Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

361–370 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#361

Earlier quoted context omitted.

Who else ?

Windsribe and iVPN. https://ipinfo.io/vpnreport

> five providers offered locations labeled as “Bahamas”: [...]. For all of them, measured traffic was in the United States, usually with sub-millisecond RTT to US probes.

Foiled by light speed once again :). Interesting blog post, thanks for sharing.

Checking out Windscribe pricing just now, I get a Cloudflare captcha. Really nice of them to make vendor selection that much easier: only two contenders left!

Re: Mullvad exit IPs are surprisingly identifying

#362

I maintain a list of "23034 IPs to blocklist.txt" blocked IPs they contain all VPN providers. Often VPN providers seed Geofeeds with wrong data, this is why i use traceroute and ping network to locate their real location.

I have a script that logs IPs for any traffic coming in to my servers on ports that don't accept traffic. I then block those IPs from accessing ports behind which there are services. If they're checking my locked doors, I don't want them coming in my unlocked doors.

There are a lot of legit scanners that look for problems to proactively warn the owner, so the mere presence of a packet on a port you aren't advertising somewhere is maybe a bit overkill, but if you think this is abuse: have you considered also reporting the abuse to the originating ISP? Otherwise they can never take action against that subscriber and the blocked IPs will just impact people that come after. ISPs that work with you and terminate subscribers that abuse their service should maybe not be blocked for more than a typical IP lease duration

Re: Mullvad exit IPs are surprisingly identifying

#363

Earlier quoted context omitted.

> Since you've made seven posts to HN about it Do you have a tool to text search a user's comment history? Your comment is very specific: "seven"!

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... (Seems to have some weird cache issues though, had to play around with the ?querystring part to get more results)

Yeah I also have to fight the URL parameters on Algolia from time to time, the JS front-end seems to have some syncing bugs

Makes me think I should probably have reported it, even if I found a quick-for-me workaround. Looking at the repo, though, it was discontinued several months ago. https://github.com/algolia/hn-search Wonder how much longer it'll be online for

Re: Mullvad exit IPs are surprisingly identifying

#364
post #322

Earlier quoted context omitted.

On the other hand, the lack of common decency can endanger innocent 3rd parties.

If you create a 3rd party app to some closed source insecure back end, thats on you for trusting them or not doing your due diligence. Time and time again private companies have rug pulled things like api access for 3rd party apps (such as twitter/X). Building 3rd party clients for private systems should already be approached with heavy scepticism and always be prepared for the worst.

Bull.

This is the best VPN regarding security and privacy there is.

I did my research

Re: Mullvad exit IPs are surprisingly identifying

#365
post #119

Earlier quoted context omitted.

I use aVPN when I’m traveling and want to order food delivery for my 93 year old mother in NY. UberEats and InstaCart will stop me from ordering when logged in my mom’s NY account if I’m in China, Saudi Arabia, India, Vietnam, etc.

yeah, I know the pain...Refer my comment above.

There is no comment of yours when I click the "parent" link until the root post. What exactly were we supposed to read before fortran77's comment?

Re: Mullvad exit IPs are surprisingly identifying

#367

Earlier quoted context omitted.

> place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad This is highly subjective statement. Almost all commercial VPN services farm and sell your data. Just by that, my ISP is definitely high trust point while any commercial VPN is a low trust.

My ISP is in a communist country, they sell other products like TV boxes, cameras, clouds and have ads/trackers on all of their products too. Should I trust my ISP than Mullvad? LMFAO.

That’s your speculation, nothing more. Your provider is likely charging good prices for their services. VPN providers often charge unsustainable prices, if you factor in their expenses. Unsustainable if you just provide VPN services

Re: Mullvad exit IPs are surprisingly identifying

#368
post #225

Earlier quoted context omitted.

If you use the VPN for the Web, browser fingerprinting is a major threat outside of specialized scenarios

In other words: a VPN service can't by itself solve all problems which potentially lead to deanonymization, it can only provide anonymous networking. Why can't it aim to solve what it can do? TOR is a great example: the TOR network itself can't perfectly anonymize you due to browser fingerprinting, but users of the TOR Browser get both the TOR network resisting deanonymization on a network level and a browser with pl…

Have you taken a look at Mullvad’s browser?

Re: Mullvad exit IPs are surprisingly identifying

#369
post #361

Earlier quoted context omitted.

Windsribe and iVPN. https://ipinfo.io/vpnreport

> five providers offered locations labeled as “Bahamas”: [...]. For all of them, measured traffic was in the United States, usually with sub-millisecond RTT to US probes. Foiled by light speed once again :). Interesting blog post, thanks for sharing. Checking out Windscribe pricing just now, I get a Cloudflare captcha. Really nice of them to make vendor selection that much easier: only two contenders left!

Looks like Windscribe is also recommended by Kagi Specials

Re: Mullvad exit IPs are surprisingly identifying

#370
post #50

Given that Mullvad is basically a bulletproof VPN host[1], it would be great if site operators could rely on this property to enact bans. Given that the solution is simple (add a pseudorandom seed), Mullvad will likely push out a fix within a couple days. 1. It's the preferred VPN of TeamPCP.

Source? Been googling for this but I don’t see any relevant info

I found these references to Mullvad and TeamPCP

>The whole operation ran primarily from Mullvad VPN exit nodes and virtual private server infrastructure, with little effort made to blend in. This was a high-tempo, low-stealth campaign designed to extract as much value as possible, as fast as possible.[1]

>Wiz CIRT observed the bulk of TeamPCP’s activity originating from Mullvad Virtual Private Network (VPN) exit nodes and virtual private server hosts such as InterServer.[2]

1: https://www.oligo.security/blog/teampcp-campaign-the-evoluti...

2: https://www.wiz.io/blog/tracking-teampcp-investigating-post-...

Post reply on HN