Live data from Hacker News

Mullvad exit IPs are surprisingly identifying

tmctmt.com

401–408 of 408 posts

Re: Mullvad exit IPs are surprisingly identifying

#401

Earlier quoted context omitted.

I dislike it here because I like Mullvad, but yes, I think it’s fair to go straight to public disclosure. Someone with likely substantial qualifications put in time to find this. The company is in it for profit (at least partially). What’s fair for the company is fair for the individual. The company can either offer to pay for bugs under the terms they want, hire more security folks to find the bugs themselves, or ju…

There was a recent discussion about disclosing publicly if the vendor ignores you. https://x.com/ZackKorman/status/2052427327418556679 Those who do bug bounties full-time ignore programs with no rewards. Those who want to gain experience or pad their resume can submit reports to programs with no rewards because they are not as competitive as those with rewards. Another issue that is often talked about is the size of…

I tried watching that but X either broke their video controls or disabled them so I can’t skip ahead and the first couple minutes are _slow_.

The whole bug bounty thing is a mess, admittedly, but lacking a bug bounty program entirely feels like immediately losing the moral high ground on “you should have told us first”. There’s a lively debate about what bugs are worth, but it’s objectively not $0 for many classes because a botnet developer will buy them for some amount.

Personally, a big part of my view is formed by the educated assumption that security practices will never improve unless poor security becomes a liability. That’s unlikely to happen with “responsible disclosure” because it gets swept under a rug. Immediate public disclosure changes that risk calculus a lot. I think wed see a lot more downward pressure from vendors to their suppliers if $RandomSaaS had to worry about losing their pants because Oracle had a vuln published.

Re: Mullvad exit IPs are surprisingly identifying

#402
post #103

Earlier quoted context omitted.

That’s been my pet theory from day 1, and not because of DDoS. Simply because they are the SSL terminator for most of the internet and can see anything going on in cleartext (and I’ve seen them protecting some shady stuff) I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)” If NSA aren’t installed at Cloudflare, I wonde…

> I’ve seen them protecting some shady stuff Hmm do we want them to decide what stuff is shady and what isn't? We're already allowing payment processors to do that and it's not good.

Sorry for necro-replying, but assuming you're talking about cloudflare they already do.

They took down KF (which is hosted in the US, so seemingly to be legal), but have always allowed everything from sites dedicated to livestreaming animal abuse to ISIS-affiliates hosting beheading videos (both which AFAIK is illegal).

Re: Mullvad exit IPs are surprisingly identifying

#403

Earlier quoted context omitted.

There was a recent discussion about disclosing publicly if the vendor ignores you. https://x.com/ZackKorman/status/2052427327418556679 Those who do bug bounties full-time ignore programs with no rewards. Those who want to gain experience or pad their resume can submit reports to programs with no rewards because they are not as competitive as those with rewards. Another issue that is often talked about is the size of…

I tried watching that but X either broke their video controls or disabled them so I can’t skip ahead and the first couple minutes are _slow_. The whole bug bounty thing is a mess, admittedly, but lacking a bug bounty program entirely feels like immediately losing the moral high ground on “you should have told us first”. There’s a lively debate about what bugs are worth, but it’s objectively not $0 for many classes be…

No software is free from bugs. Category of software that undergo extensive verification like aerospace are priced far higher to accommodate the additional QA. If such extensive verification are added to average consumer or even business software, the massive costs will pass down to average users making it too expensive. Security practices need to improve but I don't think 0-day droppers are the answer. Not every threat actor is at the same skill-level. Immediate public disclosure provides them the opportunity to hit endpoints that they would not have hit coz of low skills.

Re: Mullvad exit IPs are surprisingly identifying

#404

Earlier quoted context omitted.

I tried watching that but X either broke their video controls or disabled them so I can’t skip ahead and the first couple minutes are _slow_. The whole bug bounty thing is a mess, admittedly, but lacking a bug bounty program entirely feels like immediately losing the moral high ground on “you should have told us first”. There’s a lively debate about what bugs are worth, but it’s objectively not $0 for many classes be…

No software is free from bugs. Category of software that undergo extensive verification like aerospace are priced far higher to accommodate the additional QA. If such extensive verification are added to average consumer or even business software, the massive costs will pass down to average users making it too expensive. Security practices need to improve but I don't think 0-day droppers are the answer. Not every thre…

Software is the only field where people will routinely argue producers can’t be expected to make a product that won’t harm its users and I don’t buy it.

The way your argument reads to me is “software as a category has such little utility that profit margins can only be derived from corner cutting”.

The reality of the landscape is that most companies don’t get hacked as the result of an incredible and novel Spectre-esque attack, it’s something bland and entirely preventable.

Eg https://nvd.nist.gov/vuln/detail/CVE-2025-31324

SAP got a CVE because they just flat out didn’t implement auth on an endpoint in an app architecture that will execute files just for being in a certain directory, and also didn’t prevent writing files to executable paths (or maybe that’s how the feature works, not a SAP person). For every 0 day with a novel root, there are like a thousand that are some kind of humdrum “didn’t enforce auth/SQL sanitation/XSS/other well known exploit with comprehensive solutions”.

I do think there are good reasons to withhold some classes of exploit. If a hacker writes a 14 page proof on how to beat some encryption we had no idea was vulnerable, that’s one thing. Getting owned for making an insecure architecture and then not even putting auth over it is a whole other issue.

Re: Mullvad exit IPs are surprisingly identifying

#405

Earlier quoted context omitted.

Examples?

IP addresses are metadata - and don't require search warrants, meaning they are fair game for dragnet surveillance. Tapping into a backbone, a la Room 641A, can be used to cross-reference timestamped public posts on an anonymous message board to other data sources (e.g. subpoena Netflix for payer based of Netflix's access logs from VPN exit IPs)

please read the thread again. The parent said “it is not a high bar to own a website where a user is entering personal data”. I strongly disagree, although “high” is obviously not measurable.

Maybe I should again be more specific, again.

high bar for me is, you need to be a state sponsored hacker basically, or a large criminal organisation. Or a single, very skilled and high motivated person maybe.

Re: Mullvad exit IPs are surprisingly identifying

#406

Earlier quoted context omitted.

What’s the difference if Mullvad did not have the vulnerability described above?

The vulnerability enables clustering outgoing Mullvad traffic into user-sized buckets based on metadata analysis alone. Clustering, in turn, allows time-based deanonymization[1], against the users assumptions of being sufficiently anonymized. Adversaries who do not enjoy a backbone-traffic MitM vantage point cannot exploit this vulnerability, which makes it appear NOBUS-y. 1. Any *aaS, forum, or board, when given a (…

but, to cluster this traffic, wouldn’t you need equipment between each and every mullvad exit node and each and every server the user access? Or at least a large proportion of it?

Are you talking about a surveillance state?

Re: Mullvad exit IPs are surprisingly identifying

#407
post #233

Earlier quoted context omitted.

That's very simplistic assumption. If the German state machinery is determined to get you, ISP and VPN provider have a threshold beyond which they'll give up. Many many examples out there. "We don't keep logs" is not good enough neither realistic because how else a VPN provider is supposed to protect itself if it doesn't keep a log of what's happening inside and through its own systems.

Protect itself from what? They're not responsible for what their users do online.

That's a misconception. They are indeed responsible if they don't comply with laws that require them to log (to collect evidence, as one example: https://www.bakermckenzie.com/en/insight/publications/2026/0...).

Re: Mullvad exit IPs are surprisingly identifying

#408

Earlier quoted context omitted.

No software is free from bugs. Category of software that undergo extensive verification like aerospace are priced far higher to accommodate the additional QA. If such extensive verification are added to average consumer or even business software, the massive costs will pass down to average users making it too expensive. Security practices need to improve but I don't think 0-day droppers are the answer. Not every thre…

Software is the only field where people will routinely argue producers can’t be expected to make a product that won’t harm its users and I don’t buy it. The way your argument reads to me is “software as a category has such little utility that profit margins can only be derived from corner cutting”. The reality of the landscape is that most companies don’t get hacked as the result of an incredible and novel Spectre-es…

Now that I've thought more about it, I agree with you. Most companies fall prey to well known exploits that are not that expensive to mitigate.

I think it's mostly ship product faster > secure product first that leads to such insecure architecture. Ideally, security should be incorporated early in the software development life cycle but most start-ups rarely hire a security guy in the initial phases. https://www.reddit.com/r/indianstartups/comments/1r6zwbg/why... They expect the software devs to have that knowledge. But security hardening is a skill that takes time to develop so most devs just focus on feature development.

Even for well-established companies, most security teams are not given top priority. ->https://www.reddit.com/r/ITManagers/comments/1qwnywo/devs_ig... ->https://www.reddit.com/r/cybersecurity/comments/wjypns/does_... ->https://www.reddit.com/r/cybersecurity/comments/1fjnl9j/fed_...

Will immediate public disclosures change the mindset of top leadership regarding security? For some, yes but most will not change because breaches have become too common. They reason if top tech firms like Microsoft or GitHub can suffer breaches and come out on the other side unscathed, they too can survive a major security incident.

Post reply on HN