frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Mullvad exit IPs are surprisingly identifying

https://tmctmt.com/posts/mullvad-exit-ips-as-a-fingerprinting-vector/
95•RGBCube•1h ago

Comments

gruez•40m ago
>Surprisingly, the exit IP you are given is not randomized each time you connect to the server, but deterministically picked based on your WireGuard key

What's the point of this? This seems more complicated to implement than mapping exit ips at the server level, so surely they must be doing this for a good reason?

arciini•36m ago
I'd guess that this is to ensure one abusive user doesn't get every other user blocked from a large service (say, Google) for botting over the VPN and constantly rotating IPs.

It's a practical measure, but definitely has a privacy cost though.

stevekemp•30m ago
It's possible that contributes, but to be honest most VPN users are split "privacy seeking" and "abusive". Though I grant you paid users are probably slightly more circumspect than users of Tor, etc.

It seems more likely this is just about load-balancing use against their available nodes.

tempest_•36m ago
I imagine there are a bunch of things on the internet that break if you start trying to connect to them from varying IP addresses. Things like the various CAPTCHA schemes and rate limiting etc, IP reputation etc.
lmm•20m ago
> I imagine there are a bunch of things on the internet that break if you start trying to connect to them from varying IP addresses. Things like the various CAPTCHA schemes and rate limiting etc, IP reputation etc.

Given how much of the world is stuck behind CGNAT now, I would expect any major sites to handle it.

wg0•36m ago
VPNs are snake oil. Exit IPs are a public information.
avazhi•32m ago
> Exit IPs are a public information.

Yes, obviously.

> VPNs are snake oil

Huh?

Cider9986•30m ago
VPNs are not snake oil. They transfer the trust of your internet activity from a place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad, IVPN, or Proton. Among other benefits. If you don't like your ISP creating a profile of you and selling it to target ads to you, you should use a VPN.

>Should I use a VPN?

Yes, almost certainly. A VPN has many advantages, including:

1. Hiding your traffic from only your Internet Service Provider.

2. Hiding your downloads (such as torrents) from your ISP and anti-piracy organizations.

3. Hiding your IP from third-party websites and services, helping you blend in and preventing IP based tracking.

4. Allowing you to bypass geo-restrictions on certain content.

(https://www.privacyguides.org/en/basics/vpn-overview/)

jesterson•23m ago
> place of low-trust, your ISP, to a place of high-trust, ideally a trustworthy VPN like Mullvad

This is highly subjective statement.

Almost all commercial VPN services farm and sell your data. Just by that, my ISP is definitely high trust point while any commercial VPN is a low trust.

sfdlkj3jk342a•17m ago
I can easily pay for a VPN service with crypto anonymously. I can also use a VPN run by a company outside my country of residence and jurisdiction.

Neither of those is possible with my ISP.

dakolli•2m ago
prepaid 5g sim cards and 5g modem.
applfanboysbgon•15m ago
Your ISP farms and sells your data too.

Most VPNs are untrustworthy, but unlike ISPs, you can choose from any VPN provider in the world, not just the two or three that are local to you. And there are VPN providers in the world that have been proven not to retain data by audits + actual court cases where the court determined that the VPN provider did not have the data authorities were seeking. Do your research and choose a court-proven VPN, it's that simple.

jojobas•9m ago
Now try saying that wearing some Russian or Chinese shoes.
bilalq•21m ago
Unfortunately, the largest and most well-marketed VPNs are, in fact, less trustworthy than your average ISP.
asdfsa32•10m ago
Exactly. Most ISP are subject to local laws at least; where a lot of these ISP are overseas in shady jurisdictions.
dewey•27m ago
> VPNs are snake oil

The most generous way of reading that would be the fact that every YouTube pushing for a VPN as an essential tool just to use the internet outside of your house without getting hacked is a big exaggeration or fear mongering but there's good reasons for using a VPN for a lot of reasons and it's not snake oil.

Cider9986•19m ago
I was just talking to a friend who believes that the feds poison privacy communities by spewing nonsense like this. I don't think wg0 is a fed, and my friend didn't have any proof for his claim. My feeling is that it is probably people acting like regular humans. They hear things, they have opinions and they don't provide proof or adhere to community norms. Eternal september or something. Regardless of if it's federal agents disrupting the discussion or human nature, the response should be the same—push back with proof, and demand proof and avoiding logical fallacies.

>Also. This is how they ruined any meaningful talks about privacy

There is so much noise

"Use braive. Don't use braive. Use vpn. Don't use vpn"

Then the debate spreads to all other aspects password managers, emails and etc

JoheyDev888•27m ago
Deterministic exit IPs let any site build a persistent profile across sessions. You're not eliminating tracking, just shifting who does it. Bad trade for a privacy VPN.
GalaxyNova•19m ago
Doesn't matter much as long as it is a pseudonymous identity
stingraycharles•12m ago
It’s also not that difficult to fix, so I expect a fix to roll out soon enough.
linkregister•27m ago
Given that Mullvad is basically a bulletproof VPN host[1], it would be great if site operators could rely on this property to enact bans. Given that the solution is simple (add a pseudorandom seed), Mullvad will likely push out a fix within a couple days.

1. It's the preferred VPN of TeamPCP.

VoidWhisperer•11m ago
> Surprisingly, the exit IP you are given is not randomized each time you connect to the server, but deterministically picked based on your WireGuard key, which rotates every 1 to 30 days (unless you use a third-party client, in which case it never rotates).

I'm a little confused on this... what is stopping third parties from doing key rotations like the main app clients if it is detailed in the repo how to do it?

lorenzohess•10m ago
The purpose of a VPN does not include anonymizing users with respect to the sites they visit,so it shouldn't be too surprising that Mullvad doesn't enforce unique exit IPs. Users who want anonymity should use networks like Tor.

Mullvad exit IPs are surprisingly identifying

https://tmctmt.com/posts/mullvad-exit-ips-as-a-fingerprinting-vector/
97•RGBCube•1h ago•23 comments

Removing the modem and GPS from my 2024 RAV4 hybrid

https://arkadiyt.com/2026/05/13/removing-the-modem-and-gps-from-my-rav4/
678•arkadiyt•10h ago•396 comments

A few words on DS4

https://antirez.com/news/165
201•caust1c•5h ago•63 comments

First public macOS kernel memory corruption exploit on Apple M5

https://blog.calif.io/p/first-public-kernel-memory-corruption
293•quadrige•9h ago•54 comments

RTX 5090 and M4 MacBook Air: Can It Game?

https://scottjg.com/posts/2026-05-05-egpu-mac-gaming/
511•allenleee•12h ago•139 comments

Codex is now in the ChatGPT mobile app

https://openai.com/index/work-with-codex-from-anywhere/
228•mikeevans•7h ago•109 comments

New Nginx Exploit

https://github.com/DepthFirstDisclosures/Nginx-Rift
315•hetsaraiya•10h ago•68 comments

Gyroflow: Video stabilization using gyroscope data

https://github.com/gyroflow/gyroflow
12•nateb2022•2d ago•0 comments

Tesla Wall Connector bootloader bypasses the firmware downgrade ratchet

https://www.synacktiv.com/en/publications/exploiting-the-tesla-wall-connector-from-its-charge-por...
74•p_stuart82•7h ago•28 comments

RISC-V Router

https://router.start9.com/
89•janandonly•7h ago•51 comments

More than sixty percent of the United States is experiencing drought conditions

https://news.vt.edu/articles/2026/05/drought-united-states-la-nina-expert.html
128•littlexsparkee•5h ago•56 comments

OVMS: Open source electric vehicle remote monitoring, diagnosis and control

https://www.openvehicles.com/home
47•BHSPitMonkey•6h ago•5 comments

UFerris a Versatile Learner Board for Rust Embedded Beginners

https://www.theembeddedrustacean.com/uferris
13•stmw•2h ago•3 comments

Porting 3D Movie Maker to Linux

https://benstoneonline.com/posts/porting-3d-movie-maker-to-linux/
90•speckx•3d ago•14 comments

New arXiv policy: 1-year ban for hallucinated references

https://twitter.com/tdietterich/status/2055000956144935055
361•gjuggler•7h ago•119 comments

HDD Firmware Hacking

https://icode4.coffee/?p=1465
147•jsploit•11h ago•17 comments

Rewrite Bun in Rust has been merged

https://github.com/oven-sh/bun/pull/30412
530•Chaoses•19h ago•621 comments

What's in a GGUF, besides the weights – and what's still missing?

https://nobodywho.ooo/posts/whats-in-a-gguf/
111•bashbjorn•10h ago•42 comments

Ontario auditors find doctors' AI note takers routinely blow basic facts

https://www.theregister.com/ai-ml/2026/05/14/ontario-auditors-find-doctors-ai-note-takers-routine...
152•sohkamyung•5h ago•69 comments

Infracost (YC W21) Is Hiring Sr Dev Advocate to make agents cloud cost-aware

https://www.ycombinator.com/companies/infracost/jobs/NzwUQ7c-senior-developer-advocate
1•akh•6h ago

LLM Policy for Rust Compiler

https://github.com/rust-lang/rust-forge/pull/1040
22•liyanage•4h ago•6 comments

Computer Hobby Movement in Canada

https://museum.eecs.yorku.ca/exhibits/show/hobby_canada/hobby_canada
191•rbanffy•14h ago•74 comments

Show HN: GridTravel- A community based travel app for users to share routes

https://www.gridtravel.app
29•knuaym9•5h ago•14 comments

Find vendors used by any company

https://sub-processors.com/subprocessor/elasticsearch
4•chatmasta•1h ago•0 comments

The Power of a Free Popsicle (2018)

https://www.gsb.stanford.edu/insights/power-free-popsicle
80•NaOH•9h ago•34 comments

Show HN: Race to the Bottom

https://race-to-the-bottom.onrender.com
40•maxwellito•13h ago•23 comments

A message from President Kornbluth about funding and the talent pipeline

https://president.mit.edu/writing-speeches/video-transcript-message-president-kornbluth-about-fun...
587•dmayo•13h ago•651 comments

Velonus – Open-source AppSec scanner that deduplicates SAST noise

https://github.com/AliAmmar15/Velonus
7•AliAmmar15•2h ago•1 comments

Fossils show millipede and centipede ancestors evolved legs underwater

https://phys.org/news/2026-05-ancient-sea-fossils-millipede-centipede.html
79•gmays•3d ago•2 comments

Amazonbot is finally respecting robots.txt

https://xeiaso.net/notes/2026/amazonbot-respecting-robots-txt/
147•xena•7h ago•33 comments