Live data from Hacker News

Mullvad VPN was subject to a search warrant – customer data not compromised

mullvad.net

71–80 of 345 posts

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#71
I don't understand why go after the VPN, I think most people don't use a VPN correctly.

What good is a VPN when multiple apps on your computer are phoning home?

If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP?

To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to hide?

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#72
post #38

Earlier quoted context omitted.

> Which payment methods do you accept? > We accept cash, Bitcoin, Bitcoin Cash, Monero, bank wire, credit card, PayPal, Swish, Giropay, Eps transfer, Bancontact, iDEAL, and Przelewy24. > Can I really pay with cash? > You bet, and please! Stay anonymous all the way. Just put your cash and payment token (randomly generated on our website) in an envelope and send it to us. We accept the following currencies: EUR, USD, G…

ah yes, notoriously-anonymous physical mail

I'm confused by your sarcasm. A one-time physical mailing can be incredibly anonymous.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#73
post #44

Earlier quoted context omitted.

I might be uninformed here, but on the surface Mullvad says they don't record customer data but there's always a chance they might be recording some data or lying. So I figure that authorities still obtained a search warrant to atleast see what data they can get their hands on and to verify that this is true. In that case, it doesn't really illustrate any disconnect. > Basic knowledge and a quick investigation would…

> but there's always a chance they might be recording some data or lying. As mentioned in another comment, at least they would have to be lying + the external companies who've done the third-party audits would have to be lying too (including companies like Cure53).

An audit is always just a point-in-time (or possibly periodic) snapshot.

A VPN company is also not a monolith: They have servers literally distributed around the globe. Ensuring physical security for all of them is not trivial, and I doubt that their auditors have visited every single data center. This is to say nothing of global traffic correlation capabilities of state-level actors; access to their servers network uplink is all that's needed to deanonymize many connections.

Besides that, they have human staff as well, and while it's possible to distribute permissions and require four eyes for all important changes, there's always loopholes in a complex system.

I have no reason to doubt that Mullvad is being truthful about any of their efforts or aspects of their service, but even if they're not, this is by no means equivalent to absolute security.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#74
post #44

Once again this shows the huge disconnect between the government authorities and the tech industry. Basic knowledge and a quick investigation would make clear that Mullvad is not storing any customer data.

I might be uninformed here, but on the surface Mullvad says they don't record customer data but there's always a chance they might be recording some data or lying. So I figure that authorities still obtained a search warrant to atleast see what data they can get their hands on and to verify that this is true. In that case, it doesn't really illustrate any disconnect. > Basic knowledge and a quick investigation would…

> So I figure that authorities still obtained a search warrant to atleast see what data they can get their hands on and to verify that this is true. In that case, it doesn't really illustrate any disconnect.

They also need to follow process and make a reasonable attempt to follow a lead.

They can’t just read a company’s website, assume that no evidence exists, and then give up on that line of exploration. Note that in several high profile cases, companies have publicly claimed to not be storing data but later been found to have incriminating logs.

It would be irresponsible for them to not follow up with Mullvad, despite what they advertise.

It doesn’t make sense to suggest that this is a disconnect with law enforcement.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#75
post #14
post #5

Full title: Mullvad VPN was subject to a search warrant. Customer data not compromised As a customer, I have no doubt about the "customer data not compromised". I'm a paying customer, yet I have never given them any PII. Great service.

Technically they could have been logging your traffic, which is “customer data” even if it doesn’t identify you by name

> Technically they could have been logging your traffic

Of course they “could have” but their entire business depends on them not doing it.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#76

Earlier quoted context omitted.

Police investigations regarding 6+ officers showing up at your office do not end with “oh have a good day.”

Maybe not in the US. > We argued they had no reason to expect to find what they were looking for and any seizures would therefore be illegal under Swedish law. If this line is to be believed then the police would have been committing a crime by proceeding.

This is not how police work anywhere. There would be an entire legal process for this.

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#77

"They intended to seize computers with customer data. In line with our policies such customer data did not exist" But please tell me again how hard it is to comply with the GDPR

> But please tell me again how hard it is to comply with the GDPR

I like Mullvad (and been a paying customer on-and-off for years), but perhaps it's easier to comply with GDPR when your whole business is essentially not storing data?

Even if you are the most privacy conscious company ever, there is probably legitimate need storing more data than Mullvad in almost any other B2C scenario.

(Although it would be exciting buying e.g a TV online by sending cash in an envelope and writing the shipping address inside, the novelty probably wears of once the postal service looses your package and you can't do anything about it. Or when you loose your paper note with the ASCII armored PGP proof-of-purchase and you can't do a warranty claim)

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#78

Earlier quoted context omitted.

ah yes, notoriously-anonymous physical mail

I mean, just don't put a return address on it, and drop it off in a random post office box.

They never caught Zodiac

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#79
post #38

Earlier quoted context omitted.

> Which payment methods do you accept? > We accept cash, Bitcoin, Bitcoin Cash, Monero, bank wire, credit card, PayPal, Swish, Giropay, Eps transfer, Bancontact, iDEAL, and Przelewy24. > Can I really pay with cash? > You bet, and please! Stay anonymous all the way. Just put your cash and payment token (randomly generated on our website) in an envelope and send it to us. We accept the following currencies: EUR, USD, G…

ah yes, notoriously-anonymous physical mail

How is it not?

Re: Mullvad VPN was subject to a search warrant – customer data not compromised

#80

Earlier quoted context omitted.

ah yes, notoriously-anonymous physical mail

I mean, just don't put a return address on it, and drop it off in a random post office box.

All standard British stamps now have unique Data Matrix codes on them, which means you also have to source your stamps anonymously.
Post reply on HN