this post was submitted on 20 Sep 2023
4 points (100.0% liked)

Privacy

31253 readers
767 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 4 years ago
MODERATORS
 

Today we announce that we have completely removed all traces of disks being used by our VPN infrastructure!

top 25 comments
sorted by: hot top controversial new old
[–] [email protected] 0 points 1 year ago (1 children)

Doesnt Matter, if the police wants the data, they come with Auto Batteries and an usp and make User of the multiple Power supplies of modern servers.

They will carry the whole rack in one piece if they can.

[–] [email protected] 0 points 1 year ago

And if they don't have anything recent in persistent RAM storage..?

[–] [email protected] 0 points 1 year ago (1 children)

Why is their logo a Mole when Mullvad is The Goat

[–] [email protected] 0 points 1 year ago

In case someone actually ponders this, Mullvad means mole in Swedish.

[–] [email protected] 0 points 1 year ago (1 children)

I find the "Mullvad VPN scratch cards" interesting. If a store near you has them you could buy one and be totally anonymous. What I find a bit odd is that you can buy them on amazon as well but sold directly by mullvad. Doesn't that defeat the purpose? The idea of the card is a decoupling of your real identity from the vpn user but when you buy the card in their store doesn't it negate that?

I am probably just missing something here. Does anyone have more insight?

[–] [email protected] 0 points 1 year ago (1 children)

The code on the card is covered so Amazon might know you use Mullvad but they have no way of knowing what your account is.

Mullvad know your acct but they have no way of knowing how it is you paid other than maybe it being a scratchcard which they don't track anyway.

[–] [email protected] 0 points 1 year ago (1 children)

I am not talking about amazon knowing it. Amazon offers shops for businesses, where a business directly sells goods to their customers using amazon as a transaction platform. Those shops send the goods directly to their customers (Sometimes it comes from an amazon warehouse as well tho). If the first case is true, mullvad would send me the card directly, so they would know I bought it, which makes the card obsolete in my view.

But maybe they don't send it themself and the cards are all just sitting in a big warehouse. Either way, to me it's not 100% a given that they couldn't at least in theory know who bought it.

I am just playing devils advocate here btw, I am not really concerned about it.

[–] [email protected] 0 points 1 year ago

You are buying access to a VPN not a nuclear warhead for the black market. The link between buying a VPN card and the code used in that card to link to said vpn activity which is also pretty well protected on Mullvad is not easily discoverable. Seems like a pretty reasonable privacy gap to me.

[–] [email protected] 0 points 1 year ago (1 children)

Of only they'd kept port forwarding.

[–] [email protected] 0 points 1 year ago

Didn't really have a choice:

...Regrettably individuals have frequently used this feature to host undesirable content and malicious services from ports that are forwarded from our VPN servers. This has led to law enforcement contacting us, our IPs getting blacklisted, and hosting providers cancelling us.

Blog post

Big issue there is hosting providers cancelling them. Can't operate a business without that.

[–] [email protected] 0 points 1 year ago (2 children)

Interesting what’s going happening with mullvad. For the best part of 10’years, you hear nothing.

Does anyone know why they are recently noisy?

[–] [email protected] 0 points 1 year ago

You are incorrect. Look through their blog archive (scroll to the bottom): https://mullvad.net/en/blog/

They've been posting steadily for over a decade, maybe the posts just got more popular this year on whatever sites you browse

[–] [email protected] 0 points 1 year ago

Going by rate of blog posts by year they don't seem any noisier than usual. The opposite if anything. 18 this year and there's only 3 and a bit months left of the year whereas in 2018 they made 60.

[–] [email protected] 0 points 1 year ago (1 children)

Wow, that is very impressive. I've been a subscriber for a few years and I couldn't be happier with their service.

[–] [email protected] 0 points 1 year ago (1 children)

Except with the removal of port forwarding

[–] [email protected] 0 points 1 year ago* (last edited 1 year ago) (1 children)

I've been a subscriber for 5+ years and have zero issue with the loss of port forwarding. I use my devices for everything from gaming to torrenting, and haven't run into something cause a problem that required me to use port forwarding on mullvad.

what has been an incredible source of frustration as a user of Mullvad tho is when websites block me or hit me with repeating captchas. I've also had a huge uptick of spam coming in from weird domains. Obviously not sure if thats mullvad-related, but sounds like the issue of "individuals have frequently used this feature to host undesirable content and malicious services from ports that are forwarded from our VPN servers".

The removal of this feature seems to be a better of two difficult options.

[–] [email protected] 0 points 1 year ago (1 children)

Torrenting works better and faster with port forwarding.

[–] [email protected] -1 points 1 year ago

dogs need about one ounce of water per pound of body weight per day

[–] [email protected] 2 points 1 year ago (1 children)

It's a good day to be a Mullvad user. Switched over from Surfshark a while ago, and I love it.

[–] [email protected] 0 points 1 year ago (2 children)

Is it noticeably faster than Surfshark for you?

[–] [email protected] 1 points 1 year ago

You don't use Mullvad for their performance, you use them for their insanely paranoid security and privacy practices.

And for the record, I was never impressed with Surfshark speeds. I dropped them when they bundled a virus scanner into their VPN client, that's sketchy as hell. I don't want my VPN provider scanning my files.

[–] [email protected] 0 points 1 year ago (1 children)

I haven't noticed a difference but this company is significantly more trust worthy IMO

[–] [email protected] 2 points 1 year ago (1 children)

Funny thing is I started using Surfshark just before they started all the YouTube sponsorships. Them doing so many sponsorships actually made me trust them less somehow, if that makes sense.

Mullvad "appears" to be more trustworthy but maybe they are just better at marketing that image. They still cost twice as much as Surfshark.

[–] [email protected] 0 points 1 year ago

The best piece of marketing Mullvad ever got was when the Swedish police raided them and Mullvad literally had zero data to turn over to them.

[–] [email protected] 3 points 1 year ago

Full article:

We have successfully completed our migration to RAM-only VPN infrastructure

20 September 2023 NEWS SYSTEM TRANSPARENCY

Today we announce that we have completely removed all traces of disks being used by our VPN infrastructure!

In early 2022 we announced the beginning of our migration to using diskless infrastructure with our bootloader known as “stboot”. Completing the transition to diskless infrastructure

Our VPN infrastructure has since been audited with this configuration twice (2023, 2022), and all future audits of our VPN servers will focus solely on RAM-only deployments.

All of our VPN servers continue to use our custom and extensively slimmed down Linux kernel, where we follow the mainline branch of kernel development. This has allowed us to pull in the latest version so that we can stay up to date with new features and performance improvements, as well as tune and completely remove unnecessary bloat in the kernel.

The result is that the operating system that we boot, prior to being deployed weighs in at just over 200MB. When servers are rebooted or provisioned for the first time, we can be safe in the knowledge that we get a freshly built kernel, no traces of any log files, and a fully patched OS.