6 ms·
> Ok, but... don't users have to reply [rely] on their provider’s pinky-promise that the two parties won't cooperate with each other and share their separate da
by kfreds 2y ago
> Ok, but... don't users have to reply [rely] on their provider’s pinky-promise that the two parties won't cooperate with each other and share their separate data, thereby connecting the dots?
>
Yes. On the other hand, it does complicate things for the attacker, whether it is internal (the orgs) or external - a 3rd party attacker would have to compromise both orgs instead of one.
> After all, the two parties are already cooperating to an extent, so why can't they cooperate even more, either voluntarily or at the command of some hostile government?
Voluntarily: If you look at the business incentives that wouldn't make a lot of sense.
Forced by government: Here I'd say look at the jurisdictions of the orgs.
(disclosure: I'm one of the founders of Mullvad)
- ignoramous 2y ago> Here I'd say look at the jurisdictions of the orgs. Per Covert Surveillance Act passed in 2020, looks like Sweden (where Mullvad is based) can ask communication providers / website services to secretly add or assist with backdoors? ... Where the identity of the suspect is not known, but his contacts are known, or a third party (such as a website which the suspects visits) is known, one can permit secret data reading of these contacts, or the third party, but only in order to identify the suspect. Only (stored) historical metadata, not real-time data or communications and not by means of activation of audio or video surveillance functions can be used for this (section 4b). https://www.venice.coe.int/files/Spyware/SWE-E.htm https://www.venice.coe.int/files/Spyware/SWE-E.htm / https://archive.vn/LgE7a https://archive.vn/LgE7a
- kfreds 2y agoI'm pretty sure you're talking about this law, in which case it doesn't apply to us. https://mullvad.net/en/help/swedish-covert-surveillance-data-act https://mullvad.net/en/help/swedish-covert-surveillance-data... In short, "Mullvad is thus not covered by either the data storage provisions in the LEK for operations subject to a reporting obligation, or the duty to cooperate pursuant to the Covert Surveillance of Data Act."
- ignoramous 2y ago> it doesn't apply to us This is also what your website says, But it could be interpreted contrarily - that VPN services through, for example, encryption via signals that the VPN service itself has power over through agreements with subcontractors, etc. could possibly be seen as an electronic communications service ... And I'm not just talking about Mullvad VPN (the "electronic communication service" provider), but Mullvad AB, which also hosts websites and builds apps (like the browser and VPN clients), too. So, is the "law doesn't apply" a fact? If so, may want to reword this bit on your website to make that much clear: [Mullvad's] opinion is that the reasonable interpretation is that a VPN service is not to be considered as an electronic communications service based on previous legislative history. If not, due to the "covert" nature of the Act, if Mullvad was coerced to co-operate with the govt, it seems Mullvad couldn't even publicly talk or hint about it (like warrant canaries, for example)?
- kfreds 2y agoI'm writing this on my phone and for whatever reason can't find the passages that you're quoting. Are they in the same article that I linked? In any case, to my knowledge the law in question doesn't apply to us. If the Swedish government tried to argue otherwise we'd get our lawyers involved. Having said all of this, I am concerned about National Security Letters and similar concepts. Technologies like reproducible builds, transparency logs, and remote attestation can help there.
- ignoramous 2y agoThanks. > Are they in the same article that I linked https://mullvad.net/en/help/new-law-for-electronic-communications https://mullvad.net/en/help/new-law-for-electronic-communica... / https://archive.vn/86hGz https://archive.vn/86hGz > to my knowledge the law in question doesn't apply to us Fair. This isn't the official Mullvad position, then (which is that the law may apply)? The "Communication provider" part aside, another source (quoted above) makes it explicit that backdooring "websites" (Mullvad has a website) are fair game, btw. > If the Swedish government tried to argue otherwise we'd get our lawyers involved I don't doubt you would. Given the "covert" nature of the Act, Mullvad's arguments & Sweden's counter-arguments and the outcome from it (backdoors, compromises, coercion etc) will be kept a state secret. That is, there doesn't seem to be a way for the public to independently ascertain the claim that the Mullvad did fight and indeed "the law didn't apply"? [0] > reproducible builds, transparency logs, and remote attestation Much needed (: Per Mullvad's posts, the Act seems to grant wide-ranging powers to Swedish authorities, including installing hardware & other sorts of physical compromises (which no amount of software mitigations would thwart, I don't think). [0] Focusing on the premise: "Forced by government: Here I'd say look at the jurisdictions of the orgs."