Live data from Hacker News

WireGuard multihop available in the Mullvad app

mullvad.net

41–50 of 141 posts

Re: WireGuard multihop available in the Mullvad app

#41
This isn't Tor-like multi-hop (but is similar to other multi-hop VPN providers out there). A proper multi-hop would happen across two different vendors in control of two different networks, as it were.

The iCloud Relay paper outlined a pretty private and secure design [0] (and the intention to standardize it via IETF would probably make it simpler to self-host such a solution [1][2]). Among the VPNs, orchid.com's distributed VPN stands out as a cross-provider multi-hop solution whose privacy guarantees are closer to Tor's.

Eventually the hope is HTTP (www) itself bakes in desirable privacy properties, so regular users don't have to pay the cost of multi-hops [3].

[0] Overview: https://datatracker.ietf.org/meeting/111/materials/slides-11...

[1] https://ietf-wg-masque.github.io/

[2] https://tfpauly.github.io/privacy-proxy/

[3] https://datatracker.ietf.org/doc/draft-ietf-ohai-ohttp/

Re: WireGuard multihop available in the Mullvad app

#42

10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly…

I would think you'd do the exact opposite. If you leave a computer running anyone (Well "anyone" being a skilled adversary) can simply pull out the RAM and grab encryption keys in clear text. Law enforcement does this so often, it's practically routine. The only "safe" system is one that has been long powered off and is using tried and true cryptography, ideally open-source FDE that's been fully audited.

> simply pull out the RAM

One does not simply pull out the RAM

Re: WireGuard multihop available in the Mullvad app

#43

This thread seems to be full of people that use a VPN, I personally don’t as I find DoH + HTTPS to be enough. Why do so many of you use VPNs?

1) To simply make it harder for my ISP to see which websites I visit.

2) SNI sniffing makes some websites unavailable to me, so DoH isn't enough.

Re: WireGuard multihop available in the Mullvad app

#44

10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly…

> "They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security." I don't get it

I don't recall why, it was so long time ago. But my best guess is that they wanted to guarantee that they know what has been booted?

Re: WireGuard multihop available in the Mullvad app

#45

This thread seems to be full of people that use a VPN, I personally don’t as I find DoH + HTTPS to be enough. Why do so many of you use VPNs?

I think DoH + HTTPS works well in concert with a VPN, they're not mutually exclusive. VPN has a host of benefits, including relative anonymity, that go beyond encrypted egress to the public web.

Re: WireGuard multihop available in the Mullvad app

#46
"The entry WireGuard server will be able to see your source IP and which exit server the traffic is headed for, but it can’t see any of the traffic."

So server2 terminates the request twice? One for server1 and another time for the client who generated the request? I don't understand how it's possible for server1 to not be exposed to the data.

Re: WireGuard multihop available in the Mullvad app

#47

This thread seems to be full of people that use a VPN, I personally don’t as I find DoH + HTTPS to be enough. Why do so many of you use VPNs?

1) To simply make it harder for my ISP to see which websites I visit. 2) SNI sniffing makes some websites unavailable to me, so DoH isn't enough.

I’d never considered SNI sniffing. Great point. I’m quite fortunate in that the ISP I’m with (AAISP) is fairly privacy first and don’t _appear_ to be snooping on me in any meaningful way.

That said, I can’t say the same for my phone provider.

Re: WireGuard multihop available in the Mullvad app

#48

10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly…

I would think you'd do the exact opposite. If you leave a computer running anyone (Well "anyone" being a skilled adversary) can simply pull out the RAM and grab encryption keys in clear text. Law enforcement does this so often, it's practically routine. The only "safe" system is one that has been long powered off and is using tried and true cryptography, ideally open-source FDE that's been fully audited.

It’s practically routine for law enforcement to extract encryption keys from RAM, since when?

I’ve only heard of it being done by researchers and/or special situations.

Is this just speculation?

Re: WireGuard multihop available in the Mullvad app

#49

10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly…

[deleted]

Re: WireGuard multihop available in the Mullvad app

#50
post #49

10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly…

[deleted]

[deleted]
Post reply on HN