Mullvad on Tailscale: Privately browse the web
tailscale.com
tailscale.com
For history and how some people (John Gilmore[1]) thought uniquitous interoperable VPN tech (using the IETF standardized IPSec) be used to end-to-end secure internet traffic generally, see eg this FreeS/WAN rationale from the 90s: http://web.archive.org/web/20210125023625/https://www.freesw...
Then in between then and now were the VPN dark ages where it was mostly only used as a tech to accesss old timey corporate "internal networks".
Personally I used to run a domain parking service (back when I was a teen in the early 00s) that used the domains as web proxies and replaced all adsense blocks it could find in the content with my adsense code, and did a 50/50 split between my code and the domain owner's code. Google eventually became wise to this and banned that sort of thing but it was pretty cool while it lasted, and honestly I think it was super fair considering we didn't even add any ad blocks just re-used the existing ones already in the content.
VPNs are good at encrypting/redirecting all of your device's traffic, since they're per-computer by default. They're accordingly good at preventing metadata leaks (e.g. visited sites or used apps) on untrusted networks.
Proxies are opt-in, but can accordingly be much more fine-grained. For example, Firefox supports per-domain (via various extensions) or per-tab (via the built-in "containers" feature) proxies – VPNs usually can't do that.
These bridges/adapters do have their applications though – I have a home router that supports Wireguard natively, but not any of the higher-level protocols; this lets me use my per-tab approach with it.
It is trivial to run a socks proxy on one of the peers and have your browser point to that. Both chrome and firefox can do this on demand and for the sites you select.
SOCKS is also usually not encrypted.
> 3.13.7 Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).
> DISCUSSION
> Split tunneling might be desirable by remote users to communicate with local system resources such as printers or file servers. However, split tunneling allows unauthorized external connections, making the system more vulnerable to attack and to exfiltration of organizational information. This requirement is implemented in remote devices (e.g., notebook computers, smart phones, and tablets) through configuration settings to disable split tunneling in those devices, and by preventing configuration settings from being readily configurable by users. This requirement is implemented in the system by the detection of split tunneling (or of configuration settings that allow split tunneling) in the remote device, and by prohibiting the connection if the remote device is using split tunneling.
And yep, it does indeed cause all of the problems you describe.
That said, I'm aware of at least one that tries to support an "exempt/excluded hosts" feature, but it does this via some hack using its local DNS resolver and modifying the routing table on the fly, which does not work reliably.
https://support.mozilla.org/en-US/kb/protect-your-container-...
On my LAN I run Squid on a Raspberry Pi, and have my personal laptop configured to use that as a HTTP and HTTPS proxy.
All TLS HTTP connections going through the Squid proxy are intercepted.
This only requires that my laptop trusts a self-signed TLS certificate that Squid uses.
Someone could easily run the same kind of thing on the internet, providing free proxy service and telling their users to trust a certificate signed by them, without properly explaining the consequences of that. And a lot of novice users would likely use that proxy service. Gleefully unaware that even the “encrypted” traffic is completely visible to the proxy.
In fact, I would be extremely surprised if there aren’t a whole gazillion of services out there doing exactly that.
But in many jurisdictions running a service like that would likely be cybercrime. And even if it wasn’t illegal, it’s still not nice. So, you know, don’t go and actually create a service like that.
The word "only" is doing a lot of work there.
So I just put up with clicking through the TLS cert errors every now and then.
This blog (not mine) goes into how to do it: https://systemoverlord.com/2020/06/14/private-ca-with-x-509-...
With ubiquitous support, I hope that one day we'll be able to routinely get "subdomain CA certificates" issued by something like Letsencrypt, just like it's already possible to get wildcard certificates.
For example let’s say that I am hosting a website at somewhere.example.com
Today I would be able to get a Let’s Encrypt TLS cert for somewhere.example.com and if I control the DNS for somewhere.example.com I can get a wild card cert for *.somewhere.example.com
But from what parent is saying, with name constraints it would be possible for Let’s Encrypt to give me a cert that would allow me to act as CA for anything under my somewhere.example.com
Meaning that I could for example issue a TLS cert for treehouse.internal.somewhere.example.com using the restricted CA certificate that was given to me.
I think.
Even just using a VM for the CA would likely be sufficient. Only fire it up for signing, then keep its storage encrypted. I do this on my Proxmox server.
This, to me, is worth it for local stuff. The trusted self CA certs are better than blindly trusting an invalid cert, and some browsers require trusted certs to autofills passwords.
If you have local DNS, you can e.g. request a wildcard subdomain Letsencrypt certificate and then distribute the corresponding key and certificate to your LAN hosts.
Just because someone does not know how to do something does not mean it is difficult. It just means they did not try to learn how to do it. This is very common comment on HN. It's quite silly.
Learning how to set up a localhost proxy on a laptop is far easier than learning a programming language. But it is not something that many people on HN want to learn, cf., e.g., programming languages.
IMO not necessarily. See this part of what I said:
> telling their users to trust a certificate signed by them, without properly explaining the consequences of that. And a lot of novice users would likely use that proxy service. Gleefully unaware that even the “encrypted” traffic is completely visible to the proxy.
But in addition to that, note that where I was using the word “only” was specifically in the part of my comment where I was talking about how I set up Squid for myself using my own Raspberry Pi and my own personal computer.
Honestly, whats even more common and more silly are these kinds of comments:
"blah blah blah its easy, i did it blah blah i don't understand the problem"
Ever consider that other people are somehow different than you? Have different strengths, weaknesses and abilities? Have different needs from software? It's like, why do we even make software, you could just learn binary duh.
Somebody already did do this, except as a paid service, and had their special 'client' simulate user clicks to install the self-signed root CA cert in your OS' cert store for you.
I prefer using Firefox on my laptop so I didn’t check to see what the process is like for Chrome-based browsers to add trusted certificates (or if Chrome-based browsers only use OS-level certs).
But at least with Firefox, the user doesn’t have to go fiddling with OS level stuff.
That's why you go through seven proxies.
It was only later when they made 'consumer' vpns where they became point-to-multipoint affairs, for bridging a single computer onto the network. I'm not really sure how that confusion happened. In that era they were glorified SSH tunnels.
Technically, mullvad's VPN is also site to site, except the remote site is the internet.
I regularly used similar VPNs to connect entire segments of my home LAN to the internet.
The main difference is how you setup the client end because almost always, the other end is a network instead of a host.
Virtual means it doesn't correspond to a physical network interface. Private means it involves encryption, as opposed to a basic tunnel like ipip or 6in4. And they've always been network interfaces showing up on some node, regardless of whether that node might have been a vendor's proprietary black box.
Decades ago there were fewer uses/topologies, dedicated "routers" were more important, and people naively trusted infrastructure. Those are the differences that have evolved with time. Quick searches say OpenVPN was released in 2001, and tinc in 1998.
The common-sense meaning of "private network" was, and is, a network that is private. I had one with a bunch of my university friends - we ran our own network services that we wouldn't trust to the wider world, like we had back when we lived together and really did have our own private network.
A point-to-point line to the provider's router that then bridges you onto the public internet is a "private network" only in the most degenerate sense.
You can make an analogous argument about the traditional corporate site to site VPN, which is a point to point link between routers that bridges two non-virtual networks. By your standard, calling that a virtual network is only true in the degenerate sense.
I see your point about the possible meaning of "private", but I don't think that quibbling over the semantics is useful for much besides gatekeeping. There were plenty of corporate VPN links piping Internet-reachable IP addresses, just as there were plenty of VPN links with broken or nonexistent crypto.
Disagree. "The network", in the sense that my PC, and Bob's PC in the next town, and the server in our colo space, are all on "the network", is virtual, in a pretty essential sense. Even if 68 of the links in the network are physical wires and only 2 of them are virtual, their existence changes the character of the whole. In the same way that we have an "international network", that would be important to think of and treat as international, even though it only has one cross-border cable.
This feels like a bad idea, and perhaps it signals defeat in the enterprise space (where the tech would provide the most value, imo). Tailscale raised $100M last year, surely based on a theory of growth upmarket. While this partnership surely provides value to personal consumers, it feels, at best, a distraction from the larger opportunity and, at worst, counterproductive to achieving it.
I'm skeptical of the obvious counterpoint that this assists a flywheel of greater b2c satisfaction leading to b2b success...
a) the strategic signal it sends re developer resource allocation and b) the market signal it sends, selling a security solution while partnering with a company (not a knock - I've been a mullvad customer!) that provides solutions which are frequently used to bypass compliance/regulatory controls.
I think Tailscale going after 3 wildly different market segments (hobbyists, smb/teams, enterprises) [0] is why we're likely to see more such features, not less.
Partnering with similarly aligned organizations like Tailscale and Tor seems like a good way of increasing the userbase without engaging in sketchy business models like the rest of the VPN competition.
Okay. But it does? Our stats continue to show that making nerds happy (we're also nerds) leads to more corporate sales. (https://tailscale.com/blog/free-plan/ etc)
So if we can make something that we want ourselves and our friends and fellow nerds also like, and that also then leads to more corporate sales... why not?
Tailscale sold itself after that. The docs were excellent and it really is simple to use and run. I was able to do a full PoC in day and prove that I could join all of our environments and clouds into one VPN and have DNS resolving correctly everywhere.
Tried Tailscsle at home, took it to work and implemented it for our own needs.
Seems to me making nerds happy had a great conversion rate to paying customers.
We do?
I have a high opinion of them, one of the few VPN services I would trust not to give in even to governmental pressure. I firmly believe they would shut down their service before the compromised user privacy. That is very commendable
This is a pretty bad take. With your logic anything pro-privacy like Signal/Matrix etc would also be "x of choice for abuse/fraud/hacking etc" and thus shouldn't be used.
Mozilla is rebadged Mullvad. Proton might be ok. Everything else (Nord, Avast, Express, ...) is YouTube sponsor trash, Mullvad's the gold standard afaik.
Tailscale is clearly a superior product to it's competitors and I have regularly recommended colleagues and clients to evaluate whether it fits their needs. However, unfortunately, that is frequently not enough to "win" in the crowded and bureaucratic enterprise software space.
I would love to be proved wrong here and wish you the greatest success!
There are creative ways to get around that, but it makes implementation a complex story and heavy lift.
I’m pretty confident that you would draw an audit finding for that reason with a pure tailscale solution. (I also think that’s bullshit.)
That said my original statement was too broad. It’s not an “enterprise” issue, more use case dependent in regulated scenarios.
Too many ChatGPT interactions lately, I suspect.
If the cops or the MPAA come calling, we'll tell them to go to hell. Netflix blocks our servers? We'll set up new ones. Accused of torrenting? We didn't see anything, and we don't know who you are either. We're incorporated in a jurisdiction that makes us almost impossible to sue. We've got 4 employees, and not a single clothes iron between us.
B2B VPN products often have the opposite market positioning - straight-laced, trustworthy stuff. Absolutely not claiming to be difficult to sue. We've got 50+ employees, all of them wear shirts and some even wear ties. And suppliers like cloudflare are more than happy to help you MITM all your employees' https traffic, in the name of "security".
These just seem like positions in the market that are very hard to reconcile.
They're required to do the former (and Switter) by American laws, and for the latter: they banned the Daily Stormer, 8chan after a terrorist incident, and Kiwi Farms after their members called for open violence. It's not hard to see why these three got banned, inciting violence is not covered by "free speech".
This past summer I quit my job as Engr #3 of a startup. While there, I desperately tried to convince 1+2 that we should use tailscale instead of rolling our own VPN with wire guard and EC2. Couldn’t do it. The product was too magical and everyone was suspicious. I use it at home and tried very hard to make the case.
This feels more like a long term investment in breaking the “mesh” basis for their product. IMO it’s part of the magic and partially a problem. I couldn’t explain the security model for the mesh (as an outsider), and according to some comments it seems like it causes battery issues on mobile devices.
https://tailscale.dev/blog/battery-life
* 2% still affected according to https://tailscale.com/blog/reimagining-tailscale-for-ios/
Context: during government meetings in a particular region, their network policies would become more restrictive so that it’s only possible to connect to Chinese IPs. Chinese VPSs are exempt but cannot connect to Mullvad directly due to a Fortinet rule. Connections are done with a mix of Trojan-gfw, xray, and WireGuard
As it connects many devices in my network, a vulnerability in Tailscale will have a significant impact (they had recently a nearly 10 CVE). That’s not the case with the standard client server approach (clients can run user space Wireguard).
Even though I don’t open ports with Tailscale (more precisely, I outsource them to Tailscale), I still can’t sleep well at night!
Source: that's how I run it on Arch
Running Tailscale without privileges is a challenge because tailscaled needs to be able to configure your network, and if you enable Tailscale SSH it also needs to be able to create sessions for configured users. For people who dont need SSH and accept this challenge + maintenance burden, it is possible: https://tailscale.com/kb/1279/security-node-hardening/
I assume for DNS it also needs to modify resolv.conf as root when needed.
My primary concern though: will this lead to potential privacy leaks? Can a government agency shakedown Tailscale now to trace your Mullvad ID/connection to your Tailscale account?
tl;dr: As always, it depends on your threat model.
The question is: if a government agency goes to tailscale and says: "we're looking for Mullvad user 912830193276163872" - does tailscale log that, can they provide it, will they provide it?
I would assume that Headscale could also support this functionality in the future if you trusted Mullvad but not Tailscale.
That doesn't sound strictly true.
Mullvad and Tailscale need to settle their costs between each other, and Tailscale needs to settle with you.
What Tailscale needs to know about "your" Mullvad license is that x of y devices are using a Mullvad exit node, so they can charge you for y.
What Mullvad needs to know is a high water mark usage (data transfer, throughput, connections, whatever) for Tailscale (not you) so they can charge Tailscale some carrier grade rate.
There's little reason Tailscale couldn't do a iCloud Private Relay style Apple<->CloudFlare privacy preserving handoff.
they're not making a promise to not log that.
I think the West gains a lot more by having generally available VPN access in adversary states than it loses from their ability to purchase technical services that they still will have difficulty getting access to currency to pay for and they still will have difficulty actually shipping anything to NK.
Yes? Making it easier for North Korean citizens, or even just leadership, to communicate privately with each other and with people outside makes it easier for them to negotiate or even defect, and would help de-escalation efforts.
> What might the reasons be on the "no" side?
I guess one could argue that the North Korean government doesn't have access to secure VPN systems for government use (pretty implausible IMO) and that increasing their costs is inherently worth it? Realistically most of the opposition would come from those who benefit from the status quo (e.g. arms suppliers) and don't want to see that de-escalation, and I guess the extremely risk averse who would rather keep kicking the can indefinitely and hoping the blowup doesn't come until after they're dead, than risk actually trying to help North Korea's people.
(Or, at least, offer subsidies to their government if they stop supporting Russian and Chinese spies with their numbers stations et al.)
Mind you, I am not saying there is an existential possibility of a better policy, but the calculus would be nowhere as trivial as this.
I mean, certainly, but it's like having a club on your car's steering wheel: it's not about creating perfect protection, it's about ensuring your car isn't the softest target for theft in the parking lot.
If Cuba had fewer reasons to talk to Russia and China, then Russia and China would have fewer reasons to talk to Cuba in particular, vs. other Caribbean and Central American nations. Which would, potentially, spread their resources thinner and decrease covert-ops ROI, as they'd be having to engage with several nations who only weakly want them there, instead of one nation that desperately wants them there.
(And yes, I do realize that these powers do already engage with other nations in the area, e.g. Nicaragua. But not in the same way / not for the same reasons.)
Also, if you want to talk about countries that the US actually gives "special attention" to, I'd more compare/contrast to the relationship between the US and Panama.
Cuba would have do what those other ex-USSR satellites did and discard communism and authoritarianism in favor of democracy. Then, yes, seeing themselves as a sovereign state would be a good thing.
But I'm not sure if such an alignment could be created between the US and Cuba while Cuba remains a communist authoritarian hereditary dictatorship, since there's no shared enemy nearby and no strong shared economic incentive. Seems like the only real alignment would be Cuba becoming a democracy.
Cuba really doesn't have much of a choice, they have to trade with "friendly" nations of which America refuses to be.
Fun fact, when we (Canadians) go to Cuba they typically won't stamp our passports because they know it causes us issues when trying to enter the US.
I used to be involved in leading a US charitable nonprofit that, during the Obama years, once wanted to pay for someone to attend a technical conference in Cuba (or maybe it was to pay for a Cuban to attend a technical conference elsewhere - I forget). We did actually make it happen, but it involved consulting with lawyers, comparing the details of the situation against the applicable rules, and getting people to promise to stay within those rules.
My guess is that either Tailscale or one of the providers they depend on is cutting off Cubans as an attempt to comply with these Cuba-specific US legal obligations, or at least to reduce their risk of falling into non-compliance.
At the very least, GitHub has found ways to legally make most (not all) of their offerings available to Cubans / in Cuba despite the sanctions, except for more narrowly banned individuals and groups. So if you can obtain the open source code for Tailscale (client) and Headscale (server), you can at least use that to benefit from Tailscale’s software.
Even Google follow some of those: https://support.google.com/google-ads/answer/6163740?hl=en
Requires a lot more setup, but it is an option. I've been self-hosting headscale for some time and it is quite stable.
Right now, when I want to use Mullvad via my tailnet, I set the exit node to be a linux box at my house that is set to automatically send all traffic via Mullvad. That's free for me, since I already pay for Mullvad on that linux box at home.
fortunately it doesn't matter at all unless you've stacked up a lot of prepaid months at Mullvad.
Either way it would be good to at least have the option to use an existing account. Maybe tailscale is taking a cut since mullvad dropped recurring sub support natively.
no, why do you think that's the case? presumably the mullvad client does the exact same thing as the tailscale client will do - configure a wireguard tunnel.
edit: it will be interesting to see how much effort Tailscale put into preventing dns/route leaks vs the mullvad client
The root problem this all came from is that users can't really run two VPN clients at a time. It rarely works due to them fighting over the same resources in various OSes. So we need to either add Mullvad support to Tailscale's client or Tailscale support to Mullvad's client. The former is tons easier.
I pay for a year at a time for ease of use since they wouldn't save payment info when using port forwarding. And now since I last bought a years worth in May they turned off port forwarding and now make me drop the next 8 months of prepaid time if I'd want to use this feature (that I've been waiting for for years).
Also, geographical blocks on content such as Netflix and BBC etc
[1] https://tailscale.com/tailscale-ssh/ [2] https://tailscale.com/kb/1081/magicdns/
VPN to company is much more popular with businesses because of WFH and Covid.
consumer VPNs to random providers that advertise on podcasts are way up because of different countries having different video streaming service catalogs and because in the US consumer ISPs are increasingly privacy- and reliability-hostile. there's also a big marketing buzz because scaring people over these things was good for signups, so consumer VPN providers chose to advertise a lot.
Tailscale on the other hand is a way to re-create an actually flatly routable Internet, for myself, but with 2023 security levels.
1. Ease of use for non technical folks (my dad in the post)
2. The dangers of having an exposed ssh port (even on non standard ports)
I just don't have the time or compute to constantly tweak my security settings for a publicly exposed port, so the easiest way to solve the problem is to not have the port publicly exposed
---
It is not fully disabled, my dads account has a password for sftp.
Its covered more in part 1 (linked at the start of the blog post) but the repeated attempts at ssh'ing into my server actually killed sshd (which is how I found out about it).
The other problem is that this "server" is hosted on a residential connection in my computer room. This is just something I don't want to deal with and using a VPN fixes that since I do not need to deal with it, and its easy enough for my dad to use
Use a VPN for the same reason you close the stall door in a public restroom.
(I'm not necessarily agreeing with your premise that VPN usage has recently grown; I don't know that to be the case.)
Even if they'd log your IP and traffic (which they say they don't) they'd know way less about who you are then your ISP.
Half truths are spouted about "securing your connection" and "preventing tracking" are provided, without the supplementary information that device and browser fingerprinting do more to identify you as a user than geolocation does. With HTTPS, traffic is already encrypted, and any DNS-over-HTTPS or TLS provider will also mask where you were headed to, leaving much of the supposed benefits to be mostly snake oil.
If, however, you want to use it to access geofenced content, or you employ an obscurity-in-depth strategy to anonymize your identity, then sure, go ham. But as to why usage has exploded by the masses, a healthy dose of paranoia and influencer marketing.
If you downloaded a file over HTTPS, all they can see is the IP, domain name, and the amount of data transferred on a given connection.
People/organizations run bots that pretend to be interested in popular downloads so that they can collect these IPs.
99.999% of airport wifi users don't know that their traffic is bridged. So unless WIFI-6 introduced some network segmentation features that I'm not aware of, it's still a good idea for Grandma and Grandpa Jo.
The reason it's ubiquitous on YouTube is because they are gouging the hell out of consumers. Honestly it should be provided by your ISP as a bundled service. Although then it's just Comcast gouging you instead...
"Security" is not a legitimate application of geofencing, in my view.
Any attacker can trivially use a VPN to defeat it, yet legitimate users are massively inconvenienced by it. I've had too many accounts (bank and otherwise) locked for the crime of trying to access them while traveling internationally.
Here's a visual: https://mermaid.live/edit#pako:eNptUstugzAQ_BXL5_ADHHqBSjlUJ...
VPNs of the Tailscale type: Mostly people who self host apps and want them to be available across their devices without opening them up to the internet, or be able to access their NAS from Starbucks.
Here's how I think about customer segments:
* Those interested in online privacy
* Those interested in circumventing censorship
* Those interested in a secure network channel from their machine to "The Internet", by which I mean secure from their local ISP eavesdropping on them.
* Those interested in circumventing geographical restrictions.
Due to the nature of the Internet and how its most important protocol (IP) works, changing your IP address is a necessary, but not necessarily sufficient, step in protecting your privacy online. This fact says something about the long term relevance of VPNs, Tor, and similar technologies.
Source: I'm one of the co-founders of Mullvad VPN.
> ISPs learned how to be bad from security experts explaining how much mischief a person could get up to and deciding that sounded like a swell idea
Telecommunications companies have played a central role in government surveillance schemes for at least 50 years, well before the advent of WiFi. ECHELON was fairly extensively reported on in the late 90's.
> it might have seemed like you heard about ISPs and hackers around the same time
I connected to the Internet around 1993, but my interest in computer security didn't start until around 1996. I'm not sure if that qualifies.
From the surveillance standpoint, we now have devices we take with us and leave unattended. We are all waiting for a proverbial woodpecker to destroy civilization.
* circumvention of geoblocking
I don't want to "opt-out" and hope companies actually follow their policies, or assume their policies are sufficient when I "opt-out". So I ensure all of my network traffic is routed through my home no matter where I'm at or which device I'm using, and then from my home I ensure all my network traffic is routed through a business-grade connection that is offered under standard contract terms that preclude the type of fuckery that every ISP in America seems to think is acceptable to do to consumers.
That's why I use a VPN, and I'm pretty sure a lot of people who use a commercial VPN service do it for very similar reasons and don't have the technical know-how or wherewithal to set something like I have up for themselves.
They help to mitigate IP based tracking.
DOMAINS=(login controlplane log derp1-all derp2-all derp3-all derp4-all derp5-all derp6-all derp7-all derp8-all derp9-all derp10-all derp11-all derp12-all derp13-all derp14-all derp15-all derp16-all derp17-all derp18-all derp19-all derp20-all derp21-all derp22-all derp23-all derp24-all)
FWMARK=$(wg show $1 fwmark)
for d in ${DOMAINS[@]}; do
IPS=$(dig +answer -4 $d.tailscale.com +short)
for IP in ${IPS[@]}; do
iptables -I INPUT --in-interface tailscale0 -j MARK --set-mark $FWMARK
iptables -I OUTPUT --out-interface tailscale0 -j MARK --set-mark $FWMARK
iptables -I INPUT -d $IP/32 -j MARK --set-mark $FWMARK
iptables -I INPUT -s $IP/32 -j MARK --set-mark $FWMARK
iptables -I OUTPUT -d $IP/32 -j MARK --set-mark $FWMARK
done;
done;
iptables -I OUTPUT -d 100.100.100.100/32 -j MARK --set-mark $FWMARK
iptables -I OUTPUT -s 100.100.100.100/32 -j MARK --set-mark $FWMARK
iptables -I INPUT -d 100.100.100.100/32 -j MARK --set-mark $FWMARK
iptables -I INPUT -s 100.100.100.100/32 -j MARK --set-mark $FWMARK DOMAINS=(login controlplane log derp{1..24}-all) PostUp = /path/to/script.sh %iI'm still not sure if I like the login situation for Tailscale (allowing only 3rd party auth) but I understand why they do it.
EDIT: Turns out I can't use it yet since you have to buy Mullvad through Tailscale. I bought a year of Mullvad in May (they can't save payment info for port forwarding) and in the 4 months since they've removed port forwarding[2] and won't let me use my remaining credit for this integration.
[1] https://jackson.dev/post/replacing-tailscale-with-nixos/
As someone that already has a subscription to a VPN service (not mullvad), I’m wondering what this would get me for end devices, vs just using my vpn provider as I’m already doing
You can similarly bypass it without Tailscale, the same way you had to do it in Tailscale before this announcement, with everything egressing via a server which is the single Mullvad client. But it makes sense with the built-in solution (with probably better latency etc.) that they wouldn't want that.
In the end I was able to do a split-vpn config to allow VScode to bypass the VPN and leave the browser to use the VPN. Having tailscale just handle it would have been handy, and reading the docs today I found out that I could have just used a machine on my home network as the exitnode as well, which would have worked great too I expect.
Have to say though that this was the first time I had used tailscale "in anger" for any serious period of time away from my home network. It was superb and (apart from the VPN issue) just worked exactly as advertised and I was able to access all the stuff on my NATed home network as if I was in my home office. Brilliant product - thanks to all the tailscale folks ("tailers"?) on here for the product!
[0] https://www.ivacy.com/port-forwarding/
(They're based in Singapore)
2023 Paid VPN Relationship and Corporate VPN Ownership Map
openwrt surely will do the job on many aio or a old laptop.
Then anybody using your tailnet can use it as an exit node, and route all traffic via your home connection.
I hope they work on integrating the services both ways so I can bring my Mullvad account number over.
> (to tailscale Mar 16, 2022) Hey can you also make a Tailscale browser in the same vein as the Tor browser? Random thought.
They run servers with no hard drives: https://mullvad.net/en/blog/2022/8/1/expanding-diskless-infr...
The “compromise” is coming from inside the house. Might as well claim no one knows the admin passwords because they are written in a notebook that the management keeps in their home safe.
That said, I don't know if Mullvad is good or evil, but one of the ways you can evaluate companies is to recognize when they're making sketchy, not-relevant claims to create an air of legitimacy.
This "our servers have no disks" thing is kind of thing is marketing. It is meant to imply something that it doesn't actually demonstrate. Who cares if there are local disks? It doesn't change the threat model at all, it's mostly to convince people who don't know very much about claims which are basically impossible to prove. It's the higher-tier version of "we use military grade encryption."
Lawful Intercept on the public internet does not rely on local hard drives on any node in the network and has not since the 90s, as a specific example of how meaningless this is.
no they haven't built an impregnable system, neither has anyone else in the history of the world.
they have raised the bar very fucking high, though.
normal vpn company: oh yes, Officer, here's their credit card details and a list of all IPs they've ever connected from, and DNS logs from our internal servers
mullvad: OK, I guess you have the corrupted partial contents of memory of one machine that you managed to dump after dawn raiding us with guns and using liquid nitrogen to freeze the DRAM for a cold boot attack where you now have 90 minutes before entropy claims another victim.
one company tried a lot harder and made things a lot better. dumb equivalence arguments are dumb.
I think you need to familiarise yourself with the Mickens Security Model: https://www.schneier.com/blog/archives/2015/08/mickens_on_se...
making yourself resistant to casual subpoena attacks for little cost is valuable thing for a lot of people.
They were just unprepared. There was plenty of data to seize, but it was in RAM. They just needed the right equipment to do a cold boot attack [0] [1]
"The HotPlug's patented technology keeps power flowing to the computer while transferring the computer's power input from one A/C source (such as a wall outlet or power strip) to another (a portable UPS) and back again."
This is an excellent heuristic. Personally I like to evaluate trustworthiness in terms of integrity and competence - can I trust their values and can I trust that they know what they are doing? Words are cheap of course. Consistent action across several years is much harder to fake. It also overlaps with another heuristic I use to model and predict the behaviour of a company; a company's behaviour will converge on the shareholders' goals over time.
> This "our servers have no disks" thing is kind of thing is marketing.
You are correct that we considered that aspect while writing the blog post, but please read the content before passing judgement. See the section titled "To recap about “no disks in use”" in particular.
On the topic of "air of legitimacy" I'll just leave these here:
* Our apps have been open-source since we launched in 2009
* Our response to Shellshock: https://news.ycombinator.com/item?id=8385332
* Our thoughts on WireGuard in 2017: https://mullvad.net/en/blog/2017/9/27/wireguard-future/
* Experimental post-quantum KEM support in 2017: https://mullvad.net/en/blog/2017/12/8/introducing-post-quant...
The blog post you commented on also talks extensively about how it was one of our first steps in making our infrastructure transparent. Here are just two things we've done as part of that project:
* "This is the first time a modern off-the-shelf server platform gains coreboot support, and it is an integral part of realizing our vision of transparent and independently auditable VPN servers." - https://mullvad.net/en/blog/2019/8/7/open-source-firmware-fu...
And finally, we've spent 2-3 years designing a transparency log with distributed trust assumptions. One of many critical parts necessary to achieve our vision of transparent server infrastructure. I'll wager that there's no transparency log with a stronger threat model than ours. https://www.sigsum.org
We're certainly not without fault, but hopefully this helps inform your opinion of Mullvad.
Best regards, Fredrik Stromberg (co-founder of Mullvad VPN, Tillitis, Glasklar Teknik)
You cannot hide from advertisers if you use a smartphone with apps. App developers who put ads within their app control the apps behavior completely and hence they can fingerprint your device and track you very well without using IP addresses. And within browsers, they can fingerprint you through many javascript features of the browser. Hiding your source IP does very little for your privacy.
Almost all traffic (apps and websites) are encrypted via TLS (https, for example). So, even if you are on an insecure network, unless your OS's TLS certificate store is compromised, your communications are encrypted and protected against snooping from that insecure network.
Also, even on open wifi networks, today, it is very unlikely that the wifi is running without at least WPA2 encryption. Most modern airports run secure wifi. (But they also monitor all traffic metadata for illegal activities).
So, using a VPN as an exit node is just privacy theatre. VPN exit nodes in faraway countries are useful for bypassing content censorship in your own country, but it works only if the content streaming service cooperates with you.
Remember, all ISPs are heavily regulated by governments and can be asked to mirror specific customer's traffic for analysis. I would be very surprised if they don't proactively do it for all VPN operator nodes by default.
Maybe futile, but I'd still consider using it.
Plenty of people have and I would rather they have to spend a Tor 0day amount of cash to do it than to do it trivially.
> You cannot hide from advertisers if you use a smartphone with apps. App developers who put ads within their app control the apps behavior completely and hence they can fingerprint your device and track you very well without using IP addresses. And within browsers, they can fingerprint you through many javascript features of the browser. Hiding your source IP does very little for your privacy.
Sure, if you have sketchy apps, but Apple has both legal enforcement and approval of apps.
> So, using a VPN as an exit node is just privacy theatre. VPN exit nodes in faraway countries are useful for bypassing content censorship in your own country, but it works only if the content streaming service cooperates with you.
...? They can't trace where your requests came from....
> Can I really pay with cash?
> You bet, and please! Stay anonymous all the way. Just put your cash and payment token (randomly generated on our website) in an envelope and send it to us. We accept the following currencies: EUR, USD, GBP, SEK, DKK, NOK, CHF, CAD, AUD, NZD.
Given that Tailscale is a ridiculous company that advertises on privacy while force user to login via SSO by tech giants or OIDC which is shit in privacy, I will stick to my current origin Mullvad account and keep away from this service.
In addition, you can tell it to tell some or all of your devices to use another device as an exit node for traffic heading to the Internet.
Today they added the option to use Mullvad's VPN nodes to do that instead.
I'm a bit confused about the payment section though - I have to pay for Mullvad via Tailscale now? Can't I just use the peer keys I've registered in my own account?
Can anyone comment on whether it's possible to use something like NextDNS in conjunction with Tailscale and Mullvad?
Edit: to clarify, I'm aware of the existing NextDNS integration with Tailscale - I was wondering if this (or other third party DNS) works specifically with these new Mullvad exit nodes...
In the integration with Mullvad in particular, WireGuard connections are always direct from your device to the selected Mullvad exit node.
It doesn't make sense that this isn't available in countries where both Tailscale and Mullvad are available, like here in Norway.
why yes, the thing you turned on that explicitly says it will reroute your traffic elsewhere will reroute your traffic elsewhere.
Better move to Mumbai now to throw off the ipTrace.
https://github.com/juanfont/headscale/issues/1545
Headscale is a FOSS replacement for Tailscale's closed source coordination server. It is compatible with Tailscale's client apps, which are FOSS for Linux and Android, and partially closed source for macOS and Windows (https://tailscale.com/opensource/).
I signed up for the addon and got 15 free devices. Curious if others see this too...
From a strategy standpoint, I am not sure how this helps Tailscale at all. It changes how I view them and not in a good way.
Funny you should mention that as it's often a key reason to pick up a VPN for many users...
The privacy benefits are massively oversold, I agree with you there.
Mullvad has been at the forefront of not just VPN companies, but of any company, in their transparency, focus on their technology and pushing for further improvements in protecting data, raising the bar for trust and integrity and being more open.
Consumer VPNs are not a panacea (and Mullvad does not market themselves to be one). It is unfortunate that almost every single VPN company is actually snake oil, but Mullvad is a welcome counter-example.
I mean, if I just want to watch some geo-restricted show on a streaming service, it's a lot nicer of an experience just to use a VPN rather than having to torrent the show and run Plex or something else to provide a half-decent content browsing experience for your TV. Also, you don't have to worry about some copyright holder suing you (or more likely, extorting you) because you seeded 30s of video. Yeah, the VPN might sell your routing logs to some content company, but (1) that's unlikely and (2) is it even illegal to stream copyrighted content (pretty sure it's only illegal to provide it)?
Also out of curiosity, how adequate is Tor for bittorrenting? I would guess it constrains bandwidth pretty severely?
I've never done it, but it will have some problems: no UDP support (cannot connect to UDP trackers or use uTP with peers), no port forwarding (cannot connect to peers with closed ports), and some exit nodes might block outgoing activity towards the well-known ports (6881) though most peers don't use this port and instead use random ports.
this is incorrect.
nearly all the consumer VPN providers are indeed selling snake oil, and are only useful for obscuring your traffic from ISPs snooping. they keep logs, they have lax security, they sell aggregate whatever to data brokers, they don't give a shit about stopping leaks, etc.
Mullvad isn't, though, and spent loads of effort on ensuring even they can't usefully spy on their users.
> In addition, I think there are better tools for the job. If you want anonymity, use Tor. If you want to bypass geo-restricted content, use Bittorrent.
this is extremely dumb and unimaginative.
and at the end of the day if you think consumer vpns are stupid you can always just not use it. i don't think that them teaming up with mullvad implies anything bad or suspect about either of them. this type of a service is something that is really important and useful to a certain subset of users, and if they were going to wind up teaming up with a consumer vpn provider this is probably the least shady and most principled one they could have done it with.