Removing support for forwarded ports
mullvad.net
mullvad.net
(full disclosure this is my place of work)
Yes, I will trust you with my traffic and money /s
Tailscale Funnel does allow you to use any TLS-wrapped protocol (IE: one where the client does TLS and the server can optionally listen over plain TCP), but I'm not sure it would really meet the same goal as port forwarding in Mullvad does (for one you could use any non-TLS or UDP protocol with Mullvad port forwards, IE: Minecraft server hosting, Minecraft doesn't use TLS afaik). It's great for HTTPS though. I'm not sure how the bandwidth limits would add up over time for something more interactive like Minecraft.
Either way, Funnel does do some things well, but it's not a generic replacement for Mullvad port forwards.
After this was announced, I discussed using tailscale with my friends who use the server; some are technical enough to be able to install the client, others have devices that tailscale can't be installed on, so a tailscale subnet router would have to be set up for those devices. If it's what I have to do, I'll do it, but it's so much simpler just being able to have a publicly addressable IP with an open port.
Or I guess you're using the VPN to provide the encryption? If so, you could use SSL with let's encrypt.
Or is it access control? I guess maybe it's this one as i don't have a ready answer for you.
A while back however I just locked down all ports on my "server" (really just an old computer in my home) and instead setup a CloudFlare Tunnel[1] on it. All it really does is instead of CloudFlare forwardning HTTP requests to your server, your server connects to CloudFlare and uses that connection for bi-directional communication of HTTP request/responses. I have an nginx web server listening on a UNIX socket that the local cloudflared daemon will forward traffic to, but nginx is not needed and you could instead set up an individual tunnel for each domain/subdomain you have, but I personally just re-use the same tunnel for everything.
Works really well even though I'm behind NAT, the public IP changes, or network goes down briefly; the cloudflared daemon just reconnects. No DNS updates needs to propagate either. I can understand though if some people are reluctant to using CloudFlare, but for me this is a lovely feature they have - and it's free.
[1]: https://developers.cloudflare.com/cloudflare-one/connections...
I'd not even heard of ISPs doing that. That sounds really annoying!
You should probably rethink how you expose your service. If your service is a web service, maybe consider running it as a Tor hidden service, and pointing your non-Tor-using users to a Tor web gateway?
Maybe retiring port forwarding will help, but their IP ranges aren't going to be removed from every shitlist out there overnight.
Cloudflare gives me captchahell with infinite "click on fire hydrants or vans or bicycles or stoplights".
Amazon just pretends to "site error".
Numerous sites like Tiktok, JLwaters, my state's data portal, and others just give me a 403 forbidden.
Other sites just load a <html></html> blank document on my VPN.
And Proton is actually kind of hard to get port forwarding turned on. You can do it by adding a suffix to the OpenVPN name, or by generating a wireguard with port forwarding on.
But again, I don't think it's anything to do with port forwarding per se. The current web demands deanonymization. And naturally "abuse" is blamed, even when attached to legit accounts with legit historical purchases etc.
Regrettably, I suspect this does nothing for abusers, who are motivated, and instead impacts only "legitimate" customers.
Of course without the big fat asterisk of "actually, we have no idea what our false positive ratio is. So they could be 9000 prospective customers that we blocked."
And then the customer will think "oh wow good service, all those baddies blocked, better stay in the warm embrace of this service or who knows what will happen to my site".
https://rr.judge.sh/Screenshot%202023-05-30%20at%2011.19.52%...
I used to work at a smallish mom-and-pop website host (do those even exist anymore?) that also offered email services. Our PF firewall just straight-up blocked huge swaths of IPv4 CIDRs because it was 99% email spam and exploit scanners. We had no ability whatsoever to fight it any other way. I don't recall even a single complaint from any of our customers.
Well, there are two different reasons you might not have received any complaints...
I never successfully got an OpenVPN set up with proper port forwarding. It would appear to, and then just up and fail.
With Wireguard, I set the port automatically with UPnP (Soulseek and torrents). Have it set up there, and works like a champ.
You'll have to log in, go to Wireguard configs, set port forwarding and a P2P VPN, and download. Then do the usual with /etc/Wireguard and start it up. That's it.
Thank you! Looking into it now.
My impression is that the only way for an established, non-tiny VPN provider to have clean IPs is if they're buying residential proxys. My impression is that the only way to make the residential proxy business work at scale is either malware or unwanted misleading bundled crapware. I don't feel comfortable benefiting from a service that, at best, relies on tricking less tech savvy people into installing crapware.
I think even the more ethically dubious providers are shifting towards that model. Which makes sense since they have to pay anyways.
If you tell a police search team you have plausible deniability they will seize all your tech and investigate you. If you're actually guilty there's a decent chance there will be other incriminating evidence. If you're innocent this will be unpleasant, expensive, and they might end up finding what they think is evidence against you anyway
If the problem is hosting malicious websites, they may able to provide limited port forwarding. Browsers' restricted port can't be used by browser so it's a way to avoid web hosting I believe. A problem is that there are only 80 ports now (for Chromium). https://chromium.googlesource.com/chromium/src.git/+/refs/he...
If you're an active seeder, it makes sense to configure your machine so that it is accessible for all the peers, including ones behind NAT. If you're just a leecher though, it makes little difference.
Trackers don't enable hole-punching, existing peer connections do[0]. And hole-punching is hardly a reliable measure to base your network on, if NAT or connection-tracking is implemented in an address-/port-dependent manner[1] then hole-punching becomes more complicated or fails, especially for TCP.
[0] http://bittorrent.org/beps/bep_0055.html [1] https://www.rfc-editor.org/rfc/rfc4787.html#page-6
However, if you have a tracker in a sense of "community of people dedicated to file sharing", there will be guides on how to do a proper setup even behind carrier-grade NAT. For example, one of the trackers I know suggested using Teredo (IPv6-to-IPv4) tunneling to do the hole punching.
The companies offering those have experience dealing with copyright cartels.
Or you can just buy one. https://www.ebay.com/itm/143939358334 for example is $2 and is the private (semi public - all the benefits of private but easy to get). It's the one I use. Buying invites can lead to getting banned but if you're just chilling out on TL then you'll be fine.
A tip for private trackers. Only download new things and freeleech until you build up a buffer (You've uploaded more than you've downloaded)
Previously, when I was really into torrenting I climbed the ladder really well, I was in the forum sections where staff would share the details of banned users. They mostly cared about cheaters, unless it was a small site trying to be exclusive. I knew people who would go to tracker staff and out people for trading and selling and nothing would happen.
But overall if you want to get into the torrent community buying and trading isn't worth it. But if you just want a single solid torrent site and are willing to pay TL is the one to do it with.
IPT is solid from my memory so there won't be many that are better as a general torrent site. But for niche obivously there are tons.
But since you're already in a torrent community, Check out the IPT forums back in my day they had recruitment threads in the forums. Hang out on their chat and be friendly, don't ask for invites just be friendly after a while people will start offering invites especially if you say you aren't there yet.
Remember that user invites carry the risk that if someone in your invite tree breaks a golden rule (trading/selling invites) you will be banned too. Always prefer official recruitement.
There's currently a promotion running:
And zero chance of being picked up by copyright watchdogs who download the whole swarm's IP addresses and send legal notices to each one fishing for ISPs that will give their user's data without a warrant.
Most good private trackers have an invite system, you can't just join one on a whim and get access.
Their process is profitable enough just by scanning the well known ones so they don't need to bother with trying to get access to private trackers.
One site on that list, for example, TorrentLeech.org has been around for almost 18 years and has hundreds of thousands of active users. In fifteen years I’ve never had an issue.
There are also foreign language trackers that are largely immune like rutracker.org - you just have to make sure to download the English versions
so of course i didn't use it enough and was banned for inactivity
The risk and effort is probably not worth the reward, considering how many public tracker users are there.
What I'm imagining: someone who is mildly connected to execs at various studios/labels starting a company that participates in private trackers, and then passes information about infringement/infringers onto studios. They would only need one or two studios as clients to prove the concept and (informally) prove the idea to the rest of the industry. Their agreement with client studios includes an agreement that they won't be sued for infringement that occurs in the process of finding (other) infringers, doesn't include any license to works, and certainly doesn't include the ability to sublicense!
Sure it's possible that when this eventually goes to court, a chain of "activist" judges might go against the status quo of a company taking steps to protect its "property" - discard corporate veils, call the investigator's uploading an implicit sublicense, etc. It's just not likely, and the failure mode still would be individual licenses for the specific downloaders that were in the swarm at the time, not blanket rights to redistribute indefinitely.
For niche stuff you can even find the super hard to find. Want to find the tv version of episode 12 of season 3 of Flashpoint, there is a site where that is possible.
Some have communities which are super useful if you're into those. But if you just want to download and get good speeds, a general tracker like TorrentLeech is pretty much all you need.
One of the great losses from the shutdown of that site was the destruction of that creative community.
So then what, find public Wifi somewhere to do their "interview" from, that they'll pass for a non-shared IP address? And then hang around there all day until your turn for the interview comes up? That's the conclusion I came to last time I looked at Red's requirements years ago.
Also I just assume the interview processes have gotten much more competitive and inhuman due to the popularity, like everything these days. I got my Oink account by joining the IRC channel, and just asking nicely in a way that demonstrated a modicum of technical knowledge and reasonableness.
I'm not sure if they will allow public wifi either if it doesn't look like a residential IP. It's unfortunate... I too wish many trackers didn't do this. Totally worth it for me though. I'll just hope future me doesn't have to suffer the consequences :)
They can probably build quite a specific profile based on my searches and snatchlists, lol. There's no privacy in private trackers for the user.
The interview process is not bad, it's just particularly slow in the case of RED. Especially frustating for europeans because most volunteers are in an american timezone and so interviews often happen in the middle of the night (in Europe). OPS has faster interviews but you want to join RED if you want to climb the tracker ladder, so passing through OPS basically just adds some delay.
Anyway, if you value your anonymity this much, maybe private trackers aren't for you.
It really isn't that much of a problem. Hell even ratio cheats aren't actually a problem. If you have a ratio based torrent site fundamentally someone has to have negative ratio for the site to function. Ratio cheats basically add download to others because they download. I'm of the opinion a lot of tracker staff are just nerds who power trip. And honestly, from my experience it's largely true. Simply, torrent sites have gotten away with power tripping and creating this image that people who buy and trade torrent accounts are a problem when you can literally talk you way up the chain within 6-12 months. It's really not that hard if someone wanted to infriate them, just say you're willing to code for them and boom you got yourself a staff position with access to the database and servers. Do that well, you'll get yourself a few more, you'll get friendly with staff at other trackers they'll invite you. Literally, it would be the easiest uncover role within the cyber world. And there probably aren't that many that are easier overall.
> Anyway, if you value your anonymity this much, maybe private trackers aren't for you.
This is sure a valid point. Your data 100% is not save with private trackers. Nothing is safe with then. They act all high and mighty but holy shit will they share you data like no ones business and publically out you, steal money from the "server fund" (personally I never had a problem with it but it was always drama ScT's exit was funny), etc.
From the staff's POV it is very much a problem and some trackers are famous to drop the hammer at the slightest violation of the golden rules.
Actually, these users are generally deadbeat users. They're good at providing upload and buffering accounts but that is it. They don't make your community any better, they're spread out over multiple communities.
For example, back in the day I was on UK-T, SCC, ScT, FSC, FTN, BTN, HDBit, etc. I didn't really download much from any of them specifically. I created buffers and what not and kept my accounts alive. Like FTN I never used, for me it was actually not that good. But when I started out I just had LeechersLair, I was very active in the community, very active with comments, very active downloading and seeding because it was only account. So the good users for these sites are actually people who end up on my accidentally, aren't active in the generaly torrent scene and aren't looking for anything else. They'll make the forums better by being active there with unique content, they'll make the chat unique instead of conversations that carry on over from other chats (Been there done that), they'll file requests, etc. They'll be more active. The people who are all over the place are often deadbeats in terms of community value, if that makes sense.
> some trackers are famous to drop the hammer at the slightest violation of the golden rules.
So true, I once rejected from a so-called high level tracker FTWR (follow the white rabbit) because one guy was pissed I once said on a forum "Torrent trackers should be happy we use them." they're soo up themselves. Imagine thinking your users owe you something. The aim is to get users and get good users.
You do have a point, I guess it boils down to the definition of a 'good user'. Like you said, someone joining from an invite they bought is likely gonna be more active. From the staff's POV the activity of an account is of secondary importance though, and the respect of golden rules is paramount. Tree-bans often end up banning users with high userclasses and (very) active accounts.
From my POV as a normal user, I like the tracker being active but I don't like the web of trust being broken. An invite-only club is good because everyone was invited by a trusted member; if you can just buy your way in it's different.
Anyway, the TL;DR is that at the end of the day your personal interests change depending on what position you're in (staff, normal user, etc.) and while you as an user may not mind people buying invites because of passive benefits, the tracker staff has different priorities and definitely does mind.
I actually find it much better for ancient stuff because my provider has 10 years retention and the DMCA takedowns only started a few years ago.
otherwise many have open signups randomly throughout the year
the better ones are harder and often expect proof of previous seeding, like i've been in IPT for years with 7TB/2TB ratio but still not managed to find an invite to some of the more renowned ones.
you can even pay more if you really need plex
It's not exactly rocket surgery.
I don't live in the time zone as the TV shows I watch, so having a delay isn't really an issue. And even if I did, I wouldn't watch them immediately anyway, that's kinda the whole point.
You add the torrent to the seedbox torrent client and your (eg) home torrent client.
They are both become part of the swarm for that torrent, through the tracker or DHT, so eventually they would know about each other.
If your seedbox dowload the chunk then you home client can connect to the seedbox client and download that chunk, just as a regular participant of the swarm, no need to do anything.
Because the seedbox has a direct connectivity then if there is a seed without a direct connectivity - it can connect to your seedbox (again, discovered through DHT or tracker) and give out all the needed chunks.
A bit slower than having a direct connectivity at you home, but most of the time it doesn't matter.
Mostly because I haven't been able to find a seedbox service I trust as much as mullvad. It's impossible to tell which ones will flip to copyright authorities as soon as a little bit of pressure is applied.
Kape Tech , at the time, had a less than stellar reputation. I haven't followed it much since that time.
Details: https://news.ycombinator.com/item?id=35642700
These days, free and open source software clients are table stakes for a VPN to be considered trustworthy. The fact that PIA silently stopped releasing source code after previously promising to do so is a major red flag.
PIA official repo: https://github.com/pia-foss/manual-connections
https://helpdesk.privateinternetaccess.com/guides/linux/linu...
It's also risky because mullvad certainly has records of forwarded ports and can out you if they receive a properly worded subpoena. There is also a chance those records would be present in their backups even after you deleted the forwarded ports.
I have a separate command for port forwarded torrent client and only use it when absolutely necessary, which is almost never.
> This has led to law enforcement contacting us, our IPs getting blacklisted, and hosting providers cancelling us.
Dealing with annoyed law enforcement, hosting providers, and IP reputation is 99% of the value of a VPN. The other 1% is just setting up a VPN server to open proxy everything (which there are scripts on github that can do it in 2mins). Of course its not really preserving privacy much unless there are multiple users...
Any significantly shared connection will have at least one person abusing it and causing most of the problems, the logical conclusion would be to ban the few abusers but if mullvad truely doesn't log/retain billing data as they claim, permanent banning would be difficult as a new account could just be created.
I don't see why they couldn't do some kind of compromise like an account has to be of certain age/spend to use port forwarding. They do keep mappings of ports to account, so its not like they don't know which accounts are abusing. Getting banned would then be more expensive for the abusers.
In my personal experience investigating these scammers: people are happy to resell "used accounts of good age and reputation that they no longer need" on blackhat marketplaces — usually for about a dollar.
Here's one such marketplace: https://lzt.market/
(Hopefully linking to it like this will increase the probability of the right eyes seeing it and getting it taken down)
Let me rephrase that.
> Unfortunately port forwarding also allows people to get the value for the money they pay us, which in some cases can result in our service not functioning like a gym membership, where we aren't used for much but many users continue to pay for us (sadly many services block traffic coming from us which makes a lot of simpler uses of a VPN fail as well). We'll aggressively defend against chargebacks.
Edit: Ooh, they charge the same whether you sign up monthly or annually. Not too shabby.
According to wayback machine, they deleted the page sometime mid 2021. Here's an archived version of the page: https://web.archive.org/web/20210513051214/https://mullvad.n...
The most commonly used scenario for port forwarding would be torrenting, where users forward ports so that they can be “connectable” (i.e., accept incoming connections from the Internet).
Hopefully a competitor will start up and attract less attention for a while until we have to do it all over again.
> This has led to law enforcement contacting us, our IPs getting blacklisted, and hosting providers cancelling us.
Which mullvad specifically want to avoid doing - their whole jam is not having logs.
Could we just throw a STUN service in front of this, then?
Is it possible a lot of average torrenters are already not port forwarding?
This will degrade torrent performance and make torrenting worse, routers normally have uPnP enabled these days so we forget about it, but this will make it so you can’t connect to any other users who are also using Mullvad, for one.
[0]https://superuser.com/questions/1053414/how-does-port-forwar...
From what I understand, uPnP took off for a while, but started to become much less common about a decade ago because of the security issues it caused. I think most routers come with it disabled by default now. (If you know of any surveys indicating otherwise, I'd be curious to read them.)
Part of it is that hole punching became a standard feature for new protocols, so the need to forward ports has been reduced.
It's a very sudden move on the Mullvad part that impacts a lot of their customers. If the torrent speed drops down as much as I think it will I won't be very happy...
>If you wish to subscribe to the service, you can sign up for a PayPal subscription. With a subscription, €5 is automatically deducted from your PayPal account each month.
Otherwise they just talk about "using" or "paying". It has also been absolutely possible to a) add new port forwards if you have paid for Mullvad b) pay for Mullvad when you have port forwards, so those ToS wouldn't make sense if they referred to all Mullvad accounts.
I feel like people really need to think about who they’re trying to be private from before signing up for VPN’s.
with a VPS as your vpn, reddit/google/facebook/whatever all see you from a single ip, one that might change even less then your ISP's, all of your alternative accounts will all share this ip as well, and 0 other people use that ip address. basically data collection and alternative account identification becomes dead simple because your ip is basically your universal id.
you stand out as an individual, part of the "security" with things like mullvad is that you share that ip
security in depth of course, fingerprinting and stuff still exist, but if you have such a clearly unique ip address you have 0 chance
Also your local network, like you need to use your phone's WiFi because you don't get a good cell signal at work, but you don't want your employer seeing your personal phone activity. Same as public coffeeshops.
Do you understand the privacy argument now?
I'm just saying there are workarounds that mean we don't have to be beholden to the Mullvads of the world if they drop this feature. I think we're basically one good blog post away from a situation where most people who need port forwarding can set it up themselves via ec2. If they prefer VPNs, and can find some that do port forwarding, more power to them.
Not trolling, genuinely curious.
VPN bypasses that entirely, despite my traffic traveling to another continent on the other hemisphere.
- You can get cheaper rates on some travel expenses, such as car rentals, by changing your IP to one in a different geo.
Questionable? Maybe; but I don't really feel personally beholden to copyright/trademark law that isn't preventing a loss anywhere -- in many cases when I watch these trailers I make purchases based upon them, so if anything the corporations that region-lock their YouTube videos away from other markets are doing more damage than I -- the extra diligent customer.
If you need an absolutely vanilla answer : I VPN into a network node that can access other nodes that only host their services to the local network. That's also a big advantage, and as far as I know it doesn't step on any legal toes.
Also, hosting stuff at my house. Multiple times had ISPs that appeared to be degrading incoming connections where once again popping everything into a VPN tunnel fixed any problems. (for example when I set up a streaming website from my house with a webcam of our kittens to watch from work. Stream kept getting interrupted randomly until I routed it through a VPN)
I tend to use VPS based solutions rather than commercial VPN providers, but I've done both.
TL;DR: ISPs are shifty and untrustworthy.
I paid for a monthly subscription to the Canadian streaming provider (TSN), since I live in Canada.
For whatever reason, there was no international streaming provider. (It has been on ESPN in previous years.)
The ads on the TSN stream were horrific. They put a full 25% of the active play of every game (the first thrower in every end) in a muted PIP box so they could play more full-screen ads.
TSN decided to offer a stream of the playoff games to non-Canadian viewers who had no way of watching, and since pay-for TSN is geoblocked to Canada, they made that stream free, and geoblocked it to not play in Canada.
The international stream was also free of commercial breaks. Instead of commercials it just showed miscellaneous cameras between ends, and showed the entire ends without putting a quarter of them in a PIP box.
So obviously, my experience was much better by streaming the international stream rather than the local stream that I paid for.
[1] https://en.wikipedia.org/wiki/Scotties_Tournament_of_Hearts
That said, I never actually got incoming connections over UDP working properly anyway through these ports, even though they were supposed to be supported.
But I can understand the reasoning yeah.
Reddit has a big comparison table if you're curious: https://old.reddit.com/r/VPN/comments/m736zt/vpn_comparison_...
"gofwd" is a cross-platform TCP port forwarder with Duo 2FA and Geographic IP integration. Its use case is to help protect services when using a VPN is not possible. Before a connection is forwarded, the remote IP address is geographically checked against city, region (state), and/or country. Distance (in miles) can also be used. If this condition is satisfied, a Duo 2FA request can then be sent to a mobile device. The connection is only forwarded after Duo has verified the user.
I'll be applying for a refund.
The problem is inbound connections. If both peers are behind NAT they can't connect.
Which is not a lot because in most countries exposing your IP on the torrent leads to legal threats.
For this reason, your selection of peers will be limited. As all other peers behind NAT without port forward will be disregarded.
If you do have a port forward, other peers can connect to you, thus having all peers available.
And I run services through it that I want access to from outside my subnet.
This is more comparable to a taxi company which makes driver take a pill to forget all details on arrival. That would be harder to defend, after the first incident of "why was this car in my driveway last night? - we couldn't tell you!"
In other news despite VPNs people who commit crimes are prosecuted all the time via ordinary police work per normal. In fact despite sophisticated tech criminals on average leave behind more breadcrumbs than they ever did in prior eras.