Mullvad Blog: Hiding account numbers (mullvad.net)
from Kalcifer@sh.itjust.works to privacy@lemmy.ml on 28 May 2024 03:01
https://sh.itjust.works/post/19988162

Cross-posted from: sh.itjust.works/post/19987854


We have previously highlighted the importance of not losing your account number, encouraging it to be written down in a password manager or similar safe location.

For the sake of convenience account numbers have been visible when users logged into our website. This had led to there being potential concerns where a malicious observer could:

  • Use up all of a user’s connections
  • Delete a user’s devices

From the 3rd June 2024 you will no longer be able to see your account number after logging into our website.


#privacy

threaded - newest

Dsklnsadog@lemmy.dbzer0.com on 28 May 2024 03:10 next collapse

If someone is spying your PC you have bigger problems than your VPN account being stolen.

087008001234@lemmy.ml on 28 May 2024 03:44 next collapse

…streamers…??? i guess

socphoenix@midwest.social on 28 May 2024 04:13 next collapse

This might be a change due to that new Microsoft recall program

todd_bonzalez@lemm.ee on 28 May 2024 05:21 next collapse

I think the issue is that someone could physically look at your screen and walk away with the account number, not that they might have remote access.

Creat@discuss.tchncs.de on 28 May 2024 10:29 collapse

Since the other comment didn’t Go into detail: Microsofts “Recall” will so that on every Windows 11 PC soon. Literally index everything you do or look at, OCR-ing periodic screenshots. Also storing them, possibly including sensitive information like this.

nivenkos@lemmy.ml on 28 May 2024 12:01 collapse

Then your bigger problem is using Windows…

Creat@discuss.tchncs.de on 28 May 2024 12:13 next collapse

Yup, it would be. But many people are, so they changed that it’s displayed at all by default.

possiblylinux127@lemmy.zip on 28 May 2024 19:29 collapse

Well

[deleted] on 28 May 2024 04:58 next collapse
.
Scolding0513@sh.itjust.works on 28 May 2024 05:00 next collapse

why dont you guys do something useful like come up with a MFA powered contingency plan for people who get their ID stolen

or maybe actually come out with multihop on android?? lol

nul9o9@lemmy.world on 28 May 2024 05:36 collapse

MFA kinda defeats the purpose of Mullvad. The less they know about you the better.

mortalglowworm@reddthat.com on 28 May 2024 06:13 next collapse

A FIDO2 hardware key should do the trick. Not all MFA are based on communications.

viking@infosec.pub on 28 May 2024 06:35 collapse

You can’t use those on a router, and they are painful on mobile.

mortalglowworm@reddthat.com on 28 May 2024 06:43 next collapse

That was not the argument above, was it?

What kind of MFA you can use on a router, BTW?

I have a FIDO2 with Nfc, and it works. Is it convenient? No. Is it more secure? Yes.

loudWaterEnjoyer@lemmy.dbzer0.com on 28 May 2024 11:10 collapse

Why can’t you use FIDO2 hardware keys on a router? I have a PC running openBSD as a Router and I can use hardware keys.

viking@infosec.pub on 28 May 2024 14:08 collapse

So you are running a full-fledged OS on a standalone computer that functions as a router. An actual router has a very limited operating system with no such functionality, plus it’s always online by design, so you’d basically have to have a key that is permanently plugged in; or depending on the setup you’d have to re-authenticate ever so often. Not exactly great considering most routers are hidden somewhere in an inaccessible corner.

loudWaterEnjoyer@lemmy.dbzer0.com on 28 May 2024 19:19 collapse

It’s nothing fancy I just needed more CPU power on my router. I’m not saying it makes sense to use a hardware key to access the internet on router level, I’m just saying it works.

openBSD is actually kinda common base for routers. Also why would I hide a router in some inaccessible corner?

Scolding0513@sh.itjust.works on 28 May 2024 06:33 next collapse

6 digit totp is totally anon

possiblylinux127@lemmy.zip on 28 May 2024 19:27 collapse

You could use open time based codes

geography082@lemm.ee on 28 May 2024 12:40 collapse

All good, but mullvad should work on more rotation of server IPs or find a solution from alltheir banned server by big techs . Nearly 90% of their servers are blocked to do common internet tasks .

Alphane_Moon@lemmy.ml on 28 May 2024 13:37 next collapse

Is it really that bad? I let my NordVPN subscription lapse as I didn’t need it due to personal matters, I’ve heard a lot of good things about Mullvad and was considering them as my VPN provider.

mectag@feddit.de on 28 May 2024 18:27 next collapse

It’s exaggerated. I believe most services are generally more sceptical about users with a known VPN connection. But yeah, I think you‘ll have some hiccups when browsing with a VPN on no matter the provider, or did you have a different experience with NordVPN (I‘m legit curious)?

Alphane_Moon@lemmy.ml on 28 May 2024 19:12 collapse

I did have occasional issues with using a VPN and it was clear services were somewhat suspicious about me (very aggressive use of CAPTCHAs, additional login validation etc.).

That being said, outside of netflix (circumventing region-lock), I never had any issues with outright loosing access to tech oligopoly services.

mectag@feddit.de on 31 May 2024 08:50 collapse

Ah okay! Yeah that’s basically my experience with Mullvad. Anyways, you can try it out and if you don’t like it just don’t pay $5 for another month. 🤷‍♂️

geography082@lemm.ee on 28 May 2024 21:35 collapse

With protonvpn, are the the best vpns . And I tested all the services believe me. But the big issue mullvad have is IP bans. The rest is almost perfect . Ah and the problem with port forwarding, suddenly they decided to remove that service , with reason because people were abusing of it. But instead of just remove it one day to another, with no previous notification to the users and not giving an alternate option, felt very rough .

Kalcifer@sh.itjust.works on 31 May 2024 10:46 collapse

Nearly 90% of their servers are blocked to do common internet tasks .

Perhaps your browsing habits are severely impacted by Mullvad being blocked, but that doesn’t seem to be the universal case. I’ve had the occasional hiccup with a few sites that block VPNs (Mullvad’s IPs), but “90%” is quite an exaggeration when compared to my personal experience.