Hacker Newsnew | past | comments | ask | show | jobs | submit | reimertz's commentslogin

I know multiple people who worked / working at Mullvad and they take their business, security and privacy _very_ seriously. Not surprised to see them shine here.


Coincidentally, Mullvad, Windscribe and IVPN all worked when I was in China behind GFW, while more popular options did not.

Seems like there are VPNs, and then there are VPNs.


I'm a bit curious about how that works. I love Mullvad but routinely I find sites like Reddit completely block it. Even yesterday someone posted a Debian wiki link[0] and I was blocked. It's not all of them but Reddit is a big killer. So I thought China would block all of them (aren't they known?)

Fwiw I'm not switching from mullvad

[0] https://news.ycombinator.com/item?id=46252366


Use the Tor Onion Service [1] for Reddit instead. You never leave Tor so you don't have to deal with the usual exit node problems. No need for a commercial VPN.

[1]: https://www.reddittorjg6rue252oqsxryoxengawnmo46qy4kyii5wtqn...


Reddit blocks basically everything - since the 2023 API meltdown it's gone full 1984 censorship and opinion manipulation mode. There are two target audiences for Reddit: propagandists (who are given moderator status, even in subreddits they didn't create) and targets of propaganda (only if Reddit can verify their physical location). You're not in the first group and you don't want to be in the second.

The Tor service does not work. It's been unmaintained for years.


Yeah reddits weird because last I checked you can access it on TOR but not Mullvad ( though if you server hop enough you can usually slip through )


perhaps I shouldn't share my workaround, but I've found that Mullvad's Norway nodes consistently get past Reddit's IP-blocking :)


I use obscura—which routes through mullvad—and the reddit problem is very annoying.

I finally hit the point of searching for mirrors yesterday and turns out, they exist.[0]

It’s really only suitable for lurking or being able to view search results, but it has eased the pain a bit.

0: reddit-viewer.com


> It’s really only suitable for lurking

If you're not just lurking, log in and reddit doesn't block you.


I've found the "visit anonymously" functionality offered by Startpage gets around the problem in a pinch. It tends to break the site you're visiting a little, but masks your IP, allowing you access without shutting down your VPN.


How do other providers avoid this issue? Do they keep changing IPs or is the traffic that comes out of Mullvad worse in quality somehow?


I'd also like to know.

I'd also like to ask people not to block this way. It creates LOTS of false positives. There's much better ways to handle bots and this tactic seems particularly dumb for Reddit given they want users from places like China or elsewhere where a VPN might be required. Not to mention people using public WiFi. It's not like VPNs are uncommon these days.

If you must ban IPa then do so with a timeout and easing function. So that each hit results in a longer ban time. Bots want to move fast so even a few seconds ban time will make them switch IPs while not impacting most users (who will refresh)


From my experience, PIA VPN and Proton VPN also get blocked everywhere, from Reddit to captchas on Google Search.


PIA it’s one of the least trustworthy VPNs, highly recommend getting a different one.


They purchase residential traffic exit from botnets.


Any proof or articles you could link to backup that claim seems unlikely given their size/reputation also would be surprised they’d get blocked this often using botnet traffic


The person you're replying to is claiming that providers other than Mullvad avoid the being-blocked-by-reddit issue by using residential IPs.


While using mullvad reddit doesn’t block access if you’re signed in.

So, login without mullvad, turn it on after that and it should work.


The question is not "how do you make reddit work over mullvad".

The question is "if reddit can block mullvad why can't China".


There's a corollary to that question: why would China choose not to block Mullvad? We know every large nation with a capable online force maintains a fleet of ORBs, so maybe they consider Mullvad more useful for them as a functioning system?

Some of their own contractors may well depend on Mullvad. Perhaps as long as the overall "civilian" volume and user count remains acceptably low, the cost-benefit estimate may well be in favour of letting it slip by. (And for the civilians that do use a working variant, subject their connections to fine-grained traffic analysis.)


my current mullvad endpoint seems to be blocked by flathub (blocking package updates). nixos wiki is also blocked


It sort of worked for me, but it was very unreliable. I tried Proton and Astrill, both of which worked much better.

Mullvad is pretty good overall though.


When they wrote that 3 providers were honest about all locations I have to admit my first thought was "Mullvad, and who would the other two be?"

With their reputation and trackrecord they really can't do any shady tricks. Imagine if they weren't among the 3 honest providers? That would be HN frontpage news.


While I pay for Mullvad directly through my bank, their account number approach built a lot of trust for me. "Here's your number, use whatever to fund it. 5 euro a month, no sales."


At risk of sounding sale pitch'y. Mullvad is the only VPN the longer I use the more I like it. I've tried MANY competitors first and all the other ones so far seem to only get worse over time.

I love that I can pay directly with a crypto wallet and have true anonymity.


I do really wish they still provided port forwarding, I understand why they don't but that was really useful and the only competitors that seem to don't exactly seem trustworthy to me.


crypto is a public ledger. If someone wanted to find you, that's pretty easy target.


That depends how you obtained the crypto in the first place.

In any case, its certainly better than visa, but if you dont trust your vpn provider the real issue is they have your IP address and at best just a pinky-promise they dont log.


They can find your wallet, but if your wallet is not linked to you in an obvious way...


I went in on Monero (which Mullvad accepts for now...)the only early crypto that had a viable usage plan from the beginning. That was of course before I realized that crypto would of course just be turned into a massive scam wheelhouse and any coin with real utility value to challenge fiat currency would of course be regulated against. (not salt its still worth a lot)

I am aware most crypto is not anon without extra effort.


AFAIK transacting with Monero in the EU is now illegal, and the law is pretty explicit that this is because it's untraceable.


Not all digital currencies work that way.


They accept Monero too


Depending on crypto, and even on public ledger ones, there are ways to on-ramp cash to a new cold wallet.


For payments, a cold wallet affects only its security, never its transparency. When you pay from it, you expose an IP.


So what if i say.... use my Mullvad vpn to pay from cambodia or something.


if the on-ramp to the cold wallet was cash then what good is that transparency.


One can cycle it through an encryption or obfuscation layer with a no-log crypto foreign VPN. The layer can be LTC MWEB / Monero / Bitcoin Mixer, etc.


Can also mail cash. But you get a 10% discount only on crypto.

> We accept the following currencies: EUR, USD, GBP, SEK, NOK, CHF, CAD, AUD, NZD.

Not a bad way to get rid of some spare currency lying about that you’ll incur a fee to localize anyway.


I knew they were going to pass the test before I even clicked the article link.


Has anyone else from Europe noticed how Mullvad's speeds and latency have becoming worse and worse during peak times in the recent months? I now have to change servers regularly, which was never the case ~2 years ago.


It has certainly been wildly variable for me.


Windscribe and iVPN up there with Mullvad in TFA.

> Mullvad ... security and privacy _very_ seriously. Not surprised to see them shine here.

? TFA reflects on dishonest marketing on part of public VPN providers more than privacy / security.

That said, VPNs don't add much security, though, they are useful for geo unblocking content and (at some level) anti-censorship. In my experience, the mainstream public VPNs don't really match up to dedicated censorship-resistant networks run by Psiphon, Lantern, Tor (and possibly others).


Advertising a VPN endpoint in country A which in reality is in country B is a security concern for users trying to reduce their visibility to country B’s authorities. You’re right about the more fit to purpose tools, of course, but they’re more of an impediment to normal internet usage.


> Advertising a VPN endpoint in country A which in reality is in country B is a security concern for users trying to reduce their visibility to country B’s authorities.

Mullvad in their Terms of Service say they'll abide by Swedish and EU laws. This, among other things, means a VPN is in no way going to save your bacon from "authorities".


miss my first laptop I had while interning in SF. Each sticker was its own memory


HIFI Labs (https://hifilabs.co) | Remote | Senior Fullstack Engineer / Engineering Manager

Join HIFI Labs and work on innovative projects with well known and iconic musicians. Past artist activations include Linkin Park, Jisoo / Zayn,Rüfüs Du Sol, Dua Lipa, and Mike Shinoda. We're looking for a Senior Fullstack Engineer passionate about design, user interactions, and privacy.

You'll work with TypeScript, React/Next.js, Firebase and explore new frameworks like Astro. Experience with Styled Components, continuous deployment and devops is a plus. We also play around with React Native / Expo.

Sound like a fit? Email us at pierre at hifilabs dot co


Sadly, this is the 3rd time everything is down when we're about to go live.

It's great that pages are still being served - but we are currently blocked by not being able to access our dashboard, configuring / prepping for a launch.

And we are enterprise customers - and I am not finding a way to reach out to customer support since .. the site is down.


Is there anything specific needed that you can’t do via CLI?


If the api is down how will the cli that relies on the api work?


wrote a similar comment - good to know for the future.


Sorry but I would flag this as AI-generated unless you can provide a reference.


The user definitely is not AI but I think they may've misread something or fell for a meme/joke they saw.

There indeed is absolutely no planned sequel to or continuation of Andor, nor currently any known plans for the creator of it to create anything else in this franchise. I'd sure like it if he did, though.


I might indeed have fallen for something. I trusted an untrustworthy source. Sorry


it can only be a prequel unless they want to make a season out of Rogue One movie


@dang what happened to this post? It was at the top like 30 mins ago and now it seems shadow-banned.


It was flagged by community members and downweighted (correctly) by a moderator for being a dupe:

Whistleblower details how DOGE may have taken sensitive NLRB datahttps://news.ycombinator.com/item?id=43691142

1139 points/7 days ago/528 comments


It's a separate writeup by a separate author though, and with 500+ comments, it still seems relevant. From #1 on HN to completely disappeared. Bring it back, I say.


On HN, dupeness is more a question of whether the underlying story is substantively the same or not—or, to put it slightly differently, whether the follow-up submission is able to support a substantively different discussion or not.

In this case, the answers appear to be yes, it's substantively the same story, and no, it can't support a substantively different discussion than the previous major thread. That's why we'd treat the follow-up submission as a dupe.

This is in no way passing judgment about the importance of the story! It's just that if we weren't careful and proactive about moderating HN in this way, the frontpage would rapidly fill up with variations on the hottest stories of the moment, and avoiding repetition is a core principle here (https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...).

I wrote a long explanation about exactly this the other day—if you (or anyone) is willing to take a look at that (assuming you have the stamina) and still have a question that isn't already answered there, I'd be happy to take a crack at it: https://news.ycombinator.com/item?id=43738815.

p.s. The current case is unfortunate because the follow-up/duplicate post came a week later than the original thread. If it were hours later, or a day or two later, as is more typical, we would merge the threads and in this way avoid a split discussion. But 7 days is too wide a chasm to merge across.


I suppose it's just a bit frustrating that HN is one of the few places left on the internet where we can have a mostly civilized discussion about politics. I had missed the discussion from 7 days ago so this was news to me (and I'm sure most of the other commenters). If you miss the one chance to discuss that one topic, it can never be discussed again on HN.

I'm not opposed to this rule for moderation, and I understand the reasoning behind it. But it seems like we're just watching the country burn and when stories like this get suppressed to make room for a new rust package manager, it makes me all nihilistic.

/rant


As one who shares your frustrations: working with the HN system, and pushing back where you feel it's appropriate, are both productive.

Dang (and earlier pg and sctb, and now I suspect tomhow) often express frustrations with the HN community's collective behaviour (a recent example: <https://news.ycombinator.com/item?id=43477305>). A key consideration is the fragility of the community and service itself (socially, not technically), as evidenced by, say, <https://news.ycombinator.com/item?id=23047709>, and even more revealingly here: <https://news.ycombinator.com/item?id=22805993>.

Your argument is likely not with their beliefs or preferences, but the embodied practices of HN moderation. Which can themselves be problematic as they have a strong status quo bias, as I've pointed out repeatedly:

<https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...>.

Which often manifests as tone policing, as again I've commented (some overlap with above search):

<https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...>

Consider reversing that bias a hacking challenge.


For what it's worth: if it's one of the few places you can still have a civilized discussion about politics, that's at least in part because we don't talk about politics very often here. Every time we do, some of the civility of the site chips away. Since the whole premise of the site is to investigate how long we can stave off Eternal September, this seems an important consideration.


> it can never be discussed again on HN

For sure it can, if and when significant new information arises. That's the main point of the principles outlined at https://news.ycombinator.com/item?id=43738815.

But yes, I hear you and I know it's frustrating. There's no important topic that HN really does justice to.


I've been looking for something like this for quite some time so really happy to see an open-sourced solution with a lot of happy users.

Will report back how the 3D-printing goes.


We were about to to buy a Bambu Lab printer but then learnt there will be new printers coming out in Q1 so naturally wanted to wait.

I need to educate myself on this a bit more on this issue, but it feels like the rest of the printer industry is just catching up with the X1C (looking at Creality K2 Plus)..

Do I wait for next-gen printers from Bambu Labs which I imagine will be quite revolutionary, or do I buy we buy a Creality K2 Plus, which basically is a X1C.


Have you taken a look at the Prusa Core One?


But bigger!


I watched this movie a couple of days ago and it really touched me. Might be that we just got a cute little cat. But the story-telling, visuals, animations.. It was just so very beautiful.

Please go see it.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: