> Can I really pay with cash? > You bet, and please! Stay anonymous all the way. Just put your cash and payment token (randomly generated on our website) in an envelope and send it to us. We accept the following currencies: EUR, USD, GBP, SEK, DKK, NOK, CHF, CAD, AUD, NZD.
So, yes, there is a theory that someone may go in the trash in Sweden, finds the envelope, the stamp (and it has to be a british one), investigate who bought the stamp, get the assistance of the shopkeeper in UK (without raising suspicions), successfully reviews tons of security cameras footage to find who bought, etc.
And still don't know which activity to link it to.
A perfect waste of public resources if the NSA really does that, when all they needed to do is to purchase a VPN provider or fund Tor and claim to be no-logs VPN ;)
Better yet, they shred it: https://mullvad.net/en/help/no-logging-data-policy/#payments.
Presumably the theory is more like [1] - that the postal service, when they scan the envelope to read the address, save the scanned image and give it to the cops.
I agree that the NSA would be better off just running their own VPN services - or indeed intercepting everything on major backbones and just seeing what source IPs connect to Mullvad's servers.
[1] https://arstechnica.com/tech-policy/2013/07/us-postal-servic...
Storage is cheap - really cheap. I bet automatically capturing images of all mail during sorting and archiving that for years is not only viable, but a vital investigation/intelligence tool. One would ask Mullvad for the cash payment dates[1], and cross-reference with all mail sent to a Mullvad postal address. One city-level datapoint on where user was, cross-checked with the latest IP address, where stamps were bought[2], and you've massively trimmed the list of suspects, especially if they are behind a NAT and sharing the IP.
1. They have to keep track of payment dates, which is a side channel.
2. Where and when stamps were bought. I'm certain GCHQ can keep track of individual stamp IDs, the batches they belonged to, when they were procured by the retailer and have a reasonable guess when that specific stamp was bought by mail-sender.
You can get scans of all your mail through the informed delivery program.
"Put the money in an envelope together with the payment token and send it to us. We will open the envelope, add time to the account (corresponding to the amount of cash sent), and then use a shredder to destroy the envelope and its non-money contents."
Source: https://mullvad.net/en/help/no-logging-data-policy/#payments
The UK will know with certainty that a specific stamp was used to send a specific envelope to Mullvad. (e.g., America has been logging images of every envelope that passes through its postal service for over two decades).
It would also be trivial for the UK to know:
- When and where that stamp was initially sold (and to whom, if buying online!)
- When and where an envelope bearing that stamp entered the postal system
- When and where envelopes with other stamps from the same booklet entered the postal system
Add up enough bits and you can pierce anonymity.
This is a misconception caused by the scale of surveillance today. In the old days you were right. To do this kind of tracing they'd have to assign someone to do it which takes human resources and is not infinitely scalable. So they'd only do it to people deemed interesting enough, so average Joe was safe.
Today the scope has changed completely. Everything can be correlated all the time, so it is. No suspicion or probable cause needed.
If they don't do that, if they meet the stamp along the letter's journey, they can scan the code and check which batch it's from, and there could be a database of which post office got which batch, and then it's a matter of checking that post office's purchases/security cameras.
If all stamps are indistinguishable from each other, then you could've bought the stamp months ago on the Isle of Skye and used it in London, they wouldn't be able to tell the difference.
Perfect anonymity is probably impossible because information theory is impossible to escape. Which means you are trying to determine how far along the spectrum you can reasonably get for your particular risk profile.
Comments that pretend like perfect anonymity is the goal or act like it's binary are singularly unhelpful.
You can pay a Lightning invoice to get a voucher which is redeemable on the website. You get an extra layer of privacy, and also don't need to wait for an on chain transaction.
On the other hand, if you don't trust Mullvad's assertion that they delete the link between accounts and credit card payment records after 40 days [1], what makes you think you can trust them to not keep a record of individual scratch cards sold on Amazon, which Amazon can then correlate to an order ID and by extension account and shipping address?
At a higher level, if somebody can convince Mullvad to collude in that manner, they can likely also just ask them to outright hand over your traffic flows and connection data.
By the end of the day I agree, if you have any "real" reason for using VPN you pretty much have to implicitly trust your provider to not keep any traffic flows and connections that could correlate traffic to your IP, but not even sending money in envelope saves your from that.
If your worried about anything in a 40 day window the credit card <-> account_id is a liability
Amazon doesn’t know the redemption code on the gift card. So Amazon knows that you purchased a Mullvad gift card, but can’t associate the transaction with a Mullvad account. Likewise Mullvad knows service was paid for with a gift card (possibly that the gift card is from a lot sold on Amazon). But they do not know which Amazon transaction the card is associated with.
Unless your behavior and the behavior of others deanonymizes the Amazon purchase <-> redemption your account should be indistinguishable from any other that purchased a Mullvad gift card from Amazon in that window of time.