Live data from Hacker News

WireGuard multihop available in the Mullvad app

mullvad.net

91–100 of 141 posts

Re: WireGuard multihop available in the Mullvad app

#91
post #68

Earlier quoted context omitted.

> Mullvad is one of the non-logging VPN providers How do you know that they're not logging? Or that their ISPs are not logging?

Here's the latest Mullvad security audit (June 2020). https://cure53.de/pentest-report_mullvad_2020_v2.pdf

Unless I'm mistaken that's just a security audit of their client applications, which would not in any way prove that they aren't logging.

Re: WireGuard multihop available in the Mullvad app

#92

This isn't Tor-like multi-hop (but is similar to other multi-hop VPN providers out there). A proper multi-hop would happen across two different vendors in control of two different networks, as it were. The iCloud Relay paper outlined a pretty private and secure design [0] (and the intention to standardize it via IETF would probably make it simpler to self-host such a solution [1][2]). Among the VPNs, orchid.com's dis…

I think what people want in this case, is quick access to a different exit IP to appear on the internet with.

Re: WireGuard multihop available in the Mullvad app

#93
post #74

Earlier quoted context omitted.

The Mullvad app is huge ~100MB which is odd for what it needs to do.

My mullvad installation on Windows has 258MB but memory footprint is low. I find 5 entries in the task manager with a total of 14.6MB with active connection.

Maybe not Electron, then. Perhaps I'm confusing it with ExpressVPN's first-party app, which definitely was Electron when I tried them a few years back.

Re: WireGuard multihop available in the Mullvad app

#94
post #8

I use (and really like!) Mullvad, but have never tried the app, preferring to use my existing OpenVPN clients with the profiles Mullvad provides. This isn't because I have any reason to mistrust their app, but just because if I've already got a perfectly serviceable client on my device, why add another binary to do the same thing? But I would be interested to hear, from folks who have used the app, what you like and…

I've found their apps to be (subjectively) higher quality than most OpenVPN clients on platforms I care about (macOS, iOS, Windows). It's nice to have a consistent UI, and not have to think or care about specific profiles — it's easy for me to jump between servers much more easily (I typically connect relatively locally, but occasionally find that certain out IP addresses have been blacklisted from specific sites; it…

I'll also +1 your anecdote that the Mullvad app is simple, convenient and stable.

Re: WireGuard multihop available in the Mullvad app

#95

I use (and really like!) Mullvad, but have never tried the app, preferring to use my existing OpenVPN clients with the profiles Mullvad provides. This isn't because I have any reason to mistrust their app, but just because if I've already got a perfectly serviceable client on my device, why add another binary to do the same thing? But I would be interested to hear, from folks who have used the app, what you like and…

Split tunneling an app to NOT GO THROUGH the tunnel is easy Setting split tunneling to ONLY TUNNEL A SPECIFIC APP is hard

[deleted]

Re: WireGuard multihop available in the Mullvad app

#96

This isn't Tor-like multi-hop (but is similar to other multi-hop VPN providers out there). A proper multi-hop would happen across two different vendors in control of two different networks, as it were. The iCloud Relay paper outlined a pretty private and secure design [0] (and the intention to standardize it via IETF would probably make it simpler to self-host such a solution [1][2]). Among the VPNs, orchid.com's dis…

Splitting hairs no? I mean you're comparing multi-hop with onion routing. I'm just speaking as a layman end user. When I see multi-hop it's self-explanatory, it's literally in the name. Onion routing is another type of multi-hop with the onion routing algorithm.

The point of multihop, tor or otherwise, is for each node in the route to not know what the other knows. The first node sees packets coming from you, but not where they're going. The second see's where they're going but doesn't know where they're from (and vice versa). If the two nodes exchange this info (ex. if same person runs both nodes) then there's no point. Nothing is gained, you just incur the overhead of the extra hop.

Re: WireGuard multihop available in the Mullvad app

#97

Earlier quoted context omitted.

If mullvad is compromised, then all my traffic is also compromised and potentially my client machine is also compromised (since I'm running mullvad client). Alternately, to begin with, if my traffic wasn't sensitive or personally identifiable, then I don't actually need this multi-hop setup.

Yes, if mullvad + your machine is compromised, then indeed there is not much you can do. But first, not everyone uses mullvads client, but instead the provided configuration files for wireguard/openvpn. Secondly, not all traffic is indeed personally identifiable, especially if you're using something like mullvad with for anonymous traffic to begin with. Imagine you have another account than vinay_ys that you only use…

With a Wireguard VPN to reach Internet, all traffic from this machine meant for Internet is going via the tunnel, including the OS generated background traffic, and application generated background traffic (like update servers, analytics beacons/telemetry, license verification servers etc). These can contain tracking identifiers that can be tied back to app purchases, and even laptop purchase itself.

If you really have only limited sensitive traffic (even with fake identity), you are better off using just tor browser than using a full machine vpn.

Re: WireGuard multihop available in the Mullvad app

#98

Earlier quoted context omitted.

If mullvad gets compromised, you can still remain anonymous if the payment method is anonymous as long as the traffic you've sent to mullvad been anonymous as well. Obviously, if you log into your normal Facebook account, it isn't, but there are plenty of other uses.

If mullvad is compromised, then all my traffic is also compromised and potentially my client machine is also compromised (since I'm running mullvad client). Alternately, to begin with, if my traffic wasn't sensitive or personally identifiable, then I don't actually need this multi-hop setup.

No idea how mullvad setup is done, but in theory I think you could use Tor -> mullvad wireguard configured VPN -> target site.

That way your traffic would be "legitimized" (no infernal Captcha loops), and if the sites you visit have certificate pinning mullvad network compromise wouldn't matter.

A bunch of ifs, but that's the state of things.

edit: written before thinking out all the details, probably can't tunnel udp connections over Tor.

Re: WireGuard multihop available in the Mullvad app

#99

Earlier quoted context omitted.

If you don't want to switch to the Mullvad app, it's still worthwhile to switch to their wireguard profiles. Connections seem more stable and wireguard is far easier to configure.

Hey I’m curious about the terminology you guys are using here. Is there a manual or a page which I can read to learn more about wireguard profiles and what mullvad has done for them perhaps?

Wireguard is the latest VPN protocol. Check out the Wikipedia page (https://en.wikipedia.org/wiki/WireGuard) or it's homepage (https://www.wireguard.com/). Not all VPN providers support it yet (notably Proton VPN), but it is generally faster and more secure than OpenVPN.

It was made by Jason A. Donenfeld.

Re: WireGuard multihop available in the Mullvad app

#100
post #38

Earlier quoted context omitted.

The ease with which you can pay anonymously makes me feel that its more likely a genuine privacy provider rather than a CIA run honeypot like Crypto AG.

You can also mail them an envelope with your user ID # and some cash. It's pretty great.

I started by using the cash-in-an-envelope option. For my most recent subscription, I paid in Bitcoin. All methods were pretty easy, neat and fast.
Post reply on HN