WireGuard multihop available in the Mullvad app(mullvad.net) |
WireGuard multihop available in the Mullvad app(mullvad.net) |
The iCloud Relay paper outlined a pretty private and secure design [0] (and the intention to standardize it via IETF would probably make it simpler to self-host such a solution [1][2]). Among the VPNs, orchid.com's distributed VPN stands out as a cross-provider multi-hop solution whose privacy guarantees are closer to Tor's.
Eventually the hope is HTTP (www) itself bakes in desirable privacy properties, so regular users don't have to pay the cost of multi-hops [3].
[0] Overview: https://datatracker.ietf.org/meeting/111/materials/slides-11...
[1] https://ietf-wg-masque.github.io/
We never developed it further beyond the initial research (it was senior spring, not a lot getting done, I even forgot to buy Bitcoin). I remained (and remain) interested in decentralized VPN networks, and played around with implementing something around it, but ultimately I didn’t have the experience to build what I wanted.
Personally, I like what Orchid, Tailscale and ZeroTier are doing. I also like Fly.io and Cloudflare Workers and generally any product that iterates toward a Network Function Virtualization (NFV) platform. The root obstacle is incumbent compute-based clouds oversubscribing compute by gouging on bandwidth. This makes the cloud environment inhospitable for any cost-effective, transit-intensive business like a CDN/VPN, increasing the barrier to entry by requiring self-hosting a distributed network.
[0] https://dedis.cs.yale.edu/dissent/papers/hotpets14-torpath.p...
I'm just speaking as a layman end user. When I see multi-hop it's self-explanatory, it's literally in the name.
Onion routing is another type of multi-hop with the onion routing algorithm.
With iCloud Private Relay, it'd be harder for a single actor to de-anonymize requests; you'd either need collusion between the companies or a government entity would need to ask both companies to log network traffic at once, and this would complicate the "exit node" server since it can't filter/only record traffic from the target customer's connection without company 1 setting up a single server dedicated to being the proxy for that customer.
[1] - https://tinc-vpn.org/
This isn't because I have any reason to mistrust their app, but just because if I've already got a perfectly serviceable client on my device, why add another binary to do the same thing?
But I would be interested to hear, from folks who have used the app, what you like and don't like about it. In particular, I've had some headaches setting up split tunneling/proxying via OpenVPN - I was never all that good at its config language - and I'm wondering if the Mullvad app might make those easier to achieve.
Mullvad is trying to increase their transparency and make sure users can trust them which is great. But would there be a way for them to make it so that users do not have to trust them? What if the second server was hosted by another entity?
Simple answer: Apple doesn't get your info. Mullvad is one of the non-logging VPN providers so unless you're compromised in some other way (like logging into Google, Facebook, etc) then running a make on your is far more difficult than just serving a warrant to Apple.
How do you know that they're not logging? Or that their ISPs are not logging?
Recently, Instagram "tagged" my account as either based in Russia or using Russian currency. I'm based in Western EU and set up the VPN to connect to the same country or neighboring ones.
I'm trying to figure out if some endpoints belonging to Mullvad have been shadowbanned by Meta/Instagram. Is there someone else who uses Mullvad to surf on Meta products whose account has been impacted by sanctions directed at Russia?
My first guess is that it's a mislabelling problem or bots going rogue for an unkown reason. And, IG support is taking too long to clarify what's the culprit. So, I'm making all kind of hypotheses to reach a logical explanation before getting an official answer.
Users can use Mullvad’s TOR address: http://o54hon2e2vj6c7m3aqqu6uyece65by3vgoxxhlqlsvkmacw6a7m7k... to generate their account ID and make their payment with Bitcoin seamlessly.
I have never experienced such a smooth way to purchase from a provider, this was brilliant.
+1 to Mullvad
I randomly came across a recommendation for Mullvad from reddit, and signed up for a month. Hot damn if my download rate didn't shoot up to 15-20 MB/sec (that's megabytes, not bits) - essentially close to maxxing out my fibre.
Turns out you really do get what you pay for - and I doubt I'll be leaving Mullvad any time soon.
(no affiliation - just a happy and surprised customer!)
My favorite thing they do is trying to make server infrastructure transparent:
https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur...
The iOS app has been more reliable than the mullvad app so far, which is the reason I switched. Additionally, it allows to configure "trusted" and "untrusted" networks, which is quite useful as well. (And yes, this is not a secure feature, as a network can easily be spoofed, but I use IVPN mostly for data privacy and not for safety/security reasons)
So server2 terminates the request twice? One for server1 and another time for the client who generated the request? I don't understand how it's possible for server1 to not be exposed to the data.
> It’s a WireGuard tunnel being sent inside another WireGuard tunnel
Edit: replaced with a better diagram (and again, now based on example in [0]):
▼ ▼ ▼ ▼
YOU->NL1 tunnel SE4->NL1 tunnel PLAIN/TLS
YOU ────────────────────► SE4 ───────────────────► NL1 ───────────────► CATPICS.COM
On the wire: YOU->SE4 traffic SE4->NL1 traffic NL1->CATPICS.COM traffic
┌────────────────┐ ┌────────────────┐ ┌──────┐
Inside: │YOU->NL1 traffic│ │YOU->NL1 traffic│ │ DATA │
└────────────────┘ └────────────────┘ └──────┘
[0] https://mullvad.net/en/help/wireguard-and-mullvad-vpn/- the WireGuard public key for server 2
- the IP address for server 1
- a unique port for server2 on server 1
So all they're doing is a standard iptables redirect to the second host (which may or may not itself be under a WireGuard tunnel).
Why do so many of you use VPNs?
Absolutely love Mullvad.
There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security.
They spoke with passion about security fixes they made in the vpn client that no other had.
They got many requests regularly from others that they should add there server as an endpoint - and they sad always no. All endpoints must be 100% secure by their knowledge. Never trust anyone.
If they had to leave a laptop they used some old coffee paper trick so that one could not open the lid without visible marks.
I was super impressed by them and have never met any like them. I guess they have grown out of their tiny office now, Mullvad.
And, of course, easier (for me) to set up and configure. Maybe no _huge_ incentive to switch over to it if your setup works, but might be worth trying out if you're curious.
I've also found that the client devs respond to issues. This is great as well as I feel as though I'm getting a complete solution with Mullvad.
While I have no doubt Mullvad is great as a vanilla VPN without their client - I feel as though I'd be missing out on a few features and convenience items if I were forced to bring my own.
And to be clear - while Multihop is new, it's not new as in today. It's been out for a while in beta (if I'm remembering right) and landed in GA about a month ago. I don't see much need for it in my use case, but it's nice they're continually enhancing the overall product.
I wanted to have a VPN up 24/7 but certain sites apps don't really like VPNs. I basically have steam and privoxy set as my split tunneling apps. Steam because it seems their website's CDN breaks half the time and privoxy so I can access specific websites without a VPN.
For privoxy to work properly I use a browser extension called SmartProxy[1] which lets me setup a proxy and then I can quickly add/delete sites from using that proxy, I just add 127.0.0.1:8118 and I can basically have any site either use the VPN (default) or whitelist it so it goes through my home connection.
[1] https://chrome.google.com/webstore/detail/smartproxy/jogcnpl...
Things I mostly like:
- The relative simplicity of the app interface (though 'advanced' settings should just be a sub-section of 'preferences')
- How quickly/easily I can get connected (download, paste in account #, click connect - or change location.
- Relatively easy split-tunneling
- Easy switch between OpenVPN and Wireguard protocols
- Easy local network sharing (preference toggle)
- Tracker and ad block options (have not tested efficacy, appears to be DNS-based)
- Internet kill switch (will not fall back to non-vpn connections if set)
Things I don't like:
- Can cause issues on boot/reboot if kill switch is enabled (Windows - disable kill switch, restart app, re-enable kill switch)
- Limited options for mobile apps (and some unexpected disconnections on android)
- No configuration of app layout or color scheme
- Somewhat annoying upgrade (not bad, just no in-place upgrade solution)
If you're comfortable setting up OpenVPN profiles, the Mullvad app doesn't have much to offer you as far as I can tell. I don't recall seeing split tunneling options, though that would be cool to see
Setting split tunneling to ONLY TUNNEL A SPECIFIC APP is hard
Seems like mullvad is being used by a lot of bad actors and they're not really doing anything about it.
I like their software and monetization but their IPs are probably the lowest quality IPs in the VPN market.
FWIW I run my own VPN server on a common cloud provider, and I actually encounter more trouble there than when I'm logged into Mullvad. I think the services who can't think of more creative solutions than blanket IP bans are the real problem here.
If you set up your own VPN server on popular cloud platforms, you'll notice that almost all Cloud platforms face the same issue. Basically this is what you get when you use a data center IP for Internet browsing.
I'm guessing xTom acquired an IP block from someone in Russia a while ago and IP geolation databases are just very slow to update.
(also no affiliation, just a happy customer)
With Mullvad, a similar choice of locations - again, it doesn't seem to matter, but in a good way.
The PIA app is lovely. Mullvad's as well
All for €5 a month? Such a great company.
They solve different problems, and can be used together.
HTTPS encrypts the contents of packets between your browser and the server. Therefore it reveals to your ISP what service you are using and when, which also indicates where you are at that time (e.g., in front of your computer at home). And it reveals to the Internet service (e.g., Facebook, etc.) identifying information about your computer. That metadata - knowing what people are doing and when, and identifying information - is generally considered to be as valuable as the contents of their transactions.
VPNs encrypt everything between your computer and the VPN provider. That hides from your ISP and other intermediaries everything you do, other than indications of activity (though traffic could be your computer downloading an update, or example, without you being home). It hides some identifying information from the Internet service, such as your IP address, though your computer may communicate much more that identifies it. However, a VPN reveals to the VPN provider everything that would have been revealed to the ISP; you are merely shifting your trust from one vendor to the other (which is why HTTPS and VPNs are used together).
In a sense, a VPN provider becomes your ISP, including determining the apparent location of your computer - you can look like you are in a different country, which might change what DRM-controlled media you can access. (VPNs also are used for secure tunnels, for example by remote workers and by security-concious network administrators.)
2) SNI sniffing makes some websites unavailable to me, so DoH isn't enough.
That said, I can’t say the same for my phone provider.
My country is also blocks many sites and requires ISP to transparently route all DNS traffic to DNS servers that implement the government's block list. DNS over https is also really slow with frequent timeouts. I suspect they mess with popular DoH servers to discourage people to use it. Again, VPN solves this.
If you leave a computer running anyone (Well "anyone" being a skilled adversary) can simply pull out the RAM and grab encryption keys in clear text. Law enforcement does this so often, it's practically routine. The only "safe" system is one that has been long powered off and is using tried and true cryptography, ideally open-source FDE that's been fully audited.
[1] https://github.com/mullvad
[2] https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leak...
I’ve only heard of it being done by researchers and/or special situations.
Is this just speculation?
Leaving aside the leg work "simply" does here, especially in a coffee shop environment: would AMD's "encrypted memory" help against these kinds of attacks?
I have a laptop with an AMD Zen 3 Pro CPU that has this option in the BIOS and was wondering whether it actually did any good, as opposed to being just some marketing shtick.
How to defend against this?
...which could be soldered. Plus, there are methods to store keys in RAM in encrypted form and decrypt them only on the cache and CPU registers.
One does not simply pull out the RAM
> "They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security."
I don't get itSNI is cleartext enough to be passively logged, so you never know. Maybe some government-mandated (or supplied) switch is logging them to some short-lived log file in case they ever need to pull your hostname history.
Note that SNI sniffing protection is in the works by encrypting the client hello[0]. While it's been in draft for some years now, Chrome has a lot of work being put into it[1], so hopefully it'll be done sometime next year with support within Cloudflare and browsers soon after.
0: https://datatracker.ietf.org/doc/draft-ietf-tls-esni/?includ...
1: https://bugs.chromium.org/p/chromium/issues/detail?id=109140... (comment 20 onwards)
But the app actually has a wg tunnel inside another wg tunnel. If you (on Linux) run `wg` (as root) in a terminal when it's connected with multihop you will see that it has two peers set up for the `wg-mullvad` interface, one peer is routed through the other.
So the only thing that SE4 can see is encrypted WireGuard traffic headed for NL1.
I replaced the diagram in the previous comment, take a look.
The guide at https://mullvad.net/en/help/wireguard-and-mullvad-vpn/ only talks about how the config files does it. Which is completely different from how the app does it!
It was made by Jason A. Donenfeld.
That said, mullvad facilitates fully anonymous signup and payment, if you’re so inclined… so in that regard even if they’re secretly logging, if your OPSEC is up to par then it’s fairly moot.
Just my 0.02$
That way your traffic would be "legitimized" (no infernal Captcha loops), and if the sites you visit have certificate pinning mullvad network compromise wouldn't matter.
A bunch of ifs, but that's the state of things.
edit: written before thinking out all the details, probably can't tunnel udp connections over Tor.
Security and privacy is not a true/false thing, it's a thing you do at layers. Making payments anonymously is obviously adding another layer. Maybe it's not worth it for you, but for some it is.
If you really have only limited sensitive traffic (even with fake identity), you are better off using just tor browser than using a full machine vpn.
Using debug registers to hold an AES key purely in the CPU is genius.
I think you're missing the point here. Even if you use Tor browser or a completely new OS installation of Tails or whatever, if your payment method can be tied to you, you're once again screwed. Being able to anonymously pay, removes that vector, it's as simple as that.
To a typical customer of mullvad who also reads hn I would say this – you aren't going to gain any additional privacy by using anonymous payments. Here's why: either you believe Sweden is a safe haven for user data privacy or not.
– If it is, then you have nothing to worry about even with payment method tied to you.
– If it is not, then a Swedish government agency can compel mullvad to reveal the customer details (like payment method details) based on the WireGuard UDP socketpair details. But then they can also very likely compel mullvad to give them a live dump of traffic within the tunnel.
For truly high-risk people (journalists/whistleblowers against powerful entities, not regular geeks who want to block ad tracking), I'm not sure if any vpn service like this is a net help or does it actually cause more harm.
That's the wrong conclusion. The right one is: if you're the kind of actor who needs 100% privacy, mullvad is likely a part of solution (because of their track record), together with many other services and tooling. No one relies on one part to remain anonymous, as again, privacy and security depends on layers, not just a single layer.
> either you believe Sweden is a safe haven for user data privacy or not.
Even if Sweden is "a safe haven for user data privacy" or not, the government is not the only threat against mullvad. Mullvad themselves, the location they have their servers, their payment processors and many else can also be compromised. Paying Mullvad in cash (and protecting yourself in more ways) helps more than paying with a credit card attached to your full name, as any middleman can be compromised (and not just by a government).
> For truly high-risk people (journalists/whistleblowers against powerful entities, not regular geeks who want to block ad tracking), I'm not sure if any vpn service like this is a net help or does it actually cause more harm.
High-risk people don't rely on a single VPN service but again, layers of them in order to facilitate things like proxy chaining and multi-hop.
But, talking with you back and forward, makes it clear that you haven't actually engaged with any of these "high-risk people" you feel so sure to proclaim how things work for. I urge to actually talk to some of them and see what kind of setup they can tell you about, as you'll learn some more about how you can protect yourself and remain anonymous, if you really want to.