Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

301–310 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#301
post #282

Earlier quoted context omitted.

Most of HN readers/writers are American, of course they won't do anything unless they personally profit off it, the entire culture is built around this mindset. Meanwhile, Mullvad is Swedish, and we tend to assume we all want to help build a better world together. Mix the two, and you get this conversation :)

I would hesitate to make generalizations like that about a country with a population 35x larger than yours. There’s no US monoculture.

LOL. Sure there's no "monoculture" but there's certainly US culture and it's all about money and "screw you got mine" mindset.

Re: Mullvad exit IPs are surprisingly identifying

#302
post #297

Earlier quoted context omitted.

I don't feel like its hard to come up with examples where (I would say) its ethically wrong to disclose immediately. If you spotted a company's mistake that might endanger their user's lives or safety, would you put those users at risk simply because there was no obvious financial reward? If so, I guess we just have different opinions on the ethics involved here.

If you are talking about some open source project then I would fully agree. But when it comes to money making corporations then personally I dont agree that revealing flaws in their product comes into ethics at all. A companies paid product is flawed, their own paid engineers didnt figure that out, why should I do it for free becasue 'ethics'? This is the entire reason bug bounty programs exist in the first place.

You seem to have a very bright line between the acceptable behavior for “no money involved” and “money involved”.

For me, it’s more subtle than that.

Everybody (“almost all software”) has exploitable bugs. Are you a fool for not finding the ones in yours? Maybe. Sometimes.

There is a huge difference between Project Zero finding a trivial vulnerability almost identical to one reported months earlier (close to negligence) and Mullvad having the CEO personally posting a response here in a very calm tone.

Re: Mullvad exit IPs are surprisingly identifying

#303
post #297

Earlier quoted context omitted.

If you are talking about some open source project then I would fully agree. But when it comes to money making corporations then personally I dont agree that revealing flaws in their product comes into ethics at all. A companies paid product is flawed, their own paid engineers didnt figure that out, why should I do it for free becasue 'ethics'? This is the entire reason bug bounty programs exist in the first place.

You seem to have a very bright line between the acceptable behavior for “no money involved” and “money involved”. For me, it’s more subtle than that. Everybody (“almost all software”) has exploitable bugs. Are you a fool for not finding the ones in yours? Maybe. Sometimes. There is a huge difference between Project Zero finding a trivial vulnerability almost identical to one reported months earlier (close to negligen…

> Are you a fool for not finding the ones in yours?

If I have a company which sells a paid product, and my paid engineers do not find bugs then I absolutely do not expect the public to willfully and freely make my product better for me. This is why I would have a bug bounty program as an incentive for the public to help me makle my product better and more secure, like any other company serious about finding security bugs.

If I didnt have a bug bounty program and found out that some black hats were selling backdoors to my system online, I would consider that fully my fault for not incentivizing those hackers against doing so.

Re: Mullvad exit IPs are surprisingly identifying

#304
post #281

Earlier quoted context omitted.

https://mullvad.net/en/help/install-mullvad-app-linux >The Mullvad VPN app is available in our repository for the following supported Linux distributions: Ubuntu (24.04+) Debian (12+) Fedora (42+) The only thing I see on the issue you linked is a way to jerry-rig the fedora package. When I tried that I kept getting untrusted key warnings. You can skip them of course, but it kind of undermines any type of trust here

> When I tried that I kept getting untrusted key warnings. You can skip them of course, but it kind of undermines any type of trust here Yes, the expected procedure would be to trust those keys for that package instead of disabling integrity checks. This is an issue between you and your package manager and not something Mullvad or any other packager (except OpenSUSE maintainers) can fix for you. You complain about th…

It's a skill issue that they decide to not list open suse as a supported distro on their own help page ?

It's a skill issue that the thread has a bunch of different solutions and none of them are definitive and endorsed by the company I'm paying $5 a month too ?

Re: Mullvad exit IPs are surprisingly identifying

#305

Earlier quoted context omitted.

> Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings How to report a bug or vulnerability ... we (currently) have no bug bounty program ... send an email to support@mullvadvpn.net https://mullvad.net/en/help/how-report-bug-or-vulnerability / https://archive.vn/BeHhr

Are you seriously suggesting people shouldn't operate with a bit of common decency unless they're going to get some money out of it?

I dislike it here because I like Mullvad, but yes, I think it’s fair to go straight to public disclosure.

Someone with likely substantial qualifications put in time to find this. The company is in it for profit (at least partially). What’s fair for the company is fair for the individual. The company can either offer to pay for bugs under the terms they want, hire more security folks to find the bugs themselves, or just accept that researches get to do whatever they want with their findings.

I’d tell Mullvad, but there are companies I don’t respect enough to feel compelled to give them a heads up. Perhaps the author feels that way about Mullvad, it’s entirely within their right to use this to publicly shame Mullvad.

Re: Mullvad exit IPs are surprisingly identifying

#307
post #282

Earlier quoted context omitted.

I would hesitate to make generalizations like that about a country with a population 35x larger than yours. There’s no US monoculture.

Great, thanks for the tip. I'd hesitate assuming what country people live in :) Seems we all have something to learn from each other.

> Meanwhile, Mullvad is Swedish, and we tend to [...]

Re: Mullvad exit IPs are surprisingly identifying

#308

Earlier quoted context omitted.

VPNs are not snake oil. They transfer the trust of your internet activity from a place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad, IVPN, or Proton. Among other benefits. If you don't like your ISP creating a profile of you and selling it to target ads to you, you should use a VPN. >Should I use a VPN? Yes, almost certainly. A VPN has many advantages, including: 1. Hiding…

Marcus Hitchens (security researcher who blackholed the WannaCry ransomware domain) made a post on LinkedIn today comparing VPNs to snake oil. With regard to the way they're advertised in internet ads, they are. VPNs will not protect ordinary users from ad tracking or commercial data mining. They're marketed as a privacy tool when their privacy value is very limited. VPNs are useful for the reasons you mentioned.

It can be a factual statement about the commercial VPN landscape at large, but an incorrect statement about many individual VPN providers. It lacks nuance as a statement.

Re: Mullvad exit IPs are surprisingly identifying

#309
post #307

Earlier quoted context omitted.

Great, thanks for the tip. I'd hesitate assuming what country people live in :) Seems we all have something to learn from each other.

> Meanwhile, Mullvad is Swedish, and we tend to [...]

So what, suddenly Swedes can't live outside of Sweden? Kind of interesting to make complaints about generalizations and in the same comment falling for the same trap yourself.

Re: Mullvad exit IPs are surprisingly identifying

#310
post #295

Earlier quoted context omitted.

If I doctor performed a cancer screening on me, for free and without me asking, then yes — as a matter of courtesy I would still expect that doctor to tell me if he found cancer, rather than reading about it on his blog later.

> If I doctor performed a cancer screening on me, for free and without me asking But that would never happen, so the point is moot.

I have known doctors and lawyers and many others to do work pro-bono
Post reply on HN