Today at Security Fest in Gothenburg

#mullvad

CVE-2024-55884 - Critical OOB access in Mullvad VPN. Heap-based write via exception stack exhaustion. CVSS 9.0. Code execution possible. No patch available yet. Monitor for updates. #CVE #Mullvad #infosec

https://www.valtersit.com/cve/CVE-2024-55884/

CVE-2024-55884 | Valters IT Hub

Exit IP fingerprinting between VPN servers

On Friday the 15th of May, we became aware of a fingerprinting issue affecting Mullvad users.

Mullvad VPN

QUESTION: Does installing Proton Pass in Mullvad Browser ruin its purpose?

We want the extension for convenience, but Mullvad aims for "anti-fingerprinting" by making everyone look identical. Extensions inject custom scripts and modify the DOM. Trackers use MutationObservers to spot these client-side changes instantly. Even without logging in, your browser becomes unique.

Is the Proton Pass desktop app the only real way, despite the obvious inconvenience?

#Privacy #Mullvad #ProtonPass #OpSec

#UnplugBigTech Tipp 26: VPN-Anbieter

Viele bekannte VPN-Dienste haben fragwürdige Datenschutzrichtlinien oder unterliegen US-Gesetzen. Bevorzuge europäische Anbieter wie Mullvad oder ProtonVPN, die strenge No-Logs-Richtlinien versprechen – auch wenn deren Einhaltung letztlich eine Frage des Vertrauens bleibt.

#VPN #NoUS #Privacy #Mullvad #ProtonVPN

SecurityFest in Gothenburg this week. I'll be there working for #mullvad

If you are there, there will very likely be swag!

#Goteborg #Gothenburg #securityfest

Would like to know how this affects @LineageOS users, their bluesky is a holding page, their subreddit is heavily moderated, and the moderators are frequently hostile to questions, so perhaps here?

#lineageos #mullvad

https://mullvad.net/en/blog/any-app-on-recent-android-versions-can-leak-certain-traffic

Any app on recent Android versions can leak certain traffic

A recently discovered bug in Android 16 allows any app to leak traffic outside the VPN tunnel.

Mullvad VPN

#Frage zu #Browser #Mullvad
Es werden statt Bildern Muster angezeigt. Weiß jemand wie ich das loswerden kann?

Das wäre ganz wunderbar!

ANTWORTEN BEKOMMEN! DANKE DAFÜR! PROBLEM GELÖST - GUCKT IM VERLAUF, FALLS IHR DAS GLEICHE PROBLEM HABT.

Malgré la chute d'un #vpn récemment, certains devraient etre plus robustes, comme #mullvad qui a deja subit une perquisition et n'a rien pu donner aux flics

Par contre, paie le en crypto du coup, pour eviter le précédent de #protonmail qui a donné les data CB🤷‍♀️

https://www.techradar.com/news/mullvads-no-log-policy-proven-after-police-raid

Mullvad's no-log policy proven after police raid

No customer data was compromised, the provider said

TechRadar

Mullvad is rolling out fixes for a VPN fingerprinting issue that could let websites associate activity across different VPN servers through exit IP assignment patterns.

Users switching servers are advised to re-log to regenerate WireGuard keys and internal IPs.

https://www.technadu.com/mullvad-fingerprinting-issue-prompts-vpn-system-changes/628269/

#VPN #Privacy #Cybersecurity #Mullvad