Hacker News new | ask | show | jobs
by vmoore 1734 days ago
> For comparison, mullvad accounts have no separate identification and authentication

Yeah this was a huge learning curve for me. When you use a Mullvad OpenVPN config file, the username is your account number, and the password is the account number too.

All a bad actor has to do is enumerate account numbers programmatically and they could potentially own hundreds of accounts, although generating those would be difficult and a lot of it relies on chance.