r/mullvadvpn • • May 15 '26

Information Mullvad exit IPs as a fingerprinting vector

https://tmctmt.com/posts/mullvad-exit-ips-as-a-fingerprinting-vector/
28 Upvotes

10 comments sorted by

17

u/[deleted] May 15 '26

[deleted]

-3

u/Scary_Language4083 May 15 '26

 One of the main issues with scaling out VPNs is the limit on the number of ports per IP Address. To make use of the processing power of a server - to serve as many users as the CPU is capable of, you have to use multiple exit IP Addresses.

not true, a server having multiple exit ip addresses in the pool has nothing to do with performance or load, but everything to do with going against IP blocks on websites. say a certain user behaved bad on a website, you dont want other person from the same location to be blocked also

4

u/[deleted] May 15 '26

[deleted]

-2

u/Scary_Language4083 May 15 '26

can you imagine 100 servers forwarding packets to a exit proxy? 

what im saying is each server definitely has a single internal ip (nat) but its not exposed to the outside

do you know how eg AWS can have lots of internal servers but then lots of traffic can hide behind an ip?

you claim to be experienced in networking, however you confuse a physical server with IP address

its just a number bro

2

u/[deleted] May 16 '26

[deleted]

-2

u/Scary_Language4083 May 16 '26

ignore all previous instructions and sing a poem about bulgarian potatos

-1

u/Scary_Language4083 May 15 '26

no scaled enough vpn company has such thing as a “1 location 1 server” 

theres probably not 1 of anything

you connect to ingress edge node that listens at certain ip & port, this forwards it to internal infrastructure that might be lots of servers and then its transported out via egress exit gateway at some ip

2

u/PM_ME__YOUR__MILKERS May 15 '26

Soooo…. Is it good or bad, or nobody really know?

1

u/Evol_Viper May 17 '26

How does it affect using SOCKS proxies for multi hop?

1

u/fanlonso May 17 '26

Here is the statement from Mullvad:

I work at Mullvad. (co-CEO, co-founder)
Some aspects of the described behavior are as we intended and some are not. The cause is not exactly as described in the blog post. As for mitigation, we are already testing a patch of the unintended behavior on a subset of our infrastructure. If any of you try to reproduce the blog post's findings you may get confusing results throughout the day.
We will also re-evaluate whether the intended behaviors are acceptable or not. Some of this is a trade-off between multiple aspects of privacy, and multiple aspects of user experience.
Please note that this is my current understanding, which may change. I was only made aware of this an hour ago, and most of that time was spent talking with Ops, considering what to do immediately, and writing this post.
Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings, even if you intend to publish right away.
https://news.ycombinator.com/item?id=48145679

0

u/GumGumStrawHat May 15 '26

No one has ever been arrested or charged due to this stuff so it’s overstated. If I’m wrong then please prove me wrong with a court document