Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

371–380 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#371
post #322

Earlier quoted context omitted.

If you create a 3rd party app to some closed source insecure back end, thats on you for trusting them or not doing your due diligence. Time and time again private companies have rug pulled things like api access for 3rd party apps (such as twitter/X). Building 3rd party clients for private systems should already be approached with heavy scepticism and always be prepared for the worst.

Bull. This is the best VPN regarding security and privacy there is. I did my research

I've got a Proton VPN sub, what would you say are the biggest reasons to switch to Mullvad?

Re: Mullvad exit IPs are surprisingly identifying

#372

Earlier quoted context omitted.

Who else ?

Windsribe and iVPN. https://ipinfo.io/vpnreport

Why do so many VPN submit inaccurate info ? Are we talking intention to mislead or is it more about just scrambling / obscuring location ?

Re: Mullvad exit IPs are surprisingly identifying

#373

Earlier quoted context omitted.

I just want to say I absolutely love Mullvad! You guys did a fantastic job at designing a genuinely good and trustworthy (as much as possible) VPN vendor. You communicating here is just another data point towards this.

I almost want the people doing the mandatory VPN product placement ("This video is sponsored by NordVPN!") to do Mullvad for once. My jaw would hit the floor from unfamiliarity

If Mullvad was suddenly in that ad scene, I would get worried.

This is not anything specific against Nord, I don't know anything about them. However, at this point, I take YouTube/influencer ads as a very negative signal towards the product being pushed. I am not sure if that's fair, but that's just my gut feeling given the entire YouTube ad scene.

I think it's the cost per viewer, where "scams" are more profitable than a honest business, and that makes my gut tingle. Again, to be fair, I may be being a jerk here with my judgment.

Re: Mullvad exit IPs are surprisingly identifying

#374
post #103

Earlier quoted context omitted.

That’s been my pet theory from day 1, and not because of DDoS. Simply because they are the SSL terminator for most of the internet and can see anything going on in cleartext (and I’ve seen them protecting some shady stuff) I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)” If NSA aren’t installed at Cloudflare, I wonde…

It's within the realm of possibility that NSA is collecting data with Cloudflare's consent. It seems unlikely that Cloudflare would jeopardize their entire business model over it. Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers. Their entire value proposition is being an unobtrusive traffic intermediary.

anybody remember Lavabit?

Re: Mullvad exit IPs are surprisingly identifying

#375
post #180

Missing from the story: did they reach out to Mullvad? Would have been interesting to see how their security team responded.

As far as I can tell they did not, and I've asked both our operations and support teams. I will update this post if I am mistaken. Edit: In hindsight I regret making this comment. It was unnecessary, but removing it now would look weird.

how about this I’ll downvote it for you and you can downvote mine and we’ll just fade out together lol

Re: Mullvad exit IPs are surprisingly identifying

#376

Earlier quoted context omitted.

Depending on the severity of the issue. Emailing support with a draft of the blog post and waiting even a couple of hours for a response so they can fix it first would have been more responsible than dropping the blog post to the whole wide world and catching Mullvad with their pants down.

Why wait for a couple of hours for a response while people who could protect themselves are getting harmed? It's especially true when you don't know if the maintainer/vendor will get back to you at all, or if they even check their mailboxes regularly. The priority should be on protecting users, and not helping the company responsible for the vulnerability save face, or give them extra time to spin up their PR team, o…

The problem is how do you notify users? What are the chances that a Mullvad user is going to happen across this blog post? Of the entire world of Mullvad users, somewhere between 0 and 100% of their users is going to read it and be in a place to do anything about it. If I were to make up a number though, I'd guess it's somewhere between 1 and 10% of Mullvad users. On the other hand, by telling Mullvad first, so Mullvad can fix their system first, closer to 100% of Mullvad users get the fix before attackers figure out the issue.

Mullvad fucked up. They should been as inconvenienced as thru possibly could be too fix the problem promptly! The issue is irresponsible disclosure hurts more users than it helps.

Re: Mullvad exit IPs are surprisingly identifying

#377

Earlier quoted context omitted.

I mean, it is the CIA, but if you encrypt it before it leaves the box, and you're decent good with the key material, how are they going to get at it? Tapping the fiber then gets them encrypted flows, which isn't nothing, but, well, it would be surprising if they had access to the clear text.

Room 641A [1] would be an example of just renting a room in the DC, making it look as boring and nondescript as possible, tap the fiber lines and send a copy of all data to that room That requires cooperation from a couple people at the company. People that could do it for "patriotic duty", be payed off, simply be coerced, or be replaced by NSA agents (I wonder how many cloudflare employees are NSA plants?). If you w…

The difference is AT&T didn't publicly make statements that they didn't know about Room 641A and that they weren't helping the NSA. Google's response to PRISM was much more aggressive, and in the wake of the MUSCULAR tapping revelations, Google stepped up their encryption. I haven't worked at Cloudflare but I have worked at Google, so I can't speak to Cloudflare's internal company culture but I can say that Google was not happy about the NSA tapping their fibre.

Re: Mullvad exit IPs are surprisingly identifying

#378

Great find by the author and I have no trouble believing this is an oversight by Mullvad. Kind of shocking that something this simple slips by them but I could see myself missing it. Putting aside the IP correlation across multiple servers, at first I wondered why even keep the user IP stable on one server. But I think it makes sense because as the author states other VPNs usually have only one IP per server so they…

I feel like trying to "trick" the RNG into providing stability is the wrong approach here given all the footguns that can occur with having a low entropy seed, but I am not sure what an alternative to IP stability would be short of doing session management, which may introduce too much state into the problem to be acceptable for a VPN service.

Maybe a clientside hint that gets rotated in some circumstances with options to toggle it off would be appropriate. That should be fine as long as you don't care about someone being able to control their exit IP reliably.

Re: Mullvad exit IPs are surprisingly identifying

#379
post #217

Earlier quoted context omitted.

You should put your business ( https://proxybase.xyz ) in your HN profile. It might help to find more customers.

I’m not here to promote anything just wanted to share a valid use case in the right context.

And yet you regularly promote you own commercial product using submarine adverts on HN. Hmm... I can think of few other behaviours that HN commenters like less.

Re: Mullvad exit IPs are surprisingly identifying

#380
post #357

Earlier quoted context omitted.

No, because I don't keep a list of every article I've read over the past decade or so, but there were multiple busts where a regular law enforcement agency (FBI and their international counterparts) were able to prove the identity of a user simply by timing attacks. The fact that Tor does not intend to tackle the timing problem is plainly stated on the Tor website.

I was also curious about a source for this but if you just mean the common knowledge that... > Tor does not intend to tackle the timing problem [as] plainly stated on the Tor website. then that's not how I read the above claim about Tor "having been deanonymized". Yes, yes, it strictly fits within the meaning of what you wrote, but it's like saying bread has been made free before because someone found a place where t…

"Tor has been successfully deanonymized" = "There are documented cases of successful deanonymization attacks."

https://www.schneier.com/blog/archives/2013/12/tor_user_iden... https://www.schneier.com/blog/archives/2024/10/law-enforceme...

If law enforcement can do it, then intelligence agencies and anyone with a similar budget can do it.

I did not say there is an easy exploit available that anyone can use or that attacks have a 100% success probability.

Post reply on HN