The M247/DataPacket Problem with Mullvad VPN
worldofmatthew.com
worldofmatthew.com
I think it's pretty clear which servers are owned and which are rented.
https://mullvad.net/en/blog/2019/10/25/server-list-updated-p...
[quote]On which level and for what purposes do external parties have access to rented servers?
Hosting providers do the initial operating system installations (most often through the remote management software), after that we remove their access from the server. After this they may have access to the remote management software of the servers, so that they may aid in rebooting and reinstalling faulty servers, but they have no direct access to the operating system or the software running on the server itself.[/quote]
If its a PiKVM, they can configure on the OS something like usbguard to reject the KVM keyboard (while still allowing access to the reset and power buttons via jumper). However, if its iLO, then its a BMC and I believe it has full access to the host regardless.
Of course the exact same goes for servers hosted by mullvad themselves.
A VPN provider of their scale just doesn't fly under the radar.
Considering the threat model for most users this is fine. It's good enough for avoiding copyright lawsuits after torrenting. If you're on the radar of state actors, Tor and i2p are a better bet (but I'm sure their exit nodes are heavily monitored too!)
VPNs are great when the network you're on is less trustworthy than any other network you have no visibility into, such as in places where the network is heavily censored or otherwise restricted. They're also widely used for evading country-level streaming restrictions. But VPNs aren't really the right architecture for privacy more generally.
This can be addressed by using tunnels to create multiple hops.
See for example: Tunneling tunnels within tunnels (inside of tunnels) — https://cryptostorm DOT is/blog/multitun (I broke the url because otherwise HN is incorrectly marking the comment as [dead])
It would be great if Mullvad adds multi-hop support (>2) based on something like that.
Another possibility is to create a VPN on top of a Mixnet like Nym: https://nymtech.net/.
[1] Mullvad owns 159 servers in 9 countries (https://mullvad.net/en/servers/), so not quite sure why you wouldn't just choose to use one of those instead if concerned about this
So he's claiming that Mullvad gets things right that other providers get wrong, but they're still missing a critical step.
At the end: "All in all, Mullvad VPN appears to have put expanding the number of locations over user privacy. That points to a bigger problem in the VPN industry. That is a lack of a perfect provider. Mullvad VPN has multiple hops available but AzireVPN chooses their upstream carefully, runs everything from RAM and uses a custom made TPM-Level Rootkit that blocks common network monitoring features in Linux but does not offer real Multi-hop (Only though Socks5 proxy)."
So every problem has a solution, but no VPN is offering all of them. But I suspect that's because VPNs are mainly for downloading movies and shitposting on the internet.
or not giving your ISP a list of which websites you visited when in a situation where you could only get internet by agreeing to allow the ISP to analyze your traffic and sell the result
or to avoid regional legal restrictions which are not on the level of "if you are found out you have major problems" like non GDPR compliant US sites blocking EU users and you are from the US on holiday in the EU (most such sites are very US-local specific)
or to avoid doggy price differences depending on from where you buy something
I mean if you worry about attacks like described there you probably shouldn't use VPN anyway and probably "just" using Tor isn't good enough either.
In my country they log everything if they did setup black boxes to analyse timing in an attempt to de-anonymise then they could potentially log everything which is what they definitely do without a VPN, how am I worse off?
Matthew is not upfront with their readers about these risks.
Someone in Iran could probably couldn't care less if the British are monitoring them, and perhaps vice versa.
Those who are really worried about something will fight against that worry, or use Tor, no matter how painful it may be.
I did however notice that a lot of the geo-located services have stopped working on Mullvad endpoints, as those VPNs (like many) have been blacklisted widely now.
There was an Ask HN from 2 years ago that was also suspicious of M247 [0] -- verging on paranoia -- which provides only weak evidence, but it does not encourage us to unblock M247 anytime soon.
I guess this is the price we pay for having such VPN services relatively cheap ($5.00/mo). If they rented servers of specific server providers in an area, that gets expensive, fast.
I've been using Datapacket for a year for my e-commerce company. Amazing performance, stability and service. Best dedicated hosting I've experienced in a long time.