Mullvad VPN was subject to a search warrant – customer data not compromised
291–300 of 345 posts
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#292Full title: Mullvad VPN was subject to a search warrant. Customer data not compromised As a customer, I have no doubt about the "customer data not compromised". I'm a paying customer, yet I have never given them any PII. Great service.
> I'm a paying customer, yet I have never given them any PII. By nature, every VPN gets at least the IP you are connecting from and the IPs (and almost always also hostnames) you are connecting to. I'd consider that PII.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#293Earlier quoted context omitted.
It's likely not the kind of data they were after so there was no point in seizing equipment.
Police investigations regarding 6+ officers showing up at your office do not end with “oh have a good day.”
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#294Earlier quoted context omitted.
Technically they could have been logging your traffic, which is “customer data” even if it doesn’t identify you by name
Does anyone here know how to corroborate Mullvad's account of this event? Perhaps we can find the Swedish entity that wrote the warrant and any public information reported by the officers executing said warrant? If such information is publicly accessible, and it corroborates Mullvad's story here, I'd feel like that's pretty compelling evidence that we can trust that Mullvad isn't simply committing fraud by promising…
You can contact the “Åklagarmyndigheten” (the Swedish prosecutor authority) and ask them and they’ll help you out. Generally speaking it is pretty easy to get information from government agencies in Sweden due to our constitution. Everything is public by default, with some exceptions like military secrets. I think it shouldn’t be a problem for the prosecutor to confirm they had a warrant at Mullvads office, and maybe even to confirm they didn’t seize anything, unless they think it could harm the ongoing investigation somehow.
[0] https://www.aklagare.se/om_rattsprocessen/fran-brott-till-at...
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#295Earlier quoted context omitted.
I did notice that phrase doing a lot of work there. I'm actually super curious: when a bunch of goons turn up on your doorstep fully expecting to cart away boxes of electronics, /how on earth/ do you "demonstrate that this is indeed how our service works", there and then on the spot, in a sufficiently convincing manner that they leave again empty-handed?
I’ve got no real insight, but my guess would be that a) the goons have both technical and legal competence and b) Mullvad had legal representation show up quickly.
If they want to be massive schmucks they could in theory cart off with every server in the building, but they're also not supposed to do this, because the warrant is to seize particular things, and should be something like "servers containing the data of X user" and not just "servers" if the judge is doing what they ought to do.
The police also don't really want to cart off a thousand tons of irrelevant equipment, because it's physical labor and they have to do paperwork to catalog it and it takes up a lot of space in their evidence room. The main reason they do this in practice is to grief the target of the investigation, or to be more charitable, to make sure the target of the investigation isn't lying about which equipment is relevant. But that doesn't really apply when they're searching the building of some independent third party who has done nothing wrong and has more to lose by making false statements to the police than by the police finding what they're looking for.
So what they might do instead is ask the company which servers have relevant data on them. And if the true answer to that question is none, well, that should be the end of it.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#296Earlier quoted context omitted.
And yet you trust WhatsApp and Facebook and Signal with their claims of end-to-end encryption. Why?
i never said you shouldn't ever trust anything. I personally do trust mullvad. I've been using it for over a decade. I'm just not in denial over the fact that there is trust required. Second of all, aside from signal which I have superficially played around with, I don't and have never used any of those services you mentioned and they have absolutely nothing to do with the topic at hand so maybe you can tell me why y…
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#297Earlier quoted context omitted.
Not really. Modern web browsers expose a lot of information, such as your language, time zone, screen resolution, CPU and GPU details (number of cores, vendor, model...), etc. There's even fingerprint which depends on your GPU driver version. If you use a custom built desktop computer, you're going to have a pretty unique browser fingerprint because few people will use the same exact hardware configuration. On the ot…
So, one could think a solution would be to not use modern browsers. But then this alone makes you stand out again I guess. Maybe VPNs should start to offer “browser anonymization” as a service.
At least that's been my experience. In fact, I've even encountered problems while using Chromium and Firefox on Linux, just because some sites didn't like the user agent.
In short, to use the modern web you need a modern browser, and modern browsers are very leaky and fingerprintable by design.
> Maybe VPNs should start to offer “browser anonymization” as a service.
The problem is that they'd need to render the website server-side and then serve it to you. That has their own problems, as the VPN provider now has total control of all web content you see.
That already exists, by the way: https://www.puffin.com/secure-browser
I'd say the most realistic options to avoid browser fingerprinting is either using Apple hardware or sandboxing the browser inside a virtual machine. And it's better to use Chrome because it has the most users by a large margin. Firefox, Brave and the new Mullvad browser do implement some anti-fingerprint mitigations, but they have few users so you'll stick out more.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#298Earlier quoted context omitted.
They've invested a lot of resources in what they call "diskless infrastructure", as in everything's in server's RAM. I presume it wouldn't be difficult to argue that as soon as you shut off a server to transfer it away, things they're looking for would be lost.
HotPlug allows hot seizure and removal of computers from the field https://news.ycombinator.com/item?id=982930 (2009) https://wiebetech.com/products/hotplug-field-kit/
The problem with disks is they're hard to securely erase. Some NAT mapping gets written to a log or swap file and then you overwrite it but the device silently reallocated that sector and the old one is still there. DRAM doesn't do that. Then if you e.g. power cycle the machine once a day, it never contains data more than a day old.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#299Earlier quoted context omitted.
> their entire business depends on them not doing it... ... in a way that you, as a customer, can detect. 1. You can't have any hard guarantees about what information is retained by third parties about you. 2. As other comments here have pointed out, something smells a bit weird with this.
How profound. So what is your alternate theory of what is happening here?
If you're interested in hiding from civil snoops (RIAA, MPAA), by all means, use one. If you're interested in hiding from a government, then by all means, keep rolling the honeypot dice.
Re: Mullvad VPN was subject to a search warrant – customer data not compromised
#300I don't understand why go after the VPN, I think most people don't use a VPN correctly. What good is a VPN when multiple apps on your computer are phoning home? If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP? To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to…
A request to MS asking for who had a given IP address at a certain time could return multiple devices in different countries/states/cities. Narrows things down significantly, but not always a dead give away.