Mullvad is now available on Amazon
mullvad.net
mullvad.net
I know Mullvad already allows you to e.g. send cash in an envelope for total privacy, but that's kind of a pain, it'll take a long time to arrive, if the envelope is lost there's nothing you can do, etc.
But by physically printing covered-up codes on cards, this actually uses Amazon to create the privacy/anonymity, which kind of feels ironic given how Amazon generally tries to hoover up all the data. You can get your code with fast Prime delivery, a tracking number, pay for it with your credit card, get a free replacement if it's lost in the mail...
I love this.
While the majority of people might still redeem the code themselves, you can't automatically assume that the person who bought it is the one using it.
...and even if you think you can convince a jury, it's still enough to issue a search warrant, whereby the prosecutor will find more than enough charges to force you into a plea deal.
Your initial anonymity is your most important defense.
What exactly do you base this on?
First of all, Mullvad (like any serious VPN operator) do not log IP:s and one can probably safely assume they do not log who bought which gift card. They are also under no obligation to do so, as far as I’m aware.
But let’s assume for the sake of argument that they did: let’s assume they log IP:s and sales of gift cards down to the social security number of the person who bought it.
Now assume that I’m running a corner store where I sell among other things these gift cards, that I bought from Amazon at a small markup.
Someone uses these gift cards and the tracking (that doesn’t exist) leads back to my store.
I’m defending myself in court in a democratic western country where people are assumed innocent until proven otherwise.
The jury (in the US) or the judge (anywhere else) is informed that I buy these cards in bulk, I sell dozens of them a week, and the IP (that Mullvad doesn’t log) is a dead end.
Do you seriously believe that a judge or jury anywhere would sentence me for the crime brought forward, or that this would even hold water enough to be prosecuted in the first place?
This is almost exactly analogous to selling anonymous SIM cards (where they still exist). One is used for a drug deal. Me, the shop keeper, is prosecuted in this alternate universe because I’m selling the cards.
Really?
There are no such countries; that standard would make it impossible to get convictions for almost every crime that ever occurred.
Compare this case from the United States: https://volokh.com/2014/01/02/wrongful-convictions-proof-bey...
> In October of 2007, Elizabeth P. Coast, then seventeen, reported that when she was ten years old a neighborhood boy named “Jon” sexually assaulted her while the two were alone in her grandmother’s backyard
> [the trial court] tried and convicted Montgomery in a one-day bench trial for the assault of Coast. Coast testified under oath that Montgomery had sexually assaulted her in 2000.
> no other witnesses to the incident testified at Montgomery’s trial. Neither was any corroborating physical evidence that an assault occurred ever presented. The trial judge categorized this case as a “word against word situation.” In reaching his verdict, the trial judge concluded that Coast was more credible then Montgomery because she had “no motive whatsoever” to lie. The trial court then found Montgomery guilty of forcible sodomy, aggravated sexual battery, and object sexual penetration. On April 10, 2009, the trial judge sentenced Montgomery to 45 years in prison, with 37 years and 6 months suspended…
> On November 1, 2012, Coast voluntarily made a videotaped statement at the Hampton Police Department. After consulting with counsel and receiving Miranda warnings, Coast recounted how she had falsely testified that Montgomery had assaulted her.
> Coast explained that immediately before she accused Montgomery, her mother caught her looking at “sex stories” on the Internet. Out of fear of her mother, Coast said that she was looking at inappropriate material because she had been molested when she was ten years old. After she reluctantly named Montgomery as her attacker, the lie snowballed. Coast felt like she could not admit that the assault never happened
Generally speaking, "innocent until proven guilty" is a cornerstone in most legal systems. This has been the case, literally, for millennia, dating back to Roman times.
It is also one of the UN's human rights, and is enshrined in several countries' constitutions.
You could publish a dozen similar anecdotes every day for a decade. What's unusual about this one is that the girl was stupid enough to later admit she'd been lying.
> Generally speaking, "innocent until proven guilty" is a cornerstone in most legal systems. This has been the case, literally, for millennia, dating back to Roman times.
> It is also one of the UN's human rights, and is enshrined in several countries' constitutions.
So? Compare https://en.wikipedia.org/wiki/1977_Constitution_of_the_Sovie...:
> The Soviet Constitution included a series of civil and political rights. Among these were the rights to freedom of speech, freedom of the press, and freedom of assembly and the right to religious belief and worship. In addition, the Constitution provided for freedom of artistic work, protection of the family, inviolability of the person and home, and the right to privacy. In line with the Marxist-Leninist ideology of the government, the Constitution also granted social and economic rights not provided by constitutions in some capitalist countries. Among these were the rights to work, rest and leisure, health protection, care in old age and sickness, housing, education, and cultural benefits.
Of course, having the rights in the constitution didn't mean anyone was allowed to exercise those rights, and they most certainly weren't. "Innocent until proven guilty" is a set of words that people believe in saying, but it is not a set of beliefs that people are willing to put into practice. It has nothing to do with the legal system of any country in the world. For most crimes, proof of guilt cannot even theoretically exist. (As was true of Elizabeth Coast.)
This was covered fairly extensively in my first link:
> What’s doing the work in many of the convictions, I suspect, is that the very ubiquity of the risk makes factfinders realize that — if we were to constantly consider this generalized risk, in the absence of more specific information — a wide range of crimes couldn’t be effectively prosecuted. That’s especially true of child molestation and rape, but it’s also true of many sorts of felons’ possession of guns, robberies, and the like. It’s always possible, and not extremely unlikely, that a police officer was just trying to frame someone he already thought was a bad guy.
> But I think many people (again, deliberately or subconsciously) are unwilling to see acquittals in all such cases. A seemingly disinterested supposed victim’s testimony thus tends to be credited (unless the victim seems untrustworthy for other reasons, such as the victim’s own past criminal record). A police officer’s testimony tends to be credited, at least by many jurors. And this is so even though there is good reason for doubt, simply because whenever we are dealing with human testimony there is good reason for doubt.
> So... the “beyond a reasonable doubt” standard ends up being, in many cases, considerably less defendant-protective than one might think. Maybe that’s bad, or maybe it’s a necessary evil
So? Once again, they are anecdotes. I can similarly provide thousands of anecdotes showing presumption of innocence. It means nothing except that those cases happened.
Do you have any proof "it is not a set of beliefs that people are willing to put into practice" on a systematic scale?
> So? Once again, they are anecdotes.
"Anecdote" doesn't just mean "something I'd prefer not to have to think about", you know. Being very common makes the event systematic.
> Do you have any proof "it is not a set of beliefs that people are willing to put into practice" on a systematic scale?
Yes, we've been talking about it for a while.
> I can similarly provide thousands of anecdotes showing presumption of innocence. It means nothing except that those cases happened.
That's... not how logic works. On the one hand, we have hundreds of thousands of cases of people being railroaded for crimes they didn't commit based on no solid evidence. On the other hand, we have tens of millions of cases of people being railroaded for crimes they did commit, also based on no solid evidence.
But let's assume that second group consists only of convictions where the defendant's guilt was somehow actually proved. That wouldn't mean the system operates on the principle that people are innocent until proven guilty -- that claim is already falsified by the existence of the first group. It would mean that proof of guilt is often provided even though it isn't required.
The thing is that when dealing with something on the scale of the justice system even a hundred examples don't mean it occurs more than a fraction of a percent of the time. When assessing anecdotes to try and determine event frequency you need to understand how the anecdotes were sampled.
The law and law enforcement are two different things. Law enforcement works roughly like this: they get an IP of a website, they go to an ISP, the ISP says its this reseller, they go to the reseller, the reseller says it is this customer, they go to the customer, the customer says this IP posted the bad thing, they take the new IP and go to the ISP, ISP hands over the original users details, they go knock on the users door.
It is basically a turd rolling down hill that nobody wants to touch and everyone wants to pass on to the next person. At each step YOU are responsible for the bad thing that happened until you give them a new person to look at.
If you think it works any differently, take a look at what happened to the "TheDonald" forum after January 6th. You can shout and scream about freedoms and rights all you want, but when your girlfriend has to explain to her boss why the FBI came around asking questions about you - you hand over the next guy down the line super quick.
You’re just making assumptions without referring to the facts.
Mullvad is a Swedish company and falls under Swedish and EU jurisdiction.
ISPs in the EU are indeed required to keep track on what subscriber had what IP at what point in time. Some do this gladly and some try their absolute best to sabotage the process (like Bahnhof).
However, Mullvad is a VPN provider. They are not an ISP. If you claim that Mullvad is legally required to log IPs, then source that claim, because they clearly are not and if that claim is true that would mean they are breaking the law, which I doubt they would be willfully doing.
In your example, the buck stops with the VPN provider (which again, is not an ISP) because the info they provide is of no use.
In some cases, the buck even stops with the ISP without a VPN, because in many jurisdictions there are demands placed upon the seriousness of the alleged crime to allow personal data to be supplied to law enforcement.
The whole "based in X country" is just a gimmick.
But you are really missing the forest for the trees here. If the crime against the US is serious enough, extra-judicial rendition is on the table. So is extra-judicial execution. https://en.wikipedia.org/wiki/Assassination_of_Qasem_Soleima...
The idea of being based in a specific country giving you some sort of immunity is disingenuous.
What happened? I missed it.
You bring up a very good point. Unlike an electronic payment system [0], I assume the amazon gift card is not linked to your account on Mullvad's servers, so probably Mullvad marks the account as paid, but doesn't log the Amazon card number
0. Even that should be safe. Mullvad made a recent decision to get rid of subscriptions. Now that your account is never linked to your payment method, and we can assume that it's safe to use your personal credit/debit card. But I'd be careful, if someone is important, there is a possibility of someone tracking and logging their activities, credit card use, IPs before Mullvad purchase and after they connect.
In some jurisdictions, like Sweden (where Mullvad is based) there is such a thing as "help to commit a crime" that does get prosecuted
Unless you’re in an authoritarian regime where the courts simply follow the whims of the political leadership, selling SIM cards, gift cards for a VPN, knives or ski masks will hardly in separate cases by itself be considered obvious intent to assist criminal activity.
Nevermind the fact that you're at trial where a judge and jury is looking at this. Nevermind that the point the GP made was that if you have someone knocking on your door motivated to find something they will find something.
I am assuming if you are a nefarious actor, the goal is to not have this kind of attention, ever. You do this in all of the traditional ways - insulate and delegate.
If you buy these cards and re-sell them, you have plausible deniability. If you buy them from a re-seller you have increased anonymity.
Obviously the goal for a nefarious actor (or anyone, probably) is to not end up in court. But it’s objectively true that the idea of Amazon gift cards does in some scenarios actually give you increased anonymity compared to other payment options, if nothing else because of the timing offset if you want to disregard re-sellers.
Sounds extremely unlikely.
Buying a Mullvad gift card makes you at most a Mullvad customer. The cards are presumably one SKU, none of Amazon nor Mullvad know which one is sent to a given person.
I'm not sure what the connection might be to warrants here? Surely if a judge will sign on "hey this guy uses a VPN can we grab his laptop?", that judge would sign on any other flimsy excuse.
Step 2. They start looking for evidence
Step 3. They find uncommon actions you took to make your browsing history harder to track.
Step 4. Judge
Step 5. https://xkcd.com/538/
No one will prosecute you for using Mullvad but using it may be a red flag that you have something to hide if you’re already under investigation
Legal cases are not code, they are often fuzzy and loose, and rely on human interpretation, with all its biases and emotions, to draw a conclusion.
If the cops confiscate your computer and Mullvad is installed, and your Amazon account has a purchase history of Mullvad gift cards, your claim of “ive never used it before. Those cards were for someone else and I never used the software” won’t get you very far.
For example, "It wasn't me. A friend used my Wi-Fi!" and similar arguments will not fly as you can be seen as responsible as bill payer. Those kind of defenses could even be considered admissions of guilt.
It's concerning to see how many people suggest you claim your Wi-Fi was unprotected if accused of something. This will more likely be used against you if anything.
Even you get into account directly. You see the user using a code redeemed from gift card. And then?
You can't associate the code with anything at all even you also hack into mullvad's server. There is no way to tell that where the code was from even for Mullvad themselves let alone others as long as there is no serial number that also displays on card without scratch open it.
all that can be said with certainty is:
1. that these people bought mullvad cards on amazon.
2. these mullvad accounts were paid with cards
All you can say is that 2 is a subset of 1.
If mullvad sells the cards literally anywhere else, then you can't even say that with certainty.
Mullvad doesn’t even have to sell them anywhere else: anyone who bought one on Amazon could have re-sold it, individually or in bulk. That’s the clever part.
If i tried to claim in court I bought and resold, they'll expect to see the paper trail or judt dismiss my comment
The point is that you don’t have to do this, someone else can do it for another reason (namely profit) and the increased anonymity still applies compared to the other payment options.
There have been countless cases demonstrating that "no-log" VPN providers definitely do log, and even if by some miracle Mullvad doesn't, they can be compelled to start doing so, as the Protonmail case demonstrates.
This does nothing to reduce the paper trail.
If you really really really trust Mullvad (and you shouldn't), just use Monero.
The on-ramp to "just use Monero" isn't that simple for over 99% of users I'm guessing. Also, if they have your IP address logged, does it even matter how you paid?
It might even be more likely to deanonymize you since you're forced to interact with a physical thing. It's an extra step in the obfuscation chain that adds personal information (mailing address at least) that wouldn't be added otherwise.
I suppose if you were forced to use a non anonymous crypto like bitcoin that can be easily tracked, there might be some value to this extra step.
Don't get me wrong. I think Mullvad is a great VPN service. But if people think it's a bullet-proof solution to the problem of anonymity, they're fooling themselves.
1. The VPN provider and its infrastructure is trusted.
2. Attackers (private or government) can access data the VPN stores some period of time after you use it, but not while you are using the VPN.
3. Given assumptions (1) and (2) are true, attackers should not be able to determine which websites you visited.
A VPN does nothing if you don't trust the VPN provider (since they can always be lying about keeping logs) or if the government can access the VPN's servers/data while you're using it. But it does protect against one of the most common ways a government/private party could gain access to your browsing history: the government/private party subpoenas the websites you visited or your ISP for all pages visited by a given IP.
In this case, providing an alternate way to pay protects against storing data that an attacker can use to connect your account to your identity.
With single payments they don't need to keep it for so long.
Cause this sounds like something I read a few months ago. A pretty silly plan.
That can’t be Mullvad’s target market? New to VPNs, forgive the ignorance.
You might start investigating the state of planet earth by reading e.g. https://rsf.org/en and will find many other hints for more sources.
Police these days prefers to scout the internet for thought crime and to have an excuse why they don't go after burglars etc.
https://nypost.com/2022/03/31/twitter-user-sentenced-to-comm...
>Other Brits who have been convicted under the same law as Kelly include a law student who was sentenced to community service for sending racist messages to a soccer player and a woman who posted songs about Holocaust denial on YouTube.
For more disturbing details of what is to come for UK, read this page:
https://www.gov.uk/government/publications/online-safety-bil...
practically: everybody
For gift cards it's more async, but given that payment processors keep records that can be correlated, if Mullvad isn't careful about timestamping, how it records crediting to accounts, or the like, it would be extremely easy to de-anonymize account relations IMO.
I suppose if you're in the EU you might be able to get away with it but it is indeed tough.
The main thing that I think is missing in Mullvad's FAQ is about if they have backups of their data. If they do, then differential analysis is possible. Perhaps they only keep backups of past 14 days or something.
There are couple of risks involved using this service:
- adversary identifies that a Mullvad user is doing something, and activity started around X. They might be able to figure out what account number is associated to that.
- adversary identifies that Mullvad user X is doing something. Through payment records and differential analysis (along with other information from banks or the like) they could identify who user X is (modulo credit card theft and the like of course).
Given that Mullvad had accounts with payment processors and those processors have record keeping requirements, it feels like the second threat is very practically doable without very smart handling of backups. But it does seem like handling the first threat is done relatively well. The one risk is that someone starts doing something risky right as they sign up to the account.
Mullvad states 500k accounts. over 10 years that's 136 people/day. You're still looking at a pretty wide net if you can isolate payments from a certain time period.
I pulled the plug on Nord years ago and haven’t looked back.
Steady the course my friend.
NordVPN and all the other janky services in that space do a couple things adequately, you can pretend to be from another country and get some duck-and-cover on things like torrents, if your ISP doesn't like that kind of thing.
I'm in the same boat, basically. Would it be nice to have a VPN which takes actual security seriously? Sure, of course, but until the end of the year, what $VPN does do is paid for, and I don't care enough, in isolation, about what Mullvad offers vs what I'm getting for free.
Next time my wallet comes out is a different story.
Home ISP ---> (optional VPN to connect to rdp.sh deployed VM in the cloud) ----> Mullvad VPN on the bastion host
This is of course, not viable for the long term and very cumbersome to deal with if you're doing this on the daily. Unless you are under threat of a nation-state threat actor... you'll be fine.
Theoretically, chaining 2-3 VPNs together Tor-style would be far better (assuming they all support similar payment methods as Mulivad), but I don't know of any VPN clients that support that.
Obviously correlating a purchase to a specific account is much harder, but it still seems like a compromise on privacy.
Sounds like a solid plan.
You guys don't seem to realize that tyranny won decades ago, and you're fighting a war that has long been lost.
We are all serfs and slaves.
They conveniently list their providers here [1]. For an online shop we operate, we have blocked most of these ASNs because 99% of the traffic we saw from them was malicious.
1. Only allow known/cleared bot traffic from any non-consumer ISP.
2. Block any ASN where bad traffic comes from especially if there is no good traffic.
3. Block any VPN services.
I don’t know if Mullvad have their own ASNs or if they are hosted at services with ASNs that is classified as consumer ISPs or not. It is probably a mix.
I know for instance that OVPN have servers at some shady non-consumer ISPs. So, it sometimes gets blocked. It is also, unfortunately, not uncommon that VPN connections are used for attacks. And if the VPN uses a smaller service provider, then that whole ISP may get blocked. If the VPN uses a shady service provider. The VPN may fall victim to other user activity from that ISP.
I have not worked with any site that blocks VPN all together. Tor is often blocked along with some countries. Some streaming services blocks VPN though. Most sites do not, I think.
The way things are going right now is that these types of services will become more difficult to use on legal commercial sites over time.
No need to specifically invalidate the code inside to stop you from doing refund fraud.
So my guess would be Amazon doesn't take returns on giftcards in the first place.
Look at the hundreds of people online who bought Battlefield 2042 from Amazon. They ship a CD case with a slip of paper inside which has a code.
Hundreds of people tried to redeem codes that had already been used.
This happens to every code-consumption-based retailer. Thankfully Amazon still eats the cost of "doing business" currently.
This is what I do - I can't use router-based VPN or piHole type stuff because people on my network work on ad-related products or use sites that don't play well with VPNs or DNS-block lists of advertisers, for example.
Of course, you can terminate the VPN software manually and the kill switch and access sites using no VPN if you want, which allows for mistakes, but pretty rare in my experience. Best is to simply have another machine that doesn't have VPN software on it and you use over the naked Internet.
Also if you are new to the game, make sure you use wiregaurd, it leaves the large complex VPN protocols of old in the dust. It adds almost no latency to my connection, sometimes speeds things up.
sure it'll make for the perfect mother's day, I'm sure me mum can't wait to try it (???)
I mean, I guess I just can't comprehend buying it for someone else
More on topic: Doesn't say on the page, but does the card ever expire?
But this is pretty much fine. Maybe/hopefully (I'm not too lazy to check - 'GB' is 'upcoming') I can Amazon-subscribe and the only difference will be a bit of code-entering admin.
Starbucks snooping is resolved by more ubiquitous technologies like HTTPS, DOH, and encrypted SNI.
It narrows things down immensely, and many IPs will not have many users.
Wait, Finland doesn't have a localised Amazon. We have to buy everything from other countries (usually Germany). How does this work?
In countries that filter the internet, people do buy and sell physical VPN gift cards, to enable usage of somewhat shady VPNs.
Here's a totally legit option.
Considering that a primary use-case for a VPN is as one of the tools to help shield your data from the rampant data thieves, of which Amazon is a particularly powerful adversary, I would need a much clearer explanation of how this is a privacy enhancer.
Mullvad having a business relationship with Amazon is inherently troubling.
Now an adversary with enough geographic information about who connected and access to all of amazon's data could possibly correlate purchases with connections. 10 years ago I would have considered that infeasible, after Snowden I'm not so sure. If you live in a big city it is like still no issue, but if you are in some small town with a population of 1000 things might still be traced back to you. Still it's likely significantly superior than pretty much any other method including using crypto. If you are a possible target of a state actor you hopefully are thinking about this already.
Weirdly enough it's also cheaper to buy a 12m card there (500SEK instead of the usual 600SEK). Checked, and they're listed as a reseller on Mullvad's page so they must've gotten a good deal / are selling at a loss.
And realistically, if you're that paranoid, you're not trusting VPNs at all. You're using Tor.
NordVPN, on the other hand, is probably the worst choice for a VPN.
https://www.techradar.com/news/nordvpn-will-now-comply-with-...
That just makes your comment look silly.
Hopefully soon! It says "upcoming"...
I feel like this is - sadly - more and more required as well when browsing HN as there seem to be more and more postings where an advertisement is disguised as 'hacker news'.
Can someone enlighten me how the availability of coupon codes for a VPN provider on Amazon is considered news?
I think people here are also interested in the steps Mullvad takes to improve user payment privacy, as again every time "news" about new methods of payment or concealment of user payment history is always met with high praise and interest. (as far as I've seen anyway)
The government do get a limit number of potential users. Can this together with fingerprints, ping latency(?) etc. be used together with amazon info to narrow down the vpn user (in theory) or is that impossible?
For example, if mullvad only had 5 users in separate continents, could one measure the latency and crossreference with a amazon buy history to identify the vpn user?
To a prosecutor, that means they have a conspiracy or even RICO case on their hands.
A specific example from a little while ago in my life--I saw an article advertisement for Microsoft's sovereign cloud offering. I thought this was interesting because I think the Internet is balkanizing over time and how megacorps try to play in that scenario interests me.
I still don't know that it qualifies as news, to your point, but Amazon involvement, however incidental, in Mullvad is a datapoint I'm glad to have.
This is a product announcement from a startup. HN is all about products and startups and this one in particular is popular here. Advertisements aren’t necessarily bad, and as far as ads go, this one is the best kind.
Fun fact: The original name of HN was actually “Startup News”.
This is part of what makes HN unique and great in terms of tech news sites.
I don't use a VPN, but am glad to know of product offerings like this. If this is an "ad" then bring it on, I say.
Mullvad: PLEASE don't sell your company.
About us
Mullvad VPN AB is owned by parent company Amagicom AB. The name Amagicom is derived from the Sumerian word ama-gi – the oldest word for “freedom” or, literally, “back to mother” in the context of slavery – and the abbreviation for communication. Amagicom stands for “free communication”.
The team
Mullvad VPN AB and its parent company Amagicom AB are 100% owned by founders Fredrik Strömberg and Daniel Berntsson who are actively involved in the company.
The successors (family) to Fredrik and Daniel might have a different view.
At least in my lifetime, I won't be worried
disclaimer: I'm a random dude on the internet that thinks he know more than he does.
SIM cards requiring registrations is a development in the direction towards less privacy, I’ll give you that.
Lastly, since when has it been optional to be folkbokförd in Sweden?
You might not like it but it is true. Finland had a plan to join NATO in case they felt they had to. And when that happened they had plenty of political and public debates and support. Sweden's plan was to cooperate with Finland. In the declaration of government from late last year it was declared that Sweden shouldn't join NATO. So when Finland wanted to join NATO Sweden no longer had a plan and therefor without convincing debate or support also requested to join NATO.
This is important because laws, policy and principles aren't worth much if you can quickly change them. Sweden has shown itself capable of changing fundamental things if it is sufficiently freaked out. And to do so without much resistance or recourse. As Sweden had no alternatives, and with many even stating so publicly, it also isn't in much of a position to resist demands from the US or other countries like long standing members would. It is likely that Sweden will become a "Nine Eyes" country like Denmark which has resulted in numerous incidents for them in recent years.
And these are not the only examples. It's everything from Swedish police using teargas for the first time in history with barely anyone noticing to not being able to publish scenic drone footage without approval.
EDIT - apparently this hit a sensitive topic, sorry to offend IKEA or Mullvad fans
You can buy a bedsheet called Häxört
Or outdoor furniture called Äpplarö
Or a rugs called Ådum
https://qz.com/896146/how-ikea-names-its-products-the-curiou...
One concern though, is the blanket blockade of their IP addresses accross multiple services; I'm not talking about the avalanche of captcha's one must deal with, but for example: I wasn't even able to update a fresh install of ubuntu via sudo apt-get update && sudo apt-get upgrade... it refused to connect to mullvad IPs.
I've been running into this problem more and more, first it was linux distro issues, then, my gaming client, and perhaps the worst, Github itself.
I'm not sure what the solution is here, since Mullvad provides unparalleled respect of privacy; but the IP's they use are almost always associated with the highest levels of fraud.
Perhaps, this is the price I am willing to pay for privacy done right. Props to Mullvad, for being the best in that regard.
On the one hand, browser automation is extremely effective and nearly indistinguishable from human traffic, and bot traffic often eclipses that of human visitors, depending on what you're serving, consuming an enormous amount of resources.
On the other hand, using IP-reputation to decide who gets a captcha is one of the few methods that undeniably works. It's really unfair and I wish it didn't have to be that way, but at least for my websites, I can't serve traffic to human visitors if I don't discriminate against these IP blocks with captchas and whatever. I just don't have the hardware. The bot traffic I get is something like 50x that of sitting at #1 on the HN front page.
So you'd still have the CAPTCHA of today but with an alternative.
Assuming it's something that would seem to be a usable and smoother solution for those people you are today locking out or providing a hassle for without significant increase of malicious bots (maybe you'll even get less if it works all right and it means you can tune up the aggressiveness in the rest of the system), about how much willing would you be to try something out?
(I'm aware of PrivacyPass but IME while I did have it work at times, most of the time it works extremely poorly to the point of being unusable on both Cloudflare and hCapctcha, while maintenance and support seem on the backburner)
For a particular definition of "works." Giving everyone a captcha would also "work", but with different tradeoffs.
Thankfully Mullvads client lets you filter servers by provider so it's easy to take M247 out of rotation
This is both their selling point and their main problem; privacy means criminal abuse. This is true for all kinds of anonymity, hiding your tracks, hiding your payments, etc; TOR, cryptocurrencies, encrypted chat, they all suffer reputation damage due to criminal abuse.
And there is no obvious solution that does not impede users' privacy, as far as I know.
I would not be so fatalistic about impossibility of policies that respect privacy.
This would be a weird gift to give.
A $1.3T behemoth that readily reports Ring data to the pigs and runs large-scale cloud contracts with the Feds totally won't run these cards through a UV-B or X-ray scanner to correlate and log the activation codes.
You're 100% safe with Amazon. Hell, they even have a smile in their logo. Who could possibly doubt that?
There are probably indirect ways to force a linking, but they are probably also highly illegal. And people could also just exchange gift-cards or use more indirect ways to buy the cards, to dilute those data further. So overall this is a rather useful solution, as long as more than a handful people will buy them through amazon.
This is the part I’m not following. Unless Amazon takes specific steps to intentionally not track the code (and this doesn’t sound very Amazon-like) , why would we assume Amazon doesn’t know the code?
The scratch off protection is to prevent shoppers from seeing the code in stores, and to provide assurance that the card hasn’t been used yet (“used” as in the number is now in someone’s possession).
Edit: I misinterpreted the nature of these cards and commented prematurely.
The above attack might be a possibility if you're already being actively tracked by the NSA, but at the very least this approach gets you some degree of forward privacy in case the NSA only starts hardcore snooping after the card was already delivered to your door. Whether or not it is a useful degree of privacy is out of my area of expertise.
They'll know you bought a code, but won't have any way to connect your purchase to a VPN user. You might not even be redeeming the code yourself.