Mullvad is one of the few VPN providers that offers multiple exit IPs for its servers. If two people connect to the same server, they will usually end up with different public IPs. With only 578 servers (compared to Proton VPN’s 20,000), this kind of vertical scaling makes sense to avoid cramming too many users onto one IP, which would be a problem on sites with overzealous IP blocks and ratelimits.

  • A Mouse@midwest.social
    link
    fedilink
    English
    arrow-up
    26
    ·
    2 days ago

    Here’s a response.

    I work at Mullvad. (co-CEO, co-founder)

    Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post’s findings you may get confusing results throughout the day.

    We will also re-evaluate whether the intended behaviors are acceptable or not. Some of this is a trade-off between multiple aspects of privacy, and multiple aspects of user experience.

    Please note that this is my current understanding, which may change. I was only made aware of this an hour ago, and most of that time was spent talking with Ops, considering what to do immediately, and writing this post.

    Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings, even if you intend to publish right away.

    https://news.ycombinator.com/item?id=48145679

    • read_desert@lemmy.ml
      link
      fedilink
      arrow-up
      9
      ·
      2 days ago

      Very level headed response by the Co-Founder/Co-CEO. Also yeah, probably reach out to them first too before publishing. Bare minimum professional courtesy. Love Mullvad even though I bought into the Proton “ecosystem”.

  • AllNewTypeFace@leminal.space
    link
    fedilink
    arrow-up
    10
    ·
    2 days ago

    The Swedish relays are often blocked (presumably because they’re the default). Switch to a slightly more obscure country (say, Slovakia or somewhere) and you’re good as gold.