Earlier quoted context omitted.
In other words: a VPN service can't by itself solve all problems which potentially lead to deanonymization, it can only provide anonymous networking. Why can't it aim to solve what it can do? TOR is a great example: the TOR network itself can't perfectly anonymize you due to browser fingerprinting, but users of the TOR Browser get both the TOR network resisting deanonymization on a network level and a browser with pl…
Have you taken a look at Mullvad’s browser?
Mullvad exit IPs are surprisingly identifying
381–390 of 408 posts
Re: Mullvad exit IPs are surprisingly identifying
#382Earlier quoted context omitted.
Why wait for a couple of hours for a response while people who could protect themselves are getting harmed? It's especially true when you don't know if the maintainer/vendor will get back to you at all, or if they even check their mailboxes regularly. The priority should be on protecting users, and not helping the company responsible for the vulnerability save face, or give them extra time to spin up their PR team, o…
The problem is how do you notify users? What are the chances that a Mullvad user is going to happen across this blog post? Of the entire world of Mullvad users, somewhere between 0 and 100% of their users is going to read it and be in a place to do anything about it. If I were to make up a number though, I'd guess it's somewhere between 1 and 10% of Mullvad users. On the other hand, by telling Mullvad first, so Mullv…
It's not as if the odds of new would-be exploiters seeing it are any better. It helps that the people who are at the most risk tend to have their ear to the ground already because they know what's at stake.
When the risks are this high you have to assume that it's already being actively exploited. That means that already there are more attackers who know about the vulnerability than there are users who know about the mitigation.
All you can do at that point is let as many users as possible know how to protect themselves while Mullvad figures out how to fix the issue on their end, writes and puts out the update, and the remaining users get around to updating their systems. You can't save everyone, but hopefully you at least gave some people the chance to save themselves.
Re: Mullvad exit IPs are surprisingly identifying
#383Earlier quoted context omitted.
I have a script that logs IPs for any traffic coming in to my servers on ports that don't accept traffic. I then block those IPs from accessing ports behind which there are services. If they're checking my locked doors, I don't want them coming in my unlocked doors.
There are a lot of legit scanners that look for problems to proactively warn the owner, so the mere presence of a packet on a port you aren't advertising somewhere is maybe a bit overkill, but if you think this is abuse: have you considered also reporting the abuse to the originating ISP? Otherwise they can never take action against that subscriber and the blocked IPs will just impact people that come after. ISPs tha…
In my experience, most of the scanner firms seem to be creating their own maps of as much of the internet as they can get their grubby hands on, and then sell API access to their database of all services running on all the open ports on all the IP addresses they've probed and scanned and scraped.
Firstly, I don't want my shit listed in these databases. Secondly, the traffic is probably negligible, but it's still coming down my pipes (tubes) without an invitation, and I don't like that, plus they then profit off this uninvited behaviour. It rubs me the wrong way.
Finally, I highly doubt that (m)any of these services are doing it for altruistic purposes. They're doing it for reasons of profit, and then downstream of this is likely access by various intelligence agencies to this data.
I just don't think they have a right to this data.
> but if you think this is abuse: have you considered also reporting the abuse to the originating ISP?
That's a good point, and if I can automate that, then I will, but I don't consider it a priority. Finding the party ultimately responsible for an IP address isn't a particularly simple process.
Re: Mullvad exit IPs are surprisingly identifying
#384Earlier quoted context omitted.
Are you seriously suggesting people shouldn't operate with a bit of common decency unless they're going to get some money out of it?
Most of HN readers/writers are American, of course they won't do anything unless they personally profit off it, the entire culture is built around this mindset. Meanwhile, Mullvad is Swedish, and we tend to assume we all want to help build a better world together. Mix the two, and you get this conversation :)
Re: Mullvad exit IPs are surprisingly identifying
#385Earlier quoted context omitted.
One person can tell a lie, but a company consists of many people. You must ensure that only few people know of the logging or there will be a risk of a leak.
Well, there should only be a few people with the access needed to discover logging is happening. Just put the logging configuration in whatever secure configuration management tool is storing your TLS keys and suchlike. Make it look like an accidental misconfiguration and if an insider who isn't an NSA mole does somehow discover the logging, there's a fair chance they'll turn a blind eye anyway. After all, if you wor…
Re: Mullvad exit IPs are surprisingly identifying
#386Earlier quoted context omitted.
Is this your service? Since you've made seven posts to HN about it and also your username shows up in the commits on their GitHub. Because I'm quite curious on where the IPs are from. Usually residential IPs is a fancy wording for malware infested devices from regular people.
> Since you've made seven posts to HN about it Do you have a tool to text search a user's comment history? Your comment is very specific: "seven"!
Re: Mullvad exit IPs are surprisingly identifying
#387Earlier quoted context omitted.
This ought not be considered anything close to common courtesy. This is work. Mullvad is engaged in the business of making money. They should show how serious they are with your money. Since when do you have professionals giving you examinations out of common courtesy? Out of courtesy can I get a free cancer screening?
If I doctor performed a cancer screening on me, for free and without me asking, then yes — as a matter of courtesy I would still expect that doctor to tell me if he found cancer, rather than reading about it on his blog later.
Re: Mullvad exit IPs are surprisingly identifying
#388Earlier quoted context omitted.
The attack surface is far larger than what you specified. Any networking equipment sotting between the client and server(s) can pick up and log IP addresses. Knowing the online services one uses, and the times (to the millisecond) they used them goes a long way to deanonymize individuals. Correlating Internet routing events is very effective when combined with other data sources, like physical surveillance and knowin…
What’s the difference if Mullvad did not have the vulnerability described above?
Clustering, in turn, allows time-based deanonymization[1], against the users assumptions of being sufficiently anonymized.
Adversaries who do not enjoy a backbone-traffic MitM vantage point cannot exploit this vulnerability, which makes it appear NOBUS-y.
1. Any *aaS, forum, or board, when given a (Mullvad!) IP address and series of request timestamps, and a subpoena, can yield PII on the real identity (email, phone, billing address)
Re: Mullvad exit IPs are surprisingly identifying
#389Earlier quoted context omitted.
There are a lot of legit scanners that look for problems to proactively warn the owner, so the mere presence of a packet on a port you aren't advertising somewhere is maybe a bit overkill, but if you think this is abuse: have you considered also reporting the abuse to the originating ISP? Otherwise they can never take action against that subscriber and the blocked IPs will just impact people that come after. ISPs tha…
> There are a lot of legit scanners that look for problems to proactively warn the owner In my experience, most of the scanner firms seem to be creating their own maps of as much of the internet as they can get their grubby hands on, and then sell API access to their database of all services running on all the open ports on all the IP addresses they've probed and scanned and scraped. Firstly, I don't want my shit lis…
> most of the scanner firms seem to be creating their own maps of as much of the internet as they can get their grubby hands on, and then sell API access to their database
Yeah, sure, a lot of scanners are run by black or gray hats. Just saying that all options are on the table and blocking (or even reporting) e.g. the non-profit .nl operator organization for scanning tcp:443 on all the A/AAAA records of .nl domains is going to do much good
(Example of what they're doing: https://www.sidn.nl/en/news-and-blogs/new-system-for-logo-ba...)
Re: Mullvad exit IPs are surprisingly identifying
#390> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were…
Mullvad predates the Snowden leaks by several years and was not mentioned anywhere in them. Sure, there are other intelligence agencies, but that's the one I'd be the most worried about. Since either they run it, or they would know of it and want to emulate the idea, or know of it and have access to it from the partner agency running it. Or they are not a threat to me. There's also the issue of no publicly known case…