Security audit of account and payment services
mullvad.net
mullvad.net
I still haven't gotten any response from SurfShark about why they insist that users install a root SSL certificate and why their service can't be used without it. That alone should be incredibly scary. Installing a cert for negotiation between my computer and my provider's is one thing, but installing a cert that lets my provider spoof any SSL / TLS they want is something else entirely.
Ideally their client would allow for you to accept or even better pre-load a cert they allow.
But some OS's can be finicky about trusting certs that arent loaded into some central trust store that in principle allows you some ability to ensure everything trust IS trustworthy, but also de-facto means a cert trust can be abused.
However thats as true for the google certs, or the Gov certs that are already pre-loaded and updated with OS updates etc as it would be for that service. And rarely are people actually looking at trust chains for the sites/services they use.
That said, i would trust google or even the NSA/gov over some rando vpn provider, if for no other reason than its on literally every install and there are millions of preying eyes watching.
There are many VPN services that begin by reselling white-label VPN solutions, such as provided by NordVPN,[1] because it's cheaper and easier than building your own globally distributed high-capacity, low-latency network. Many suspect Proton VPN did so[2].
[1]https://nordvpn.com/white-label/ (old link, can't find an archived version of the page) [2]https://archive.is/iZ2l2
Even though, to me, it seems like a LOT of trouble since tons of services have managed to roll out a VPN product without resorting to white labelling Nordvpn
I would like to reiterate that this is completely untrue and borders on disinformation.
ProtonVPN maintains its own VPN infrastructure, and we take our commitment to user privacy very seriously.
It shouldn’t be surprising that the VPN space is a very competitive market, and certain people have a vested interest in defaming certain VPN providers, especially among a technical audience.
> https://en.wikipedia.org/wiki/Crypto_AG
> https://www.washingtonpost.com/graphics/2020/world/national-...
Personally, I just don't see how you can possibly trust any assurance offered in the current world? You are implicitly handing your private traffic to a third party black box and hoping it is as "private" as they claim. For 99 percent of customers I'm sure this is fine, but I would not be surprised in the slightest if we find out in the future one of these was run by an intelligence agency. We've already seen them take advantage of fake/compromised encrypted messaging apps.
In the US, I would suspect all of them. They ply you with multimillion dollar contracts. If you try to resist, they weaponize whatever they can against you. Consider the case of Qwest. After the CEO refused to work with the NSA, he was brought in on unrelated criminal charges: https://www.foxbusiness.com/features/former-qwest-ceo-joe-na...
As with anything relying on trust with a third party, one should definitely actively assess their individual threat models and risk profiles. It might be useful for parts of your traffic, not necessarily all
For outgoing, I also heard that proxychaining is a thing (which might not help you if collaborating actors compromised all obv)
I've tried twice, and it just wouldn't work. I tried with their software built from scratch, and I tried their OpenVPN stuff.
Once I can find a way to make it work, I would definitely use it.
I don't see why you'd want anything to do with them or their subsidiaries, unless your only research is googling "best VPN" and accepting the resulting misinformation at face value.
I've been a Mullvad customer for a couple of years now.
I actually have a wireguard connection right on my pfsense router, so I can selectively send traffic to the VPN at a network level using firewall rules. It's awesome.
Oh awesome. I have some EUR left over as well. You can't send cash from the US to Sweden via mail right?
Not sure what would happen if they caught you.
Where the line in between lies, I have no idea.
I assume it’s to avoid responsibility and money laundering.
From what I see there are limits on the amount of cash you can mail in the US as well.
In reality, nobody gives a fuck if you mail someone 50 euros.
I'm also in WA. Did you just use https://www.usps.com/international/first-class-mail-internat...?
According to https://www.usps.com/international/letters.htm, it sounds like for cash you need to file a customs form. Did you do that too?
> [...] paper money [...] are prohibited in Priority Mail Express International shipments to Sweden.
So don't pay for Priority Mail Express, just First-Class:
> First-Class Mail International is a generic term for mailpieces that are postcard-size, letter-size, or flat-size and weigh less than 16 ounces [...]
If you don't trust the network you're on, use Mullvad. If you want to appear as though you're in a different location, use Mullvad. If you want to bypass your network's firewall, use Mullvad. If you don't want the service you're using to see your true IP, use Mullvad.
But most people don't need a VPN running all the time. Or even most of the time.
And while yes, you don't provide your personal information directly to Mullvad, it wouldn't be very hard to deduce you from your traffic with some amount of effort.
No more than any ISP, and (in the USA) they're pretty universally going to spy on you, so even if (ex.) Mullvad is a coin-toss it's a win.
That site is now storing the link between your IP address and that other information. Some of those will be hacked, leaked, aggregated and combined with other datasets at scale.
Of course, your ISP/employer does know that you're visiting the Internet cafe, and in the case of work (and some ISPs) can stop you from doing so.
If you visit a website from an Internet cafe, the website may still be able to figure out who you are, just like they can when you bounce between different networks normally. And of course, if you login to your account on a website or put your shipping address or something in when buying something, you're self identifying (unless you have throwaway accounts or forwarding addresses or whatever). And finally, if someone really wants to figure out who you are to a high degree of confidence, they will.
I find this lands pretty well and is close enough to being technically correct without getting into the details that non-technical people would start glazing over if I got into.
https://www.vice.com/en/article/jg84yy/data-brokers-netflow-...
A commercial VPN, even a very good one is probably not good protection if you're being directly targeted by the NSA. It's very good against your ISP selling your browsing habits to advertisers. There's a spectrum between the two and it's likely decent protection for most of that.
If you are targeted by any 3 letter agency this will not help/save you.
If you're worried about your shady ISP and/or other entities mining the heck out of your traffic and/or selling this data it helps.
VPNs won't let you evade the law, but they can reduce data footprint in certain contexts.
Meanwhile, Mullvad has no idea who bought that scratchable one-time payment coupon, and we have pretty decent faith in them not logging metadata about your tracking for later study. The Mullvad server I am connecting to is claimed to be operating 100% without persistent storage.
But does one need a reason to exercise their right to privacy?
I was merely trying to point out that not everyone has a "reason" other than the fact they want to be private.
Also region lock on legit services.
Torrenting, even here in Sweden had media companies look up IPs in torrent swarms, go to court to get ISP logs = send lawyer letter.
- I want to pirate content, which I do infrequently but like to do safely when I do it - I need to access a region-locked system
Otherwise, I just use iCloud Private Relay in Safari since that blocks IP addresses and prevents against my ISP while not causing as many problems for accessing websites.
https://twitter.com/privacylawyer/status/1117884896553263104...
Here in Canada, the usual copyright notices that came with a "pay this amount to settle" through your ISP were rightfully deemed to be almost extortionate scare tactics, and thus illegal. So copyright holders quickly moved to just outright suing people, directly through courts. So VPNs are essential, since you can be much more exposed to legal issues now than when "settlement notices" were the worst case scenario.
You can also review audits from a different vendor, Cure53, that were done in 2018[1] and 2020.[2]
[1]https://cure53.de/pentest-report_mullvad_v2.pdf [2]https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leak...
Isn't this complete overkill? I suppose this effectively mandates the use of a password manager, but I wonder where the 48 number came from.
hunter222222222222222222222222222222222222222222
Also, since we are talking about hash functions, keys don't even enter the discussion. Hashing is about making password guessing difficult. The length alone doesn't determine how difficult it is anyway, since there are 48 character passwords in popular wordlists. Just enforce 2fa, use argon2 or similar with a minimum password length of 12 and call it a day.
Those are two areas where I have serious privacy concerns and am seeking a zero trust solution.
So I guess that's just a security/privacy concern, but the key point is that you should be secure/private before you think you need it.
In addition, your traffic will be the only thing coming from that VPS, so tying network information to you will be easier.
The key thing to remember about VPNs is that you are re-positioning your trust. Instead of trusting your ISP with your traffic, you are trusting the VPN provider. A hosting provider is about as trustworthy with your traffic as an ISP, and offers the same amount of pseudo-anonymity. It's a lateral move at best.