3 ms·
Couldn't you give them short-lasting keys, that they can use to sign session keys? e.g. 1. Connect to Mullvad over Tor, authenticate with real-world user ID
by heartbeats 4y ago
Couldn't you give them short-lasting keys, that they can use to sign session keys?
e.g.
1. Connect to Mullvad over Tor, authenticate with real-world user ID
2. Use this to sign a blinded token
3. Use this to connect to Mullvad anonymously after some delay
The first run would be kind of dodgy, but after that you could get new session keys on a fixed schedule and switch them out at a random interval.
If they see that user A authenticates and 10 minutes later, key A comes online, that can be traced, but if you then wait a week, authorize key B, and then wait a few more days to start using it, you should be good.
In practice, this has way too many issues to work in practice. It still requires you to trust them not to e.g. log IPs and correlate it that way, so it's all just snake oil.
- jaywalk 4y agoIt seems like you're trying to solve a totally different problem that doesn't exist. If you have a subscription, that means Mullvad must store information that ties your account to the subscription payment processor. That is the information they don't want to store anymore, because they want their users to be anonymous. Their system is already setup so that users can't be correlated with VPN activity.