4 ms·
What is the threat model where correlating the payment with the account number is the main threat? If you can relate the account number to Mullvad traffic, then
by A_No_Name_Mouse 4y ago
What is the threat model where correlating the payment with the account number is the main threat? If you can relate the account number to Mullvad traffic, then isn't it far easier to monitor the traffic and see what IP is connecting through it (my local ISP IP)? And if you cannot, what harm is there in knowing someone uses Mullvad? I pay by bank card and I don't see the risk here.
- dahfizz 4y agoI think the threat model is a three letter agency demanding a list of customers from Mullvad. Mullvad does their best to make sure no such list exists, but by having credit card info they are forced to know your identity.
- A_No_Name_Mouse 4y agoI assume that all national security agencies monitor all traffic and can already see I only connect to Mullvad. And I'm sure they will have noticed I use it when going through the logs of several SaaS services and see that it is always a Mullvad IP that uses my account. No secret IMHO
- gzer0 4y agoOften times, some take the extra step of utilizing services such as rdp.sh or any other "instantly" deployable VM in the cloud (these are services that take monero/cryptos btw), sort of like a bastion host. Once connected to that instance, they would then deploy their mullvad that was bought via amazon to add yet another layer of obfuscation. Home ISP ---> (optional VPN to connect to rdp.sh deployed VM in the cloud) ----> Mullvad VPN on the bastion host This is of course, not viable for the long term and very cumbersome to deal with if you're doing this on the daily. Unless you are under threat of a nation-state threat actor... you'll be fine.
- anonporridge 4y agoIf you're already doing this and buying an instance with monero, you're just buying Mullvad service with monero as well for the 10% discount they offer for it.
- Ajedi32 4y agoDoesn't that just make rdp.sh a single point of failure? It has access to both your real IP and the contents of your private communications (it even terminates the TLS connection on your side). Theoretically, chaining 2-3 VPNs together Tor-style would be far better (assuming they all support similar payment methods as Mulivad), but I don't know of any VPN clients that support that.