HeadlinesBriefing favicon HeadlinesBriefing.com

Mullvad VPN's Exit IP Flaw

Hacker News •
×

Mullvad VPN assigns exit IPs deterministically rather than randomly, creating a privacy vulnerability. Researchers discovered users receive IPs in predictable percentiles across different servers, reducing potential combinations from trillions to just 284. This pattern stems from the VPN's implementation of Rust's random number generator.

The flaw allows correlation attacks that could deanonymize users across different sessions. When a banned user creates a new account, moderators can compare IP ranges with >99% accuracy to identify sockpuppets. The vulnerability persists even when users switch servers if they don't rotate their WireGuard key.

Users can mitigate this risk by avoiding frequent server switches and regularly rotating their public key through the Mullvad app. While the vulnerability affects anonymity, it doesn't compromise encryption or reveal actual identities—just correlation between different sessions from the same user.