6 ms·
mullvad has time and again shown itself to be one of if not the best actors in the entire vpn space, but you still have no real way of knowing if they are being
by coconut08 3y ago
mullvad has time and again shown itself to be one of if not the best actors in the entire vpn space, but you still have no real way of knowing if they are being honest.
also their business definitely doesn't depend on being honest or standing for their values. there are plenty of vpn's who run on fake marketing that give the impression that they have certain values and do certain things while actually not doing it and they are way more successful than mullvad.
- qzx_pierri 3y ago> there are plenty of vpn's who run on fake marketing that give the impression that they have certain values and do certain things while actually not doing it and they are way more successful than mullvad. Yes, but Mullvad also doesn’t whore themselves out to any YouTuber that will accept a sponsorship agreement. I’ve never seen an ad for them. I’ve only heard of them from people who tell me they’re the best. Of course we shouldn’t trust them 100%. Trust isn’t required them competent OpSec is implemented within a workflow. Trust is a vulnerability.
- coconut08 3y agopretending you don't need trust when you actually do is a vulnerability. of course you need to trust that mullvad is doing what they actually say they are doing. there is literally no way for you to verify everything they claim.
- EGreg 3y agoAnd yet you trust WhatsApp and Facebook and Signal with their claims of end-to-end encryption. Why?
- doublerabbit 3y agoI don't myself. If it isn't on my own infra, I won't trust it. The idea that folk are keeping passwords in some cloud management portal owned by some company boggles my mind. But this is a very controversial opinion and offends many.
- zamnos 3y agoAlright, I'll bite. Not all password managers are the same. In particular, the good ones have no direct access to your data. It's encrypted before reaching them, so even if they get hacked, the attacker can't access your passwords without your master password as well, which hopefully you're not giving out. You don't have to trust password managers if you don't want to, but if you want others to accept your reasoning as to why, you'll have to convince them using an argument that actually applies.
- rft 3y agoWhile GP didn't spell this out, they have, in my opinion, a point. If you use a cloud portal, usually web based (be it browser, electron or similar), that asks for your master password, you need to trust the provider that the master password is not send to their servers. Even if you trust the provider to adhere to this principle, if their infrastructure is compromised an attacker can serve you a different webapp that sends your master password to the server. Same goes for auto-updating native apps. This does not render the model of keeping the master password client side only moot, it is more secure no matter what. You successfully mitigate the read-only attack of dumping the storage of the cloud provider. However, if you assume a full, on-going compromise of the infrastructure, your password is not secure anymore. I get that this is moving the goal posts a bit but I wanted to post this anyway. I think if you have highly valuable credentials and want the maximum security for them, you should play out as many possible attack vectors as possible.
- coconut08 3y agoi never said you shouldn't ever trust anything. I personally do trust mullvad. I've been using it for over a decade. I'm just not in denial over the fact that there is trust required. Second of all, aside from signal which I have superficially played around with, I don't and have never used any of those services you mentioned and they have absolutely nothing to do with the topic at hand so maybe you can tell me why you brought them into this conversation?
- EGreg 3y agoBecause I don’t think it’s wise to trust ANY company with major secrets, just because they claim to not view them. Thus I agree with your sentiment and recommend it be applied far more widely
- panick21_ 3y agomullvad is working on a fireware attestation system that can allow clients to verify the exact version of the software running on the server. But I think this is not fully deployed. https://mullvad.net/en/blog/2022/1/12/diskless-infrastructure-beta-system-transparency-stboot/ https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur...
- azalemeth 3y agoThis is also one of the very few uses of remote attestation that I support as a consumer.
- cormacrelf 3y agoSome places passed laws during the pandemic allowing for the execution of a will using witnesses connected via video link. How does that sit with you
- sangnoir 3y ago> mullvad has time and again shown itself to be one of if not the best actors in the entire vpn space, but you still have no real way of knowing if they are being honest. There are parallels to the now-defunct Crypto AG. Impeccable reputation, but no way of independently verifying it it did what it said on the can. It took decades for the truth about its links to the CIA to come out.