4 ms·
It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security
by brapachin 3y ago
It appears in this audit. They only reviewed test production servers.
Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info).
Maybe I’m wrong someone pls lmk. But I’m not convinced a test of this calibre demonstrates Mullvads claims of no logging.
- nemo8551 3y agoI would have liked it if the audit had also provided a number of logins to be used on that server to act like typical users. Just so it was operating as a normal server would. This could have led onto auditing a live server. Auditing an in use customer facing server would definitely require a good amount of controls to ensure the auditors didn’t log any possible customer data.
- amarshall 3y agoIt wouldn’t make that much of a difference, I think, since they could just do the same with the real servers but only for the period of the audit. There has to be some faith that the subject isn’t actively deceptive and malicious, or the audit has to be random and at any time.
- stonepresto 3y agoAt some point of paranoia people should really look into selfhosting a VPN service. Sure, your VPS provider can see one side of the traffic so its not bullet proof, but that can be mitigated. Mullvad is a nice middle ground for those who don't see that as worth their time or don't know how. Its good to see they're at the very least trying to keep up appearances.
- dewey 3y agoI doubt that's the better way. How is self-hosting helping with the paranoia vs. using Mullvad? I don't really see how it's more secure to run some software that you haven't audited on a VPS somewhere at a provider you haven't audited. I'd trust a company with resources to run their own hardware, investing into a more secure setup [1] and contributing to more open infrastructure [2] much more than I trust myself to run something securely which isn't my sole occupation. [1] https://mullvad.net/en/blog/2022/1/12/diskless-infrastructure-beta-system-transparency-stboot/ https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur... [2] https://mullvad.net/en/blog/2019/8/7/open-source-firmware-future/ https://mullvad.net/en/blog/2019/8/7/open-source-firmware-fu...
- rvnx 3y agoSelf-hosting also makes you vulnerable to the network hosting you (not only the hosting server itself, but also the internet transit provider) and of course the website you are visiting, as you are the only user from that source IP (rendering a VPN practically useless).
- BLKNSLVR 3y agoThere may be holes in this but: 1. |Router| -> Wireguard / OpenVPN -> |VPS| 2. |Device| -> Wifi -> |Router| 3. |Device| -> app -> |Mullvad| = |Device| -> |VPS| -> |Mullvad| -> Internet Can do various mixing and matching if you have more than one VPS. Again, it rearranges rather than removing the vulnerabilities, and it's pure window dressing against an organised, financed actor. I've done this as an intellectual challenge more than anything else.
- pokeymcsnatch 3y agoI do this, mostly for the static IP that isn't linked directly to me and my approximate location, with mullvad exit only for 'sensitive' stuff. The degree of separation is nice even if the breadcrumbs are there. Best if the VPS allows crypto or cash payments.
- stjohnswarts 3y agowhy would self host be better? Do you have a list of VPS that are better than mullvad?
- aborsy 3y agoSelf hosting isn’t private at all. You will replace home IP with VPS IP, both of which linked to you. Also, VPS provider probably logs the traffic.
- AndyMcConachie 3y agoYou're asking Mullvad to give outsiders access to their customer's connections. That's something they've promised to never do.
- slowmotiony 3y agoI work in a bank and wish it worked like that too. "Sorry ECB, sorry SEC, we don't allow auditors access to our customers money". :-) My work would be so much easier! Too bad we can't do it because we'd go to prison.
- afiori 3y agoThey don't state it clearly but this was a "we are capable not to mess up" audit rather than a "we are keeping your promises" audit. I believe it is relevant to the threat model of an attacker gaining (partial) access to a production server (eg no accidental logging), not to the threat model of mullvad deploying malicious code. I feel like this is a meaningful audit but would have liked if they had stated this more explicitly
- sargun 3y agoMullvad has been chopping away at system transparency for a little while: https://mullvad.net/en/blog/2019/6/3/system-transparency-future/ https://mullvad.net/en/blog/2019/6/3/system-transparency-fut... -- Effectively, a mechanism by which their servers can perform attestation to their server really being what is says it is. I think they might have even spun this out into a separate project. With this, you can "trust" Mullvad that what's audited is really what you're using.
- jonfw 3y agoAudits can't account for a company acting in bad faith to mislead an auditor. It accomplishes two things- 1. ensure that the company isn't misconfiguring things and accidentally breaking their own policies 2. provide a paper trail that would directly implicate people in the event of fraud, removing plausible deniability for the folks involved.