Malwarebytes' privacy VPN is Mullvad in a shady trenchcoat
dustri.org
dustri.org
https://mullvad.net/en/help/partnerships-and-resellers/
The essence of the article:
Except that Malwarebytes Privacy is just some paint on top of Mullvad and various open-source tools, which would be a parasitic albeit fine behaviour if this was clearly disclosed (as Mullvad is (amusingly) doing on its website), but there is no mention of this whatsoever on Malwarebytes' one. Worse, they're using a possessive voice when talking about the servers (that are Mullvad's) and the code (mostly Wintun and wireguard-windows amongst other, to which they didn't contribute back a single line of code.
Speaking of code, it's shipping
7z.dll from 2018, licensed under LGPL, and some parts under BSD, violating this license. wintun.dll, from the Wintun project, without mentioning it, thus violating its license. Most of the embedded dependencies are from 2018, and subject to documented vulnerabilities:
OpenSSL 1.1.0h pcre2 7z, as mentioned above Poco 1.9.0
> web app that has client code that gets executed in the browser,
That's the technicality stuff, the client triggers an event, that then uses this GPL piece of code that is on the server. I went through our stuff (mostly NPM) and they all are either Apache/MIT but there was one piece like ahh... Anyway not making money yet but will bring this up for review with legal.
Thanks
I ask because I'd be in violation. I've attached the GPL to a bunch of dinky little projects I haven't bother hosting a public repository for because I don't think anyone else in the 'verse really cares. In most cases I know I'm the only user, but there are a few that some other people have at least downloaded (probably bots or mistakes, but downloaded nonetheless).
- Bundling the source with the program (a)
- Letting people download the source from the same place as they can download the program (d)
- A written offer to hand over the source on request (b, c, e)
I also did not mention (because it was not relevant to the parties being discussed) one other option: If you received the binaries from someone else, with a written offer for source code, and you are distributing the binaries non-commercially, you can simply forward a copy of the written offer of source code you received.
The section of the GPL 2 you want is section 3, and in GPL 3 it’s section 6.
Note that there are some changes here compared to v2 of the GPL.
IANAL but my understanding/interpretation (simplified) is you have to either:
6a) Ship the binaries in a physical product with a copy of the source code accompanying
6b) Ship the binaries in a physical product along with an offer to provide the source code on request
6c) "occasionally and noncommercially" ship the binaries (not necessarily in a physical product) along with an offer to provide the source code on request
6d) Make the binaries available from somewhere (e.g. a website) which also offers the source code (e.g. GitHub would count)
6e) Ship the binaries via a P2P mechanism if you include a link to where you host the source code
Again, IANAL but if you hosted a GPLv3 binary somewhere without source code, it would technically be a violation of the GPL.
However, since you are the copyright holder in this case, you can ship it however you want - it would just prevent anyone else from then distributing it under the GPL since they wouldn't be able to comply with section 6, since they don't have the source code.
[append]
> wintun.dll, from the Wintun project, without mentioning it, thus violating its license.
Also, after reading the license, I don't see this particular clause at all.
For your code. The LGPL code still requires source distribution. (Plus, the BSD clause requires attribution.)
I am curious and want to understand, not arguing, but this is a serious allegation. Can someone point out exactly where the Wintun violation is?
I’m not a lawyer, but I’ve read the license [1] carefully, and I don’t see an obvious violation for failure to mention Wintun. Section 3 “RESTRICTIONS” does say no removing of proprietary notices, labels or copyrights - is that the problem? It says no redistributing the “rights of the Software” which is different than using the Software directly. And maybe(?) most relevant it says you cannot use the name Wintun to promote your own software, which seems potentially almost opposite of this claim of violation. The license does not seem to mention any requirement to post the name of the project, did I miss something subtle?
[1] https://git.zx2c4.com/wintun/tree/prebuilt-binaries-license....
> Section 3 “RESTRICTIONS” does say no removing of proprietary notices, labels or copyrights - is that the problem?
The license in itself doesn't say that, but the header to link to the DLL is dual-licensed under GPL and 3-BSD (note that the rest of WinTun is solely GPL), and all BSD variants requires notices (even if it is in an About section).
> It says no redistributing the “rights of the Software” which is different than using the Software directly.
So no sub-licensing, for example. They can distribute the software as-is (if using this license), but they cannot adjust the restrictions to a more permissive software (say, BSD or MIT license). This is to enforce GPL2 in other scenarios. This is equivalent in proprietary licenses, where it says that the software is licensed to you but its IP is not transferred.
> And maybe(?) most relevant it says you cannot use the name Wintun to promote your own software, which seems potentially almost opposite of this claim of violation.
"Promotion" here has a specific meaning, at least in the US. Mentioning that your software uses WinTun for legal compliance is not promotion. Mentioning WinTun in your advertisement for the software (unless to mention that it uses WinTun for its VPN), and especially mentioning that WinTun reccomends your software is banned. This might be very obvious, but even 3-BSD (example follows) has maintained this language because trademark laws are weird.
Extract of 3-BSD:
3. Neither the name of the copyright holder nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission.Haha, no. Even if entirely true, it's really not a serious allegation.
https://genesis.malwarebytes.com/api/v1/wai.gif
Not sure I would ever trust any privacy claims from a company that stores this type of made-for-fingerprinting data.
[0] https://www.maxmind.com/en/geoip2-precision-city-service
[1] https://www.maxmind.com/en/geoip2-isp-database
[2] https://www.maxmind.com/en/geoip2-connection-type-database
> Not sure I would ever trust any privacy claims from a company that stores this type of made-for-fingerprinting data.
Reminder that every resource you request from anywhere causes the server to be able to index all this info on you. Anyone doing anything where audience matters has a subscription to MaxMind GeoIP lookup, giving you all this info inline on every request. There is nothing special about this GIF except it shows you the info the server has.
If it bothers you, the idea of servers having all this info tying your requests together, you can switch on “Private Relay (Beta)” on MacOS and iOS, but note that the beta doesn’t play nice with a custom profile for DNS (it will look up once for filtering, and again for private relay).
FWIW I know plenty companies that try to be a good company and not just a profitable one.
A VPN (ideally with “kill switch”) + encrypted DNS would do the same for all traffic from your machine.
For the curious (a click through a proxy): https://archive.is/51hnq
{
"location":{
"city":"Manassas"
"country":"United States",
"countryCode":"US",
"state":"Virginia",
"stateCode":"VA",
"zipcode":"20109",
"latitude":"38.7911",
"longitude":"-77.5264",
"continentCode":"NA"
},
"connectionDetails":{
"isp":"G-Core Labs S.A.",
"connectionType":"CORPORATE",
"autonomousSystemNumber":"199524",
"autonomousSystemOrg":"G-Core Labs S.A."
},
"ipHash":"801ccd1d1dd4a01f73b789c5c25d70cd",
"classC":"45.135.229",
"ip":"45.135.229.10"
}Apart from all the legal trouble like dealing with copyright violations (DMCA emails), law enforcement requests etc. it is also increasingly difficult for the VPN providers to circumvent VPN detection services (like https://focsec.com). Netflix, Spotify and others are investing heavily into VPN detection technology, so it is a constant cat and mouse game, they always need to bring up new locations.
I never understood why. It seems to me that only effect of this "investing" is surge in piracy.
Back in the day Netflix really didnt seem to care about region blocking beyond the most basic check, and why would they - you pay your subs and you get content.
Being able to get more content by proxying to say the US etc actually got them more subscribers not less.
... but I don't think Disney is.
(And yes, Disney+ is technically only available outside of Asia - while some services inside of Asia is branded Disney+, they are not even the same system at all!)
> Mozilla also offers a white-label version of Mullvad VPN, while subtly implying that they operate the VPN themselves: “A Virtual Private Network from the makers of Firefox.”
Maybe 'misappropriate' is a bit of a stretch, and certainly the rest of the language in the above comment is tiresomely partisan, but it's not hard to see what they meant.
I can support Mozilla and use Mullvad at the same time. It wasn't a mystery who was running the underlying service to me, that was actually a selling point.
This quote is very telling of journalism today. Many internet publications and YouTube videos are just listcle machines and company marketing hype generators with very little actual investigative work.
Even mainstream channels that I consider decent like LinusTechTips very often stretch something that could be said in 2:30 minutes into a 10+ minute long video, making me feel like I'm wasting my time when I could read a few different articles in that same timespan and be better informed.
Not to mention the typical bullshit overselling of the capabilities of a VPN, while realistically for the average user the most useful thing about a VPN is being able to watch region locked content and torrent movies without getting a letter from their ISP. For any serious need for privacy using something like the Tor network is the best choice.
Disclaimer: I contributed to Wireguard but already liked Mullvad before they included Wireguard.
- Speed isn't always the fastest
- Desktop application isn't as polished
- Fewer countries supported
- Popular streaming services block it easily
- The account system might be confusing to newcomers
White these concerns are fair, I still think it's better than the competition.
Rarely I'll come across 403 errors. Usually when I do, it's another online store.
This is a feature. Some VPN providers resort to routing through residential IPs to unblock streaming services.
But they are a pretty awesome service. I will just pay with crypto next time I guess.
Are they shady now?
I also want to know if there is more to the story.
0: https://blog.malwarebytes.com/malwarebytes-news/2012/12/cham...
It installs a half dozen always-on background processes, even on Mac. These processes are constantly phoning home [with an obfuscated payload].
I have written to them to ask why a on demand scanner is doing this and got no response.
I suspect that they have are highly regarded mostly because of good marketing.
By the way, they call themselves "Malware Bytes". History says that when someone tells you they have nefarious intentions, you should believe them.
However, none of that is related to this article, which is just them using some open source software without bothering to keep the license requirements.
To be fair, that's likely going to be a requirement to detect any malware that actively hides itself.
Using a VPN adds an additional potentially untrustworthy third party in a privileged position to monitor your activity. Do the benefits outweigh that cost?