Earlier quoted context omitted.
If you create a 3rd party app to some closed source insecure back end, thats on you for trusting them or not doing your due diligence. Time and time again private companies have rug pulled things like api access for 3rd party apps (such as twitter/X). Building 3rd party clients for private systems should already be approached with heavy scepticism and always be prepared for the worst.
Bull. This is the best VPN regarding security and privacy there is. I did my research
Mullvad exit IPs are surprisingly identifying
371–380 of 408 posts
Re: Mullvad exit IPs are surprisingly identifying
#372Re: Mullvad exit IPs are surprisingly identifying
#373Earlier quoted context omitted.
I just want to say I absolutely love Mullvad! You guys did a fantastic job at designing a genuinely good and trustworthy (as much as possible) VPN vendor. You communicating here is just another data point towards this.
I almost want the people doing the mandatory VPN product placement ("This video is sponsored by NordVPN!") to do Mullvad for once. My jaw would hit the floor from unfamiliarity
This is not anything specific against Nord, I don't know anything about them. However, at this point, I take YouTube/influencer ads as a very negative signal towards the product being pushed. I am not sure if that's fair, but that's just my gut feeling given the entire YouTube ad scene.
I think it's the cost per viewer, where "scams" are more profitable than a honest business, and that makes my gut tingle. Again, to be fair, I may be being a jerk here with my judgment.
Re: Mullvad exit IPs are surprisingly identifying
#374Earlier quoted context omitted.
That’s been my pet theory from day 1, and not because of DDoS. Simply because they are the SSL terminator for most of the internet and can see anything going on in cleartext (and I’ve seen them protecting some shady stuff) I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)” If NSA aren’t installed at Cloudflare, I wonde…
It's within the realm of possibility that NSA is collecting data with Cloudflare's consent. It seems unlikely that Cloudflare would jeopardize their entire business model over it. Unlike other companies in the leaked NSA slides that participated in PRISM, Cloudflare would face a near-total loss of customers. Their entire value proposition is being an unobtrusive traffic intermediary.
Re: Mullvad exit IPs are surprisingly identifying
#375Missing from the story: did they reach out to Mullvad? Would have been interesting to see how their security team responded.
As far as I can tell they did not, and I've asked both our operations and support teams. I will update this post if I am mistaken. Edit: In hindsight I regret making this comment. It was unnecessary, but removing it now would look weird.
Re: Mullvad exit IPs are surprisingly identifying
#376Earlier quoted context omitted.
Depending on the severity of the issue. Emailing support with a draft of the blog post and waiting even a couple of hours for a response so they can fix it first would have been more responsible than dropping the blog post to the whole wide world and catching Mullvad with their pants down.
Why wait for a couple of hours for a response while people who could protect themselves are getting harmed? It's especially true when you don't know if the maintainer/vendor will get back to you at all, or if they even check their mailboxes regularly. The priority should be on protecting users, and not helping the company responsible for the vulnerability save face, or give them extra time to spin up their PR team, o…
Mullvad fucked up. They should been as inconvenienced as thru possibly could be too fix the problem promptly! The issue is irresponsible disclosure hurts more users than it helps.
Re: Mullvad exit IPs are surprisingly identifying
#377Earlier quoted context omitted.
I mean, it is the CIA, but if you encrypt it before it leaves the box, and you're decent good with the key material, how are they going to get at it? Tapping the fiber then gets them encrypted flows, which isn't nothing, but, well, it would be surprising if they had access to the clear text.
Room 641A [1] would be an example of just renting a room in the DC, making it look as boring and nondescript as possible, tap the fiber lines and send a copy of all data to that room That requires cooperation from a couple people at the company. People that could do it for "patriotic duty", be payed off, simply be coerced, or be replaced by NSA agents (I wonder how many cloudflare employees are NSA plants?). If you w…
Re: Mullvad exit IPs are surprisingly identifying
#378Great find by the author and I have no trouble believing this is an oversight by Mullvad. Kind of shocking that something this simple slips by them but I could see myself missing it. Putting aside the IP correlation across multiple servers, at first I wondered why even keep the user IP stable on one server. But I think it makes sense because as the author states other VPNs usually have only one IP per server so they…
Maybe a clientside hint that gets rotated in some circumstances with options to toggle it off would be appropriate. That should be fine as long as you don't care about someone being able to control their exit IP reliably.
Re: Mullvad exit IPs are surprisingly identifying
#379Earlier quoted context omitted.
You should put your business ( https://proxybase.xyz ) in your HN profile. It might help to find more customers.
I’m not here to promote anything just wanted to share a valid use case in the right context.
Re: Mullvad exit IPs are surprisingly identifying
#380Earlier quoted context omitted.
No, because I don't keep a list of every article I've read over the past decade or so, but there were multiple busts where a regular law enforcement agency (FBI and their international counterparts) were able to prove the identity of a user simply by timing attacks. The fact that Tor does not intend to tackle the timing problem is plainly stated on the Tor website.
I was also curious about a source for this but if you just mean the common knowledge that... > Tor does not intend to tackle the timing problem [as] plainly stated on the Tor website. then that's not how I read the above claim about Tor "having been deanonymized". Yes, yes, it strictly fits within the meaning of what you wrote, but it's like saying bread has been made free before because someone found a place where t…
https://www.schneier.com/blog/archives/2013/12/tor_user_iden... https://www.schneier.com/blog/archives/2024/10/law-enforceme...
If law enforcement can do it, then intelligence agencies and anyone with a similar budget can do it.
I did not say there is an easy exploit available that anyone can use or that attacks have a 100% success probability.