9 ms·
Mullvad exit IPs are surprisingly identifying
- gruez 5mo ago>Surprisingly, the exit IP you are given is not randomized each time you connect to the server, but deterministically picked based on your WireGuard key What's the point of this? This seems more complicated to implement than mapping exit ips at the server level, so surely they must be doing this for a good reason?
- arciini 5mo agoI'd guess that this is to ensure one abusive user doesn't get every other user blocked from a large service (say, Google) for botting over the VPN and constantly rotating IPs. It's a practical measure, but definitely has a privacy cost though.
- stevekemp 5mo agoIt's possible that contributes, but to be honest most VPN users are split "privacy seeking" and "abusive". Though I grant you paid users are probably slightly more circumspect than users of Tor, etc. It seems more likely this is just about load-balancing use against their available nodes.
- tempest_ 5mo agoI imagine there are a bunch of things on the internet that break if you start trying to connect to them from varying IP addresses. Things like the various CAPTCHA schemes and rate limiting etc, IP reputation etc.
- lmm 5mo ago> I imagine there are a bunch of things on the internet that break if you start trying to connect to them from varying IP addresses. Things like the various CAPTCHA schemes and rate limiting etc, IP reputation etc. Given how much of the world is stuck behind CGNAT now, I would expect any major sites to handle it.
- nly 5mo agoIronically the CGNAT at my ISP is so broken at peak times the only way I can actually use the internet is via a VPN (presumably because I then only occupy one connection tracking slot on the NAT) I'm also stuck in a 2 year ISP contract
- TheDong 5mo agoIt's simpler to implement because it's more stateless, and it's a better user experience. If you get a new exit IP each time you connect, you need something like a NAT table to look up "key 0xabc exits ip 1.2.3.4", and that grows to be the size of the number of users you have active, and you need to save it forever so that when the NSA asks who used the IP for what duration you can tell them. With a static mapping derived from the key, you don't need a table like that. It's also better UX since it means reconnecting your VPN software (say you switch wifi hotspots) doesn't give you a different IP address, so things like SSH sessions can resume, which wouldn't be possible if it were a different public IP each time.
- Riany 5mo agoMy guess is deterministic assignment makes load distribution and debugging easier. But for a privacy product, that convenience probably needs to be reconsidered
- wg0 5mo agoVPNs are snake oil. Exit IPs are a public information.
- avazhi 5mo ago> Exit IPs are a public information. Yes, obviously. > VPNs are snake oil Huh?
- Cider9986 5mo agoVPNs are not snake oil. They transfer the trust of your internet activity from a place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad, IVPN, or Proton. Among other benefits. If you don't like your ISP creating a profile of you and selling it to target ads to you, you should use a VPN. >Should I use a VPN? Yes, almost certainly. A VPN has many advantages, including: 1. Hiding your traffic from only your Internet Service Provider. 2. Hiding your downloads (such as torrents) from your ISP and anti-piracy organizations. 3. Hiding your IP from third-party websites and services, helping you blend in and preventing IP based tracking. 4. Allowing you to bypass geo-restrictions on certain content. (https://www.privacyguides.org/en/basics/vpn-overview/ https://www.privacyguides.org/en/basics/vpn-overview/)
- jesterson 5mo ago> place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad This is highly subjective statement. Almost all commercial VPN services farm and sell your data. Just by that, my ISP is definitely high trust point while any commercial VPN is a low trust.
- sfdlkj3jk342a 5mo agoI can easily pay for a VPN service with crypto anonymously. I can also use a VPN run by a company outside my country of residence and jurisdiction. Neither of those is possible with my ISP.
- 5mo ago
- JoheyDev888 5mo ago[flagged]
- GalaxyNova 5mo agoDoesn't matter much as long as it is a pseudonymous identity
- stingraycharles 5mo agoIt’s also not that difficult to fix, so I expect a fix to roll out soon enough.
- malfist 5mo agoLet's see, short summary of the article, saying nothing new or important. It's not x it's y. Comment history is exactly this type of comment everywhere. This is an AI comment from an AI account.
- deleted 5mo ago[deleted]
- linkregister 5mo agoGiven that Mullvad is basically a bulletproof VPN host[1], it would be great if site operators could rely on this property to enact bans. Given that the solution is simple (add a pseudorandom seed), Mullvad will likely push out a fix within a couple days. 1. It's the preferred VPN of TeamPCP.
- fastily 5mo agoSource? Been googling for this but I don’t see any relevant info
- watchful_moose 5mo agooopsie, has someone burned their proprietary intel for internet points?
- ryoshoe 5mo agoI found these references to Mullvad and TeamPCP >The whole operation ran primarily from Mullvad VPN exit nodes and virtual private server infrastructure, with little effort made to blend in. This was a high-tempo, low-stealth campaign designed to extract as much value as possible, as fast as possible.[1] >Wiz CIRT observed the bulk of TeamPCP’s activity originating from Mullvad Virtual Private Network (VPN) exit nodes and virtual private server hosts such as InterServer.[2] 1: https://www.oligo.security/blog/teampcp-campaign-the-evolution-of-modern-supply-chain-attacks https://www.oligo.security/blog/teampcp-campaign-the-evoluti... 2: https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild https://www.wiz.io/blog/tracking-teampcp-investigating-post-...
- VoidWhisperer 5mo ago> Surprisingly, the exit IP you are given is not randomized each time you connect to the server, but deterministically picked based on your WireGuard key, which rotates every 1 to 30 days (unless you use a third-party client, in which case it never rotates). I'm a little confused on this... what is stopping third parties from doing key rotations like the main app clients if it is detailed in the repo how to do it?
- nvme0n1p1 5mo agoThird party clients include e.g. the WireGuard driver in the Linux kernel. It's definitely not the network driver's job to mitigate an attack against one specific commercial service.
- DANmode 5mo ago> what is stopping third parties from doing key rotations Knowing to do so, primarily.
- lorenzohess 5mo agoThe purpose of a VPN does not include anonymizing users with respect to the sites they visit,so it shouldn't be too surprising that Mullvad doesn't enforce unique exit IPs. Users who want anonymity should use networks like Tor.
- jorvi 5mo agoThat is exactly the point of public VPNs.. If I'm on a public VPN, I don't want anyone to know who is making the request, including the terminating IP. Think about it. By your logic, VPNs shouldn't be used for torrents because VPNs shouldn't anonymize you to the terminating IP. Whereas they work gangbusters for that. If you are talking about private VPNs.. Mullvad isn't one.
- charcircuit 5mo agoI think you are misreading his comment. He is saying that on a VPN it is standard behavior that if you visit site A and site B they will both see you connecting from the same IP and can infer you are potentially the same person.
- fragmede 5mo agoSite A and B have to collude in order to make that inference. Outside of Cloudflare, no one is colluding at that level.
- 5mo ago
- deleted 5mo ago[deleted]
- Riany 5mo agosurprising that the mapping may be stable enough to become a user-level signal. and rotating away from deterministic assignment seems like a cheap way to avoid creating an extra fingerprint
- solenoid0937 5mo ago> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. This sounds like how I'd design a VPN if I were an intelligence agency.
- asdff 5mo agoMakes you wonder...
- BLKNSLVR 5mo agoEvery now and then there are articles like this one about something that Mullvad may or may not be able to do better, and there are always comments about whether they're an intelligence front. I don't know the answer, but there are two ways to take it: 1. Submarining to destroy confidence in an actually trustworthy, decent VPN company 2. They're an intelligence front. For me, Mullvad have the appearance of the greatest likelihood of being legit since they're not aggressively pushing their product with lies and fear mongering. That gels with my vibe. If they're an intelligence front, well, most VPNs probably are as well, so I'm no worse off. Luckily I'm not doing anything that would get me in the kind of trouble for which multi-jurisdictional cooperation is worthwhile.
- 8cvor6j844qw_d6 5mo ago[dead]
- deleted 5mo ago[deleted]
- linkregister 5mo agoYou'll find comments accusing anything of being an intelligence front on internet message boards. I agree with you that public evidence is overwhelmingly in favor that Mullvad is earnestly trying to protect privacy.
- gchamonlive 5mo agoIt's a game of cat and mouse. The service keeps banning IP ranges, the user keeps reconnecting to different servers and regions. The server can't know exactly who's who, just that a bunch of users are using mullvad, while the user just need to find one server on one IP range that works. Seems like a good deal to me. I don't care if they know I use mullvad, I care they don't know I'm me, and that's not something mullvad will easily disclose.
- dns_snek 5mo ago> I don't care if they know I use mullvad, I care they don't know I'm me That's exactly what the article is about, a side channel information leak that de-anonymises users, did you read it?
- gchamonlive 5mo agoCan it get my IP? I'll go ahead and answer that it can't. It knows I'm mullvad user X, thus deanonimization, "it knows I use mullvad", but it doesn't know my original IP, so "it doesn't know I'm me".
- dns_snek 5mo agoI'm not sure what you're going for, your ISP-assigned IP doesn't tell them your legal name either. But when you connect to the site from via server A and later via server B they can tell that you're the same person. And they can deanonymise you through data brokers. All Mullvad IPs are traceable back to the same number (acting as a pseudo account identifier) so if you ever entered your PII on any website when using Mullvad, it can be linked to the same Mullvad account. And if you ever visited any of those sites without using a VPN, your home IP can be linked to your Mullvad ID through browser fingerprinting. And if you ever entered any PII on any website from your home IP, you can once again be deanonymised. Now the existence of browser fingerprinting isn't Mullvad's fault, but this flaw makes it a lot easier to accidentally deanonymize yourself.
- 5mo ago
- fooker 5mo agoIt seems surprising that people would expect a VPN to be comparable to Tor. It does seem ridiculous once you spell it out like that, and then you have to realize that it’s plausible to de-anonymize even Tor users by controlling exit nodes.
- curtisf 5mo agoMost of the big consumer VPNs include "privacy" with an implication of anonymity in their marketing, so it shouldn't really be surprising
- vintermann 5mo ago"Not knowing who a user is" privacy may still be useful even if you don't have, "not knowing two users are the same user" privacy.
- unselect5917 5mo agoIt is privacy with respect to your ISP. A lot of ISPs are pretty shitty. Some will rat out their own customers to copyright mongrels and threaten to disconnect you - which is important when there's a local monopoly. Things you connect to or log in to are clearly going to be able to ID you at least with in the context of the login that you use regardless of what the VPN does. I'm logged into HN through Mullvad as it happens. I usually leave it on regardless of what I'm doing because what I'm doing isn't my ISP's business even though I'm pretty happy with them.
- lucb1e 5mo ago> what I'm doing isn't my ISP's business even though I'm pretty happy with them. But it is Mullvad's? I think I'm from a spoiled part of the internet (as in, with an ISP that legit cares) so maybe I'm biased, but swapping one vendor out for another seems relatively no-op to me. Is it that there is a bigger pool of VPN providers than ISPs available at a given address (even when including (M)VNOs), and so it's easier to find one that sounds like they care as much as the ISP should have?
- 5mo ago
- paulpauper 5mo agoThis is why VPNs have always been crap. The pool of IPs are backlisted/tainted, so you will run into various roadblocks and cpatchas, in addition to slow speed. If you are serious about privacy and don't want blocks and blacklists, buy high speed private proxies. Don't use a pooled service.
- BLKNSLVR 5mo agoA VPN by any other name would smell as sweet.
- faangguyindia 5mo agoI maintain a list of "23034 IPs to blocklist.txt" blocked IPs they contain all VPN providers. Often VPN providers seed Geofeeds with wrong data, this is why i use traceroute and ping network to locate their real location.
- BLKNSLVR 5mo agoI have a script that logs IPs for any traffic coming in to my servers on ports that don't accept traffic. I then block those IPs from accessing ports behind which there are services. If they're checking my locked doors, I don't want them coming in my unlocked doors.
- notpushkin 5mo agoThis might be a good idea, but consider banning them for, say, a couple hours at a time. It’s easy to rotate IP, especially if you’re using a residential proxy service, and there’s a good chance you’ll end up blocking real users using the same ISP.
- m00dy 5mo agoyeah, I'm using https://proxybase.xyz https://proxybase.xyz for this. It's like Mullvad but for proxies. No kyc, no email but supports xmr.
- notpushkin 5mo agoI like the API-centric nature of it. $10/GB seems a bit steep though, especially compared to Mullvad’s 5 €/mo. Search for “mobile proxy” – those are usually cheap-ish monthly subscriptions, with unlimited traffic, and often an API to rotate the IP programmatically if you need it. No KYC, but you usually do have to sign up with an email.
- m00dy 5mo ago@ notpushkin, yes, it's a bit more expensive because it's for different use cases. You can't use VPNs or Mullvad for anything mission critical. Just try to log in to your bank in US, it will increase your risk score on their end because VPNs by nature are very easy to detect whereas "residential proxies" much harder.
- arian_ 5mo agoWe keep adding layers of encryption and the metadata keeps snitching on us anyway.
- charcircuit 5mo agoReusing the same VPN between multiple identities is a horrible idea regardless. And let's be real. As a forum moderator if you ban a Mullvad user and then a new Mullvad user signs up the next day it is probably the same person. You should be using residential or mobile proxies if you want privacy and to blend in to everyone else.
- connorboyle 5mo ago> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person. I don't see how the author is arriving at this ">99% chance" purely from the numbers provided in the article. Assuming the first (banned IP) seed and the second seed are both in the range 0.4423 - 0.4358 (a stronger assumption than is justified by the example), all this tells us is that the first and second IP addresses both have seeds in a range that would contain 0.4423 - 0.4358 = 0.65% of all Mullvad users, which 0.0065 * 100,000 = 650 users. We've eliminated >99% of users as "suspects", but we haven't actually gotten >99% accuracy in identifying an individual across multiple exit IPs. In more Bayesian thinking, the overlap in potential seeds is great evidence to think these IP addresses represent one and the same person (or Mullvad VPN account at least), but as far as I can tell, that's not what the author is saying.
- grey-area 5mo agoSay your forum is a big one and has 1000 active users, with 1 joining every day. Most will be a lot smaller/less active. What are the chances that someone uses this vpn, joins your forum the day after someone was banned, and has an ip in a similar range? For most small websites this would be strong evidence.
- Robin_Message 5mo agoI think you are (informally and correctly) doing Bayes theorem here. The prior is combined with the conditional to give the posterior estimate; the conditional is not itself the estimate.
- fizza_pizza 5mo ago[flagged]
- tempera 5mo ago[dead]
- 47282847 5mo agoMissing from the story: did they reach out to Mullvad? Would have been interesting to see how their security team responded.
- kfreds 5mo agoAs far as I can tell they did not, and I've asked both our operations and support teams. I will update this post if I am mistaken. Edit: In hindsight I regret making this comment. It was unnecessary, but removing it now would look weird.
- Havoc 5mo agoSeems fine. You didn’t exactly demand a 90 day embargo or something.
- luxuryballs 5mo agohow about this I’ll downvote it for you and you can downvote mine and we’ll just fade out together lol
- timbit42 5mo agoNo, but the top voted comment on this post is a response from the co-founder of Mullvad.
- haunter 5mo agoI just use it to watch iPlayer outside of the UK lol
- saratsai 5mo ago[dead]
- tschumacher 5mo agoGreat find by the author and I have no trouble believing this is an oversight by Mullvad. Kind of shocking that something this simple slips by them but I could see myself missing it. Putting aside the IP correlation across multiple servers, at first I wondered why even keep the user IP stable on one server. But I think it makes sense because as the author states other VPNs usually have only one IP per server so they are essentially simulating that. The advantages for the user are, if they find a server that works for accessing some service they can connect to that server again and it will work again because they get the same IP. The IP correlation across multiple servers they should fix though with something like rand.seed(user_pub_key + server_id)
- lxgr 5mo ago> The advantages for the user are, if they find a server that works for accessing some service they can connect to that server again and it will work again because they get the same IP. On the flip side, if they’re getting banned by a service because of a noisy neighbor on the same IP, they’d have no way to work around that, no?
- TurdF3rguson 5mo agoYou mean if the neighbor somehow burned every VPN location?
- lxgr 5mo agoDoesn’t even need to be every location. Some services are only accessible from a single country, and Mullvad has at most a handful of locations per country. All things considered, there are just an incredibly small number of IPs shared among all users, no matter the allocation strategy.
- saguntum 5mo agoI feel like trying to "trick" the RNG into providing stability is the wrong approach here given all the footguns that can occur with having a low entropy seed, but I am not sure what an alternative to IP stability would be short of doing session management, which may introduce too much state into the problem to be acceptable for a VPN service. Maybe a clientside hint that gets rotated in some circumstances with options to toggle it off would be appropriate. That should be fine as long as you don't care about someone being able to control their exit IP reliably.
- kfreds 5mo agoI work at Mullvad. (co-CEO, co-founder) Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post's findings you may get confusing results throughout the day. We will also re-evaluate whether the intended behaviors are acceptable or not. Some of this is a trade-off between multiple aspects of privacy, and multiple aspects of user experience. Please note that this is my current understanding, which may change. I was only made aware of this an hour ago, and most of that time was spent talking with Ops, considering what to do immediately, and writing this post. Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings, even if you intend to publish right away.
- ignoramous 5mo ago> Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings How to report a bug or vulnerability ... we (currently) have no bug bounty program ... send an email to support@mullvadvpn.net https://mullvad.net/en/help/how-report-bug-or-vulnerability https://mullvad.net/en/help/how-report-bug-or-vulnerability / https://archive.vn/BeHhr https://archive.vn/BeHhr
- wren6991 5mo agoTo support? Oof.
- kfreds 5mo agoI'm not sure what you mean by "Oof". We don't have a dedicated security team because security and privacy are integral to all aspects of our service. It doesn't make sense to centralise it. As for our support team they are responsive and experienced. Several of them have worked with us for many years and do offensive security research in their free time. Unlike many organisations we don't see customer support as a cost center, just like we don't see security as a cost center. Our support team represent our customers, and as a consequence contribute a lot to how we prioritise our roadmap.
- reincoder 5mo agoI work for IPinfo. Even though we are in the VPN detection business, I will give Mullvad the benefit of the doubt, to be honest. They were one of the three VPN providers we found that did not attempt to submit inaccurate geolocation information to IP geolocation providers like us. I am sure they will fix the issue.
- Melatonic 5mo agoWho else ?
- reincoder 5mo agoWindsribe and iVPN. https://ipinfo.io/vpnreport https://ipinfo.io/vpnreport
- lucb1e 5mo ago> five providers offered locations labeled as “Bahamas”: [...]. For all of them, measured traffic was in the United States, usually with sub-millisecond RTT to US probes. Foiled by light speed once again :). Interesting blog post, thanks for sharing. Checking out Windscribe pricing just now, I get a Cloudflare captcha. Really nice of them to make vendor selection that much easier: only two contenders left!
- Melatonic 5mo agoLooks like Windscribe is also recommended by Kagi Specials
- Melatonic 5mo agoWhy do so many VPN submit inaccurate info ? Are we talking intention to mislead or is it more about just scrambling / obscuring location ?
- reincoder 5mo agoYou have to ask them. I tried but did not get a clear answer. We operate nearly 1,400 servers across almost 160 countries ourselves. From our perspective, it is VERY hard to maintain and expand a network infrastructure of this scale. When you start getting servers in West Africa, Northern Africa, the plains in North America, or Oceania, the Eastern Indian Ocean, you are expected to pay magnitudes more compared to servers with equal performance in NYC or Amsterdam. Maintaining such a diversified network infrastructure from a technical point of view is extremely challenging. Then there is the official and bureaucratic process. Now, we are just scratching the surface. VPNs require high volume traffic throughput. Some countries (entire countries) just do not have the capacity to offer that. So, most of the time VPN companies tend to work with specialty VPN infrastructure companies. They provide everything from hosting to networking across dozens of locations they operate in. I believe there are even white-label VPN companies that handle everything from infrastructure handling all the way to billing and even support handling. You just bring your branding. It can be argued that there is little incentive to go out there, do it all from scratch. Is it intentional or just obscuring? From what we see, it leans intentional. The location they report is not inaccurate information by accident, it looks quite deliberate. Legacy IP geolocation services rely on something called a geofeed. A geofeed is a self-reported unverifiable report published by a network operator. Geofeeds are not widely adopted (1.5% of IPv4 and 0.70% of IPv6 allocated prefixes, 2023 data), but VPN providers maintain theirs diligently. They actively publish the locations they want IP geolocation providers to report. One point raised by a journalist on the reporting side: imagine your VPN server points to one of the offshore islands in the Caribbean that sit outside US jurisdiction, only to find out the actual VPN server is in Miami. That is a bit risky.
- camgunz 5mo ago"identifying" is the wrong word here--that's only possible if Mullvad stores a mapping between IP addresses and people, which according to them, a 3rd party audit, and a law enforcement raid they do not. It's also worth saying it's possible to use Mullvad entirely anonymously by mailing them cash, which I do. Also if the threat model you're addressing w/ VPN usage is anything other than "I don't want my ISP to know what I'm doing" you need to use/do something else.
- seethishat 5mo agoI'm a long-time Mullvad user. I will continue to buy and use Mullvad VPN services (with my credit card that has my name on it) so long as it is legal to do so in my country. VPNs are not 100% anonymous. They are not meant to be. Instead, they are meant to provide some level of privacy to law-abiding adults. Most people would be embarrassed if their co-workers and neighbors knew the intimate personal details of their lives. Things they like, things they buy, things they do, etc. So, most people should use a VPN to protect their privacy. By definition, 'most people' don't want or expect 100% anonymity online. They just want a bit of privacy in their personal life and their relationships. That's it. VPNs don't protect (and are not intended to protect) criminals who want 100% anonymity from governments while committing online crimes. This is an important distinction. 'Most people' are not criminals and do not have this unrealistic expectation from Mullvad and other VPN providers.
- nusl 5mo agoVPNs aren't anonymous, no, despite people pretending they are. Nonetheless, the findings in this report do highlight some things that make user identification easier than you'd expect it to be. I'd not throw the report out just due to what you argue here. These findings are valid nonetheless.
- deleted 5mo ago[deleted]
- righthand 5mo agoSounds like it’s time to drop Mullvad (their ui client is terrible chromium app anyways) and start using a selfhosted provider. This screams three-letter agency.
- bstsb 5mo agomuch anonymity provided by VPNs is through how many people use their exit nodes, “disguising” your traffic among others. also if you hosted your own VPN it would be trivial for one to find its host from an ASN, and from there subpoena your billing information
- righthand 5mo agoSure but I’m not necessarily trying to hide my name from the law. And you dont get much disguise when your vpn company is compromised and logging it.
- AtNightWeCode 5mo agoReality check. VPN is the most common fingerprint to begin with. Any small site is never hit with unique users from unique VPN providers.
- robotburrito 5mo agoIs it wrong that I assume these VPN services are probably honeypots in some way?