13 ms·
WireGuard multihop available in the Mullvad app
- mft_ 4y agoTangential, but I recently discovered Mullvad. For years, I've used whichever mainstream VPN provider had a good deal on come renewal time, and cycled through a few of the usual suspects. Recently, I was with Surfshark, and was really struggling to get download rates above a few hundred K/sec - and sometimes even worse. I didn't even suspect the VPN at first, but ultimately tried a different provider as a diagnostic step. I randomly came across a recommendation for Mullvad from reddit, and signed up for a month. Hot damn if my download rate didn't shoot up to 15-20 MB/sec (that's megabytes, not bits) - essentially close to maxxing out my fibre. Turns out you really do get what you pay for - and I doubt I'll be leaving Mullvad any time soon. (no affiliation - just a happy and surprised customer!)
- toomuchtodo 4y ago+1 for Mulvad, it Just Works and they are a great service provider. (also no affiliation, just a happy customer)
- throwanem 4y agoWhich exit point are you using? How close is it to you? I only get about 5MBps no matter which node I use and have suspected ISP throttling, but haven't tested too much since 5MBps is enough to get by with; this might make a good way to gather more info.
- mft_ 4y agoWith Surfshark, an assortment of (mostly) European locations - e.g. Germany, Netherlands, Czech Republic, Switzerland. When things were slow, the choice of exit location didn't seem to make much difference - tho' sometimes I needed to cycle through to find one that worked at all. With Mullvad, a similar choice of locations - again, it doesn't seem to matter, but in a good way.
- netfortius 4y agoHow are Mullvad apps across multiple platforms? I've been with PIA for quite a while, and I got it to work they way I want it, on macOS, windows and android, and I liked even more some of their recent exit points marked "for streaming", as I watch sports online, and there is a significant improvement when using those, with some countries local free broadcasting, but performance in the rest , sometimes, is really atrocious. I am just concerned about trading performance gain for tweaks/options/stability on multiple platforms (never found OpenVPN to be better, at least when it comes to PIA apps).
- mirceal 4y agoused it on macos, ios, linux. the app is solid. wireguard rules.
- seanw444 4y agoI use the app frequently on Android and Arch Linux, and it works equally well on both.
- mft_ 4y agoI use it on Mac, Windows, and iOS - they just work well.
- satyamkapoor 4y agoThe ios app reviews of PIA says it's now owned by a company which used to make malwares. I'm really happy with PIA as compared to Mullvad. Works better for me but this review is making me feel unsafe :( The PIA app is lovely. Mullvad's as well
- cycomanic 4y agoI used mullvad for streaming sports in Australia being in Europe at the time, no problem streaming in full HD. My machine is running linux although I doubt that makes a difference.
- sph 4y agoMullvad is fantastic. I get full bandwidth when torrenting 24/7 from my NAS, and I don't get blocked when I need to stream something unavailable in my country, and they have port forwarding support. They also have an Android TV client so I can watch on my couch. All for €5 a month? Such a great company.
- clsec 4y agoThat's strange. I've had the opposite experience. I was with Cyberghost and, after 3 yrs of good speeds, almost overnight it basically became so slow that it was unusable. I then tried out Surfshark and have been very happy with the speeds that I've gotten for the past year+.
- mft_ 4y agoI had been with Surfshark for nearly a year when everything slowed down. They could have been having temporary technical issues, of course, but it went on over a long enough period that my troubleshooting made it through multiple steps to trying a different VPN provider - so over a week, IIRC.
- neurostimulant 4y agoIn the end, it depends on how your ISP peers with your VPN provider's network. VPN companies tend to host their servers on networks with cheap bandwidth, which don't necessarily have great peering with many residential ISPs.
- throwanem 4y agoI use (and really like!) Mullvad, but have never tried the app, preferring to use my existing OpenVPN clients with the profiles Mullvad provides. This isn't because I have any reason to mistrust their app, but just because if I've already got a perfectly serviceable client on my device, why add another binary to do the same thing? But I would be interested to hear, from folks who have used the app, what you like and don't like about it. In particular, I've had some headaches setting up split tunneling/proxying via OpenVPN - I was never all that good at its config language - and I'm wondering if the Mullvad app might make those easier to achieve.
- _rend 4y agoI've found their apps to be (subjectively) higher quality than most OpenVPN clients on platforms I care about (macOS, iOS, Windows). It's nice to have a consistent UI, and not have to think or care about specific profiles — it's easy for me to jump between servers much more easily (I typically connect relatively locally, but occasionally find that certain out IP addresses have been blacklisted from specific sites; it's trivial to "refresh" the connection to hop over to a different server and not have to think about it). And, of course, easier (for me) to set up and configure. Maybe no _huge_ incentive to switch over to it if your setup works, but might be worth trying out if you're curious.
- seanw444 4y agoI'll +1 your anecdote with mine: that Mullvad's app is pretty great. It's very simple, isn't buggy, has just what's needed, and has a good UI. I'm pleased with it. Better than the others I've used.
- anakaine 4y agoI'll also +1 your anecdote that the Mullvad app is simple, convenient and stable.
- windexh8er 4y agoI would agree with a couple additional points. The first is that the app has a nice GUI that works across all platforms I'm interested in (mainly Linux) - but it also has a very handy CLI. I've also found that the client devs respond to issues. This is great as well as I feel as though I'm getting a complete solution with Mullvad. While I have no doubt Mullvad is great as a vanilla VPN without their client - I feel as though I'd be missing out on a few features and convenience items if I were forced to bring my own. And to be clear - while Multihop is new, it's not new as in today. It's been out for a while in beta (if I'm remembering right) and landed in GA about a month ago. I don't see much need for it in my use case, but it's nice they're continually enhancing the overall product.
- Exuma 4y agoAre we required to force it to use Wireguard instead of "Automatic" for this to work?
- johnwayne666 4y agoI’m wondering how this compares to Apple’s iCloud Private Relay. Mullvad is trying to increase their transparency and make sure users can trust them which is great. But would there be a way for them to make it so that users do not have to trust them? What if the second server was hosted by another entity?
- E4YomzYIN5YEBKe 4y agoI believe that with iCloud Private Relay, the second hop is a different company (Cloudflare/Akamai/Fastly). Whereas multihop offered by Mullvad and other VPN companies they own both hops which would make correlation easy for them.
- mikece 4y ago"I'm wondering how this compares to Apple’s iCloud Private Relay." Simple answer: Apple doesn't get your info. Mullvad is one of the non-logging VPN providers so unless you're compromised in some other way (like logging into Google, Facebook, etc) then running a make on your is far more difficult than just serving a warrant to Apple.
- matthews2 4y ago> Mullvad is one of the non-logging VPN providers How do you know that they're not logging? Or that their ISPs are not logging?
- clsec 4y agoHere's the latest Mullvad security audit (June 2020). https://cure53.de/pentest-report_mullvad_2020_v2.pdf https://cure53.de/pentest-report_mullvad_2020_v2.pdf
- odensc 4y agoUnless I'm mistaken that's just a security audit of their client applications, which would not in any way prove that they aren't logging.
- BrightOne 4y agoSeems similar to ProtonVPN's Secure Core, but using Wireguard directly. Nice.
- mirceal 4y agoI see you like wireguard, so i put a wireguard connection in your wireguard connection. jokes aside, huge fan of wireguard and mullvad
- dosshell 4y ago10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security. They spoke with passion about security fixes they made in the vpn client that no other had. They got many requests regularly from others that they should add there server as an endpoint - and they sad always no. All endpoints must be 100% secure by their knowledge. Never trust anyone. If they had to leave a laptop they used some old coffee paper trick so that one could not open the lid without visible marks. I was super impressed by them and have never met any like them. I guess they have grown out of their tiny office now, Mullvad.
- Rastonbury 4y agoWhat is the coffee paper trick?
- LanternLight83 4y agoIt must be attached such it tears when opened, tamper-evident- similar techniques are common fro doors, either across the frame or more stealthily near the hinge. You want it to be a little stealth because an informed adversary could break the seal, remove it, and be prepared to replace/recreate it when they're done (like faking a new wax seal)
- oceanplexian 4y ago
- saurik 4y agoThe UI we have is somewhat awkward, but this has also been supported for a while in our Orchid app (to the point where I have been actually working on another app designed to surface this one feature better, but that isn't out yet), supporting arbitrarily deep tunnels across multiple WireGuard (or OpenVPN, even going back/forth between them) providers (unlike this, which seems to just be "two hops, both from Mullvad").
- gzer0 4y agoTangentially related: Users can use Mullvad’s TOR address: http://o54hon2e2vj6c7m3aqqu6uyece65by3vgoxxhlqlsvkmacw6a7m7kiad.onion http://o54hon2e2vj6c7m3aqqu6uyece65by3vgoxxhlqlsvkmacw6a7m7k... to generate their account ID and make their payment with Bitcoin seamlessly. I have never experienced such a smooth way to purchase from a provider, this was brilliant. +1 to Mullvad
- vinay_ys 4y agoHow does it matter that your payment is anonymous when all your traffic is going through them?
- capableweb 4y agoIf mullvad gets compromised, you can still remain anonymous if the payment method is anonymous as long as the traffic you've sent to mullvad been anonymous as well. Obviously, if you log into your normal Facebook account, it isn't, but there are plenty of other uses.
- vinay_ys 4y agoIf mullvad is compromised, then all my traffic is also compromised and potentially my client machine is also compromised (since I'm running mullvad client). Alternately, to begin with, if my traffic wasn't sensitive or personally identifiable, then I don't actually need this multi-hop setup.
- capableweb 4y agoYes, if mullvad + your machine is compromised, then indeed there is not much you can do. But first, not everyone uses mullvads client, but instead the provided configuration files for wireguard/openvpn. Secondly, not all traffic is indeed personally identifiable, especially if you're using something like mullvad with for anonymous traffic to begin with. Imagine you have another account than vinay_ys that you only use via mullvad (and potentially other accounts). Using something like cash (or bitcoin for that matter) as a payment method makes it less likely the real person you will be connected to this other account. Security and privacy is not a true/false thing, it's a thing you do at layers. Making payments anonymously is obviously adding another layer. Maybe it's not worth it for you, but for some it is.
- Trias11 4y ago+2 Mullvad
- cpressland 4y agoThis thread seems to be full of people that use a VPN, I personally don’t as I find DoH + HTTPS to be enough. Why do so many of you use VPNs?
- trashburger 4y ago1) To simply make it harder for my ISP to see which websites I visit. 2) SNI sniffing makes some websites unavailable to me, so DoH isn't enough.
- cpressland 4y agoI’d never considered SNI sniffing. Great point. I’m quite fortunate in that the ISP I’m with (AAISP) is fairly privacy first and don’t _appear_ to be snooping on me in any meaningful way. That said, I can’t say the same for my phone provider.
- godelski 4y agoBut do you also trust your phone carrier? (I don't trust either my ISP nor my phone) Or when you're out on WiFi that isn't yours? It's a cheap way to add a little extra bit of security and privacy.
- judge2020 4y ago> don’t _appear_ to be snooping on me in any meaningful way. SNI is cleartext enough to be passively logged, so you never know. Maybe some government-mandated (or supplied) switch is logging them to some short-lived log file in case they ever need to pull your hostname history. Note that SNI sniffing protection is in the works by encrypting the client hello[0]. While it's been in draft for some years now, Chrome has a lot of work being put into it[1], so hopefully it'll be done sometime next year with support within Cloudflare and browsers soon after. 0: https://datatracker.ietf.org/doc/draft-ietf-tls-esni/?include_text=1 https://datatracker.ietf.org/doc/draft-ietf-tls-esni/?includ... 1: https://bugs.chromium.org/p/chromium/issues/detail?id=1091403#c20 https://bugs.chromium.org/p/chromium/issues/detail?id=109140... (comment 20 onwards)
- 4y ago
- ignoramous 4y agoThis isn't Tor-like multi-hop (but is similar to other multi-hop VPN providers out there). A proper multi-hop would happen across two different vendors in control of two different networks, as it were. The iCloud Relay paper outlined a pretty private and secure design [0] (and the intention to standardize it via IETF would probably make it simpler to self-host such a solution [1][2]). Among the VPNs, orchid.com's distributed VPN stands out as a cross-provider multi-hop solution whose privacy guarantees are closer to Tor's. Eventually the hope is HTTP (www) itself bakes in desirable privacy properties, so regular users don't have to pay the cost of multi-hops [3]. [0] Overview: https://datatracker.ietf.org/meeting/111/materials/slides-111-pearg-private-relay-00 https://datatracker.ietf.org/meeting/111/materials/slides-11... [1] https://ietf-wg-masque.github.io/ https://ietf-wg-masque.github.io/ [2] https://tfpauly.github.io/privacy-proxy/ https://tfpauly.github.io/privacy-proxy/ [3] https://datatracker.ietf.org/doc/draft-ietf-ohai-ohttp/ https://datatracker.ietf.org/doc/draft-ietf-ohai-ohttp/
- INTPenis 4y agoSplitting hairs no? I mean you're comparing multi-hop with onion routing. I'm just speaking as a layman end user. When I see multi-hop it's self-explanatory, it's literally in the name. Onion routing is another type of multi-hop with the onion routing algorithm.
- judge2020 4y agoSince it's the same company with access to both the first and second server, it wouldn't be too hard to log network on both ends and sync it up. With iCloud Private Relay, it'd be harder for a single actor to de-anonymize requests; you'd either need collusion between the companies or a government entity would need to ask both companies to log network traffic at once, and this would complicate the "exit node" server since it can't filter/only record traffic from the target customer's connection without company 1 setting up a single server dedicated to being the proxy for that customer.
- teawrecks 4y agoThe point of multihop, tor or otherwise, is for each node in the route to not know what the other knows. The first node sees packets coming from you, but not where they're going. The second see's where they're going but doesn't know where they're from (and vice versa). If the two nodes exchange this info (ex. if same person runs both nodes) then there's no point. Nothing is gained, you just incur the overhead of the extra hop.
- doubleorseven 4y ago"The entry WireGuard server will be able to see your source IP and which exit server the traffic is headed for, but it can’t see any of the traffic." So server2 terminates the request twice? One for server1 and another time for the client who generated the request? I don't understand how it's possible for server1 to not be exposed to the data.
- deleted 4y ago[deleted]
- justsomehnguy 4y agoYou probably missed > It’s a WireGuard tunnel being sent inside another WireGuard tunnel Edit: replaced with a better diagram (and again, now based on example in [0]): ▼ ▼ ▼ ▼ YOU->NL1 tunnel SE4->NL1 tunnel PLAIN/TLS YOU ────────────────────► SE4 ───────────────────► NL1 ───────────────► CATPICS.COM On the wire: YOU->SE4 traffic SE4->NL1 traffic NL1->CATPICS.COM traffic ┌────────────────┐ ┌────────────────┐ ┌──────┐ Inside: │YOU->NL1 traffic│ │YOU->NL1 traffic│ │ DATA │ └────────────────┘ └────────────────┘ └──────┘ [0] https://mullvad.net/en/help/wireguard-and-mullvad-vpn/ https://mullvad.net/en/help/wireguard-and-mullvad-vpn/
- topdancing 4y agoThis isn't how it works. If you actually pull down one of their multihop configurations - you'll see: - the WireGuard public key for server 2 - the IP address for server 1 - a unique port for server2 on server 1 So all they're doing is a standard iptables redirect to the second host (which may or may not itself be under a WireGuard tunnel).
- justsomehnguy 4y agoWell, I stand corrected, because I relied on their promo description. *shrug_emoji* I replaced the diagram in the previous comment, take a look.
- deleted 4y ago[deleted]
- kingkawn 4y agoNot available on their mobile app?
- _joel 4y agoTested this a bit when it was announced, works well albeit with an expected hit on latency and throughput. Absolutely love Mullvad.
- UberFly 4y agoLots of bumps here in support of Mullvad and it's warranted. OVPN is another that is top-rung as far as quality, no-logging, speed, etc. They even went to court to prove they didn't have any logs. Not affiliated, just a happy subscriber. Support Wireguard too.
- wiseguy317 4y agoBeen using Mullvad for years, this is pretty nice. I actually get great throughput with multi-hop on.
- daqhris 4y agoI'm a happy Mullvad user. But I have one concern. Recently, Instagram "tagged" my account as either based in Russia or using Russian currency. I'm based in Western EU and set up the VPN to connect to the same country or neighboring ones. I'm trying to figure out if some endpoints belonging to Mullvad have been shadowbanned by Meta/Instagram. Is there someone else who uses Mullvad to surf on Meta products whose account has been impacted by sanctions directed at Russia? My first guess is that it's a mislabelling problem or bots going rogue for an unkown reason. And, IG support is taking too long to clarify what's the culprit. So, I'm making all kind of hypotheses to reach a logical explanation before getting an official answer.
- Thorentis 4y agoI suspect that "Russian" will be the new pejorative that Big Tech is able to throw at anything they feel like banning. Want to ban a user for using a VPN because it's harder to track them? Accuse them of being "Russian linked" and bam, no further justification needed.
- TameAntelope 4y agoYou probably don't even need to lie, it's likely Russian hackers are using every major tor/VPN available commercially.
- tomxor 4y agoI've noticed the IPs on their relatively newer servers using "xTom" as a provider are being incorrectly identified as Russian by some IP based geolocation services... it's a bit hit or miss. I'm guessing xTom acquired an IP block from someone in Russia a while ago and IP geolation databases are just very slow to update.
- wraptile 4y agoI use Mullvad and I constantly run into things like ASN bans etc. For example, cloudflare often bans whole ASN making many websites not accessible through Mullvad. Seems like mullvad is being used by a lot of bad actors and they're not really doing anything about it. I like their software and monetization but their IPs are probably the lowest quality IPs in the VPN market.
- Sporktacular 4y agoHas anyone got multihop working using the standard Wireguard app? Can it be added in config files or is it by CLI only?
- panick21_ 4y agoHave been using them off and on for years. Met some people who work for them at some conferences. Company makes a great impression in general. My favorite thing they do is trying to make server infrastructure transparent: https://mullvad.net/en/blog/2022/1/12/diskless-infrastructure-beta-system-transparency-stboot/ https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur...
- illiac786 4y agoIVPN has wireguard multihop since a while I believe: https://www.ivpn.net/knowledgebase/general/what-is-a-multihop-vpn-service/ https://www.ivpn.net/knowledgebase/general/what-is-a-multiho... The iOS app has been more reliable than the mullvad app so far, which is the reason I switched. Additionally, it allows to configure "trusted" and "untrusted" networks, which is quite useful as well. (And yes, this is not a secure feature, as a network can easily be spoofed, but I use IVPN mostly for data privacy and not for safety/security reasons)