be considered anything close to common courtesy. This is work. Mullvad is engaged in the business of making money. They should show how serious they are with your money. Since when do you have professionals giving you examinations out of common courtesy? Out of courtesy can I get a free cancer screening?

>Since when do you have professionals giving you examinations out of common courtesy?

Maybe when they decide on their own volition, without any external pressure, to go and poke around your system?

"Hey, I'm a mechanic, I was looking at your car parked out there and noticed something incredibly dangerous that needs immediate fixing. I'll tell you what it is for $1,000."

Please...

Re: Mullvad exit IPs are surprisingly identifying

#289

Earlier quoted context omitted.

> Most of HN readers/writers are American, of course they won't do anything unless they personally profit off it, the entire culture is built around this mindset American culture is highly varied. For some this is true, for others this is wrong and highly insulting. Maybe try a narrower brush next time.

It's OK for the country to have a pervasive culture yet not every resident or citizen of the country to be a part of that culture, or even actively work against it. If you're not one of them matching that description, it shouldn't be insulting, as it's not about you in the first place. Maybe not everything is aimed towards you, especially if you don't feel like the description actually matches you :)

Sweden, the entire country, has the population of New York City, and is about 3/4 the size of Texas.

Re: Mullvad exit IPs are surprisingly identifying

#290

Earlier quoted context omitted.

What are those certain situations?

Backups are not encrypted by default. It just takes a single person on the other side of the chat not enabling e2e for your messages to be readable. Meta data is also not encrypted. Your messaging graph is known to Whatsapp including message timestamps. Also, IIRC, they (Meta) could also partially bypass the e2e (they can't access past messages but they can receive future messages) without you noticing (unless you ha…

> Backups are not encrypted by default

And it is very difficult to back them up anywhere other than a secret bucket at Google

Also they say messages are E2E encrypted. I don't recall that page saying anything about what happens at rest. Presumably the Meta AI will have, or already has access to them.

Post reply on HN