Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

341–350 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#341
post #266

Earlier quoted context omitted.

Mullvad predates the Snowden leaks by several years and was not mentioned anywhere in them. Sure, there are other intelligence agencies, but that's the one I'd be the most worried about. Since either they run it, or they would know of it and want to emulate the idea, or know of it and have access to it from the partner agency running it. Or they are not a threat to me. There's also the issue of no publicly known case…

Intelligence agencies use parallel construction to disguise their real methods. Further, more sophisticated methods are reserved for bigger targets. Intelligence agencies aren't running around discussing their methods publicly, most intelligence agency work doesn't result in public criminal charges.

So they gave away all their other extremely valuable methods in the leaks except for Mullvad?

Re: Mullvad exit IPs are surprisingly identifying

#342

Earlier quoted context omitted.

Most of HN readers/writers are American, of course they won't do anything unless they personally profit off it, the entire culture is built around this mindset. Meanwhile, Mullvad is Swedish, and we tend to assume we all want to help build a better world together. Mix the two, and you get this conversation :)

> Most of HN readers/writers are American, of course they won't do anything unless they personally profit off it, the entire culture is built around this mindset American culture is highly varied. For some this is true, for others this is wrong and highly insulting. Maybe try a narrower brush next time.

Every time someone makes a cultural comment here, the reply is always "America is a big country". America can be a big country and still have common cultural elements. It's not inaccurate to say that citizens of a large country mostly share some common characteristics. Those characteristics are what makes them one country.

Re: Mullvad exit IPs are surprisingly identifying

#343

Earlier quoted context omitted.

>Since when do you have professionals giving you examinations out of common courtesy? Maybe when they decide on their own volition, without any external pressure, to go and poke around your system? "Hey, I'm a mechanic, I was looking at your car parked out there and noticed something incredibly dangerous that needs immediate fixing. I'll tell you what it is for $1,000." Please...

Even better, the mechanic writes a blog post about the dangers of non-functioning brakes, but doesn't tell the car owner, because they didn't have a sign advertising their "car issue bounty program". Seems to be a systemic issue with computer guys feeling entitled to financial compensation for strange reasons. See also, people licensing their software as "open source" and then being mad when people make money off it.

Even better, the mechanic writes a blog post about how the locks on that guy's car don't work, and how anyone could just steal it, but doesn't tell the guy because, after all, the guy wasn't paying him to.

Re: Mullvad exit IPs are surprisingly identifying

#344
post #43

It seems surprising that people would expect a VPN to be comparable to Tor. It does seem ridiculous once you spell it out like that, and then you have to realize that it’s plausible to de-anonymize even Tor users by controlling exit nodes.

I thought part of Tor's design was routing through multiple relay nodes, so even an exit node doesn't see the source IP?

Re: Mullvad exit IPs are surprisingly identifying

#345
post #200

Earlier quoted context omitted.

To support ? Oof.

I'm not sure what you mean by "Oof". We don't have a dedicated security team because security and privacy are integral to all aspects of our service. It doesn't make sense to centralise it. As for our support team they are responsive and experienced. Several of them have worked with us for many years and do offensive security research in their free time. Unlike many organisations we don't see customer support as a co…

"We don't have a dedicated security team because security and privacy are integral to all aspects of our service".

Do you have people whose role is explicitly security? Who are the security SMEs in your organization if not? I personally find the "Security is so important to us that we don't have a team dedicated to it" argument weak, and often results in misaligned incentives - if individuals have to alternate hats from "deliver results" to "properly vet security", the business push to deliver tends to win out. I'd be very curious to hear how you ensure your team doesn't fall into that trap.

Re: Mullvad exit IPs are surprisingly identifying

#346

> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…

I don't understand your logic. If you are an intelligence agency who controls a VPN, you can just directly monitor the traffic yourself. You have no incentive to make it easier for external observers to guess which users are coming out of which exit IP addresses.

Re: Mullvad exit IPs are surprisingly identifying

#347
post #143

Earlier quoted context omitted.

You really think someone would do that?

What, just go on the Internet and tell lies ? Who would do such a thing‽

Funnily enough, that snippet from Arthur used to be my favorite forum weapon. I miss forums a lot these days.

Re: Mullvad exit IPs are surprisingly identifying

#348

Earlier quoted context omitted.

> It does significantly lower the bars for identifying you though, but the requirements are still high If you squint a bit, it looks a lot like a "Nobody But US" (NOBUS[1]) scheme. A few more identifying bits could tip the scale for party that has a whole host of other bits on a list of suspects, without being useful to most other people. 1. https://en.wikipedia.org/wiki/NOBUS

Then why complicate it by being publicly insecure? If Mullvad were wanting to defeat anonymity, they could simply log the traffic metadata while falsely advertising they aren't. Their ads on San Francisco's public transit are good.

There's a real value for no such agency types having something that is secure against "normal" government activity - a subpoena is one thing, and designing something that defeats that gives you a lot of legitimacy.

Re: Mullvad exit IPs are surprisingly identifying

#350
post #178

I work at Mullvad. (co-CEO, co-founder) Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post's findings you may get confusing results throughout the day. We will also re-evaluate wheth…

Carl here (Obscura CEO, one of Mullvad's partners) This was an interesting finding, though as kfreds mentioned it would have been better to notify the vendor before publishing. The main finding (IP-position-in-pool correlation between servers) seems to include genuinely unintended behaviour. Given our great experience with the Mullvad team, I'm sure this will be addressed soon. In general, if you want different "iden…

Apparently I already use Obscura despite never paying for it :)

https://obscura.com/check/

Post reply on HN