Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

391–400 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#391

Earlier quoted context omitted.

Even better, the mechanic writes a blog post about the dangers of non-functioning brakes, but doesn't tell the car owner, because they didn't have a sign advertising their "car issue bounty program". Seems to be a systemic issue with computer guys feeling entitled to financial compensation for strange reasons. See also, people licensing their software as "open source" and then being mad when people make money off it.

Even better, the mechanic writes a blog post about how the locks on that guy's car don't work, and how anyone could just steal it, but doesn't tell the guy because, after all, the guy wasn't paying him to.

Both of y'all confusing individual with corporate.

  The mechanic writes a blog post about how the locks on [a car model] don't work, and how anyone could just steal [cars], but doesn't tell the [car company] because, after all, the [company] wasn't paying him to.
Especially, when the car company spends on 'certifications' (security audits, in this case) and specifically markets it as a differentiator. That said, uncoordinated public disclosures in cybersecurity are bad form, given the well-established existing norms & culture; but at least, let's get analogies right.

Re: Mullvad exit IPs are surprisingly identifying

#392

Earlier quoted context omitted.

Even better, the mechanic writes a blog post about how the locks on that guy's car don't work, and how anyone could just steal it, but doesn't tell the guy because, after all, the guy wasn't paying him to.

Both of y'all confusing individual with corporate. The mechanic writes a blog post about how the locks on [a car model] don't work, and how anyone could just steal [cars], but doesn't tell the [car company] because, after all, the [company] wasn't paying him to. Especially, when the car company spends on 'certifications' (security audits, in this case) and specifically markets it as a differentiator. That said, uncoo…

Obviously there are a hundred variables that differ between the analogy and the actual situation. You changed one that felt important to you (individual/corporation) but there are still 99 that differ. That's what makes it an analogy instead of just being a retelling of the actual situation.

But yes, if you found a general fault in the locks of a certain car model and publicized it without first informing the company and giving them a fair chance to inform the affected customers, people would probably be annoyed with you. Individuals even, not just companies.

"You chose that car that advertises good locks. Guess what, the locks are actually bad and now I'm gonna publish exactly how, to teach the manufacturer a lesson about paying me money".

Re: Mullvad exit IPs are surprisingly identifying

#393

Earlier quoted context omitted.

Windsribe and iVPN. https://ipinfo.io/vpnreport

Why do so many VPN submit inaccurate info ? Are we talking intention to mislead or is it more about just scrambling / obscuring location ?

You have to ask them. I tried but did not get a clear answer.

We operate nearly 1,400 servers across almost 160 countries ourselves. From our perspective, it is VERY hard to maintain and expand a network infrastructure of this scale. When you start getting servers in West Africa, Northern Africa, the plains in North America, or Oceania, the Eastern Indian Ocean, you are expected to pay magnitudes more compared to servers with equal performance in NYC or Amsterdam. Maintaining such a diversified network infrastructure from a technical point of view is extremely challenging. Then there is the official and bureaucratic process.

Now, we are just scratching the surface. VPNs require high volume traffic throughput. Some countries (entire countries) just do not have the capacity to offer that.

So, most of the time VPN companies tend to work with specialty VPN infrastructure companies. They provide everything from hosting to networking across dozens of locations they operate in. I believe there are even white-label VPN companies that handle everything from infrastructure handling all the way to billing and even support handling. You just bring your branding. It can be argued that there is little incentive to go out there, do it all from scratch.

Is it intentional or just obscuring? From what we see, it leans intentional. The location they report is not inaccurate information by accident, it looks quite deliberate. Legacy IP geolocation services rely on something called a geofeed. A geofeed is a self-reported unverifiable report published by a network operator. Geofeeds are not widely adopted (1.5% of IPv4 and 0.70% of IPv6 allocated prefixes, 2023 data), but VPN providers maintain theirs diligently. They actively publish the locations they want IP geolocation providers to report.

One point raised by a journalist on the reporting side: imagine your VPN server points to one of the offshore islands in the Caribbean that sit outside US jurisdiction, only to find out the actual VPN server is in Miami. That is a bit risky.

Re: Mullvad exit IPs are surprisingly identifying

#394

Earlier quoted context omitted.

> Since you've made seven posts to HN about it Do you have a tool to text search a user's comment history? Your comment is very specific: "seven"!

Actually should have clarified, I meant submissions not general posts. I just searched their profile's submissions and found seven mentioning proxybase. I actually didn't check their comments.

To me, that is even worse that comments. That violates my internal rule about submarine adverts. At least they can be honest about it and add their business to their profile, and mention it when they submit.

Re: Mullvad exit IPs are surprisingly identifying

#395

Earlier quoted context omitted.

Are you seriously suggesting people shouldn't operate with a bit of common decency unless they're going to get some money out of it?

I dislike it here because I like Mullvad, but yes, I think it’s fair to go straight to public disclosure. Someone with likely substantial qualifications put in time to find this. The company is in it for profit (at least partially). What’s fair for the company is fair for the individual. The company can either offer to pay for bugs under the terms they want, hire more security folks to find the bugs themselves, or ju…

There was a recent discussion about disclosing publicly if the vendor ignores you. https://x.com/ZackKorman/status/2052427327418556679

Those who do bug bounties full-time ignore programs with no rewards. Those who want to gain experience or pad their resume can submit reports to programs with no rewards because they are not as competitive as those with rewards.

Another issue that is often talked about is the size of the bounty. Most are small https://www.theregister.com/security/2019/01/15/want-to-get-...

Re: Mullvad exit IPs are surprisingly identifying

#396
post #13

Earlier quoted context omitted.

Unfortunately, the largest and most well-marketed VPNs are, in fact, less trustworthy than your average ISP.

I'm a normal person who watches sports streams and maybe 2 years ago I downloaded a torrent of some art movie. My ISP is Comcast. How does your advice apply to me?

Using a VPN shifts your risk. Your local ISP can't see as much of your activity, but another company that probably has a business model of reselling your data to governments, intelligence agencies, and ad companies now can. If your concern is masking piracy, maybe that shift of risk is worthwhile, but you still want to avoid some of the more obvious bad actors[0]. You certainly should not have all your internet traffic going over a VPN all the time.

If you're at all worried about being targeted for political speech or you're part of a targeted group, then you need to be more careful. This map is a bit outdated, but it does give some insight on who to avoid [1].

Ironically, Mullvad is one of the more trustworthy VPNs out there and still the one I'd recommend.

[0]: https://www.koi.ai/blog/urban-vpn-browser-extension-ai-conve...

[1]: https://windscribe.com/blog/the-vpn-relationship-map/

Re: Mullvad exit IPs are surprisingly identifying

#397
post #13

Earlier quoted context omitted.

Unfortunately, the largest and most well-marketed VPNs are, in fact, less trustworthy than your average ISP.

I'm a normal person who watches sports streams and maybe 2 years ago I downloaded a torrent of some art movie. My ISP is Comcast. How does your advice apply to me?

[deleted]

Re: Mullvad exit IPs are surprisingly identifying

#398

Earlier quoted context omitted.

I'm a normal person who watches sports streams and maybe 2 years ago I downloaded a torrent of some art movie. My ISP is Comcast. How does your advice apply to me?

They don't know, they're just parroting what other people have shouted without evidence.

What? This is something that's incredibly well documented at this point. Many VPN companies operate as arms of data broker and media companies or they resell data to them. Some of them didn't start out that way, but with the way acquisitions have played out, that's where we're at now. I replied in the parent comment if you're interested.

Re: Mullvad exit IPs are surprisingly identifying

#399
post #13

Earlier quoted context omitted.

Unfortunately, the largest and most well-marketed VPNs are, in fact, less trustworthy than your average ISP.

source: trust me bro

I'm saying be skeptical of who you give your trust to. You're the one seemingly pushing to trust actors who have a proven track record of not being worthy of that trust.

Re: Mullvad exit IPs are surprisingly identifying

#400
post #357

Earlier quoted context omitted.

I was also curious about a source for this but if you just mean the common knowledge that... > Tor does not intend to tackle the timing problem [as] plainly stated on the Tor website. then that's not how I read the above claim about Tor "having been deanonymized". Yes, yes, it strictly fits within the meaning of what you wrote, but it's like saying bread has been made free before because someone found a place where t…

"Tor has been successfully deanonymized" = "There are documented cases of successful deanonymization attacks." https://www.schneier.com/blog/archives/2013/12/tor_user_iden... https://www.schneier.com/blog/archives/2024/10/law-enforceme... If law enforcement can do it, then intelligence agencies and anyone with a similar budget can do it. I did not say there is an easy exploit available that anyone can use or that att…

First link:

"The FBI didn’t have to break Tor; they just used conventional police mechanisms to get Kim to confess."

Second link:

"From the limited information The Tor Project has, we believe that one user of the long-retired application Ricochet was fully de-anonymized through a guard discovery attack. This was possible, at the time, because the user was using a version of the software that neither had Vanguards-lite, nor the vanguards addon, which were introduced to protect users from this type of attack. This protection exists in Ricochet-Refresh, a maintained fork of the long-retired project Ricochet, since version 3.0.12 released in June of 2022."

Did you even read those links?

Post reply on HN