I work at Mullvad. (co-CEO, co-founder) Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post's findings you may get confusing results throughout the day. We will also re-evaluate wheth…
Mullvad exit IPs are surprisingly identifying
311–320 of 408 posts
Re: Mullvad exit IPs are surprisingly identifying
#312Re: Mullvad exit IPs are surprisingly identifying
#313Earlier quoted context omitted.
Why? If I was an intelligence agency and designing a VPN I would simply log all the IPs connecting to my VPN and not rely on statistics on exit nodes to identify the users, even more so because they rely on the users to pick different servers.
It's not even a hypothetical, this has already happened at least once: https://en.wikipedia.org/wiki/Operation_Trojan_Shield
yeah, spicy
Re: Mullvad exit IPs are surprisingly identifying
#314Re: Mullvad exit IPs are surprisingly identifying
#315Earlier quoted context omitted.
> Most of HN readers/writers are American, of course they won't do anything unless they personally profit off it, the entire culture is built around this mindset American culture is highly varied. For some this is true, for others this is wrong and highly insulting. Maybe try a narrower brush next time.
It's OK for the country to have a pervasive culture yet not every resident or citizen of the country to be a part of that culture, or even actively work against it. If you're not one of them matching that description, it shouldn't be insulting, as it's not about you in the first place. Maybe not everything is aimed towards you, especially if you don't feel like the description actually matches you :)
Re: Mullvad exit IPs are surprisingly identifying
#316Re: Mullvad exit IPs are surprisingly identifying
#317Earlier quoted context omitted.
Are you seriously suggesting people shouldn't operate with a bit of common decency unless they're going to get some money out of it?
When their 'common decency' is directly benefiting a money making corporation with shareholders and directors then yes they should definitely get some money out of it.
Re: Mullvad exit IPs are surprisingly identifying
#318Missing from the story: did they reach out to Mullvad? Would have been interesting to see how their security team responded.
Re: Mullvad exit IPs are surprisingly identifying
#319I work at Mullvad. (co-CEO, co-founder) Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post's findings you may get confusing results throughout the day. We will also re-evaluate wheth…
Re: Mullvad exit IPs are surprisingly identifying
#320Earlier quoted context omitted.
In many countries, a VPN provider can be significantly more trustworthy than an ISP. In Germany, for example, you can have your home searched simply for insulting a politician. The ISP will then immediately hand over the data to the authorities, which most VPN providers do not do. The same goes for torrents. If some random law firm sends a letter to Telekom saying, “Hey, your customer downloaded a movie please give u…
That's very simplistic assumption. If the German state machinery is determined to get you, ISP and VPN provider have a threshold beyond which they'll give up. Many many examples out there. "We don't keep logs" is not good enough neither realistic because how else a VPN provider is supposed to protect itself if it doesn't keep a log of what's happening inside and through its own systems.