Does your privacy setup actually make you stand out more?

For the past month and a half I’ve been trying out some VPN services on my phone, trying to see which one works better for my use case. Most recently I’ve installed and been running Mullvad.

I pretty regularly log in to my work email on my phone via the browser. Last week I received a message from IT saying they have detected a connection to my account “from an IP address associated with Mullvad VPN.” Could I please confirm that it was indeed me, and if yes, why was I “using a VPN service for this specific connection?”

In the weeks preceding this, I was trying out IVPN and Windscribe. I always set all services to connect only to the servers in my country, this specific scenario being one of the reasons why. There were no questions about the other providers servers, yet the one about Mullvad arrived immediately.

This didn’t make me feel exactly “private” lol. I mostly use VPN to keep my ISP out of the loop. Yes, in retrospect I understand that it’s just generally not a great idea to be connecting to work accounts on a commercial VPN, that much is clear however I just honestly didn’t think about it at all.

All this to say, if you use a more established privacy-oriented service, be it VPN or other.. could that actually make you an unwitting target of more inspection or noticeability, in whatever context? What do you guys think

1 Like

VPNs should trigger any good companies’ monitoring - because that’s exactly how a potential attacker would exfiltrate from a compromised account, if they don’t have residential proxies at hand. Additionally, even though MullvadVPN is a legitimate service, a certain percentage of their customers - who use the same servers as you - will be using it for mischief.

So the usual recommendation stands: don’t log into your bank account or work accounts from a commercial VPN server.

3 Likes

I login to my US financial accounts with proton vpn all the time. I do it purposely. Here’s why:

  • I trust proton more than my isp.
  • I often am looking up relevant things in another browser while my account is open, and I prefer my vpn to be on for those searches.
  • If I turn it off, I might forget to turn it back on.
  • I already delete cookies and site data between sessions anyway, so there’s no loss in convenience of having to fully re-authenticate each time when they see me logging in from a different IP.
  • I rarely have issues logging in and if I do, changing the server usually fixes it. I always make sure to pick a server in the same US state as my legal address.
  • If I ever make the move to become an expat or to become nomadic, I’ll need to use a VPN to login to my accounts anyway. Many US financial institutions block traffic from other countries if you try to login and due to overcompensating Patriot Act compliance, many have it baked into their terms that they will close your accounts if they discover you don’t live in the US anymore. You’re basically forced to use a VPN if you go this route. It’s a mess. I want to show a pattern that I regularly use VPNs now so it doesn’t look suspicious later.
2 Likes

Mullvad is cheap, anonymous, and easy to share with other people. It has become popular among cyber criminals, you will get laughed at for using anything besides mullvad in those communites. All their exit IP’s are associated with abuse and are heavily flagged in threat intelligence feeds.

2 Likes

Mullvad is not cheap. There are pleanty other VPN providers that are more affordable. To name a few that were already mentioned in this thread, Proton VPN and Windscribe.

If this is about accepting Monero, I would not be surprised if in a year from now they stop accepting it because Europe citzens won’t be allowed to buy Monero anymore. The only option may be cash.

5 simultaneous connections, basically, if you have a phone, a pc and a tv you are already using 3 of those.

Not my area, I’ll take your word.

Someone can correct me here but I feel that most popular VPNs have IPs that are flagged. That is why we get so many captchas when browsing websites. Companies probably have access to those lists of IPs to flag exfiltration.

4 Likes

Mullvad intentionally publishes a complete, real-time public server list (including ownership status and providers) so that probably doesn’t help.

The price of a VPN should be based off it’s monthly price not yearly discounts.

3 Likes

I’ve always tried to tunnel my VPN connection through Cloudflare WARP, so the resulting traffic would look more “normal” and less likely to get flagged.

1 Like

Here’s a source backing that up. Script kiddies or cybercriminals, your choice though.

3 Likes

Yes.

So this led me down a bit of a rabbit hole, and I will preface with: I realize this a comment, and not a full-blown exposé of the EU Anti- Money Laundering framework (which is the legal framework that I think you’re referring to). So I’m mostly expanding here, for the benefit of other readers.

It is not likely that the AML framework will make it illegal for EU citizens to buy Monero, but instead make it illegal for financial institutions of various kinds (expanded on in a quotation below) to sell Monero. This is close to, but not quite exactly the same as making it illegal to buy, because EU citizens can still purchase Monero from one another. It will certainly be more challenging to obtain in general. Below is a small summary, from this article on “The Defiant” (I can’t vouch for their journalistic integrity, I do not follow their publications).

New AML regulations specifically forbid credit institutions, financial institutions and crypto asset service providers (CASPs) from maintaining or working with anonymous accounts or anonymity-enhancing cryptocurrencies, according to the AML Handbook, recently published[1] by the European Crypto Initiative (EUCI).

...

The handbook notes that these restrictions do not apply to hardware or software providers, or to makers of self-hosted wallets, as long as they don’t have access to or control of those wallets themselves. Existing anonymous accounts will have to undergo customer due diligence before they can be used when the rules take effect.

The guidelines are not all crypto-related. Anonymous bank and payment accounts, passbook accounts and safe-deposit boxes must follow the same AML rules.

...

[1]: note mine, article’s hyperlink to publication removed because the forum would not allow me to post a link to the EUCI’s publication on Canva’s website.

It seems to (from a little more reading I have done) also require that the same financial institutions employ various (seemingly rather arduous) checks and on-going surveillance of their cryptocurrency customers to track patterns and report fraud, money laundering, general criminal activity.

I’m honestly a bit shocked by that kind of legislation, but it is in line with the vast amount of anti-privacy/pro-surveillance legislation we’ve seen coming out of … basically everywhere. It’s rather disappointing, and I wish the “it makes catching criminals easier” line of reasoning weren’t seemingly so effective in convincing people to not punish their representatives for eroding their privacy.

Anyway, thank you for mentioning this. It was an interesting read. I am, for once (in this way specifically), glad I don’t live in the EU.

If we think about the resistance to chat control which is universally opposed by many on the know and then consider how many of the people that oppose chat control hate or dislike crypto, it’s indeed a sad situation. There’s not enough people to defend it.

Even many people in crypto are using it transparently and custodially.

And it’s exact bad reputation are created by these people.

Actually extremely sad if you think about Satoshi’s dream of freedom money to how it’s been co-opted and mutillated.

1 Like