Hacker News new | ask | show | jobs
by shrimp_emoji 1039 days ago
Note that Mullvad's WireGuard settings offer a "multihop" feature, meaning the VPN destination your ISP sees and the VPN endpoint the end service sees differ.
1 comments

I'm not sure how that protects you though. ISP sees your traffic going into WG1. They know all of Mulvad's IPs, so isn't it just as easy to correlate that traffic when you exit through WG2?

/question from ignorance

Assuming the ISP monitors the entire network graph (your computer, the VPN server's activity, and the end service's server), you wouldn't. At that point, it's game over unless you're using mixnets or something.

If they merely monitor your computer and the end service, the correlation weakens a little with plausible deniability.

The real win is when the ISP adversary is monitoring your computer and the WG servers and NOT the end service. In that case, say they see you go to WG1, and then they see WG1 going to an end service. This is also correlation, and pretty undeniable. But say they see you go to WG1, then they see WG1 go to WG2, and they have no visibility of WG2's traffic. Then the tracking's broken; the footprints run off into the surf.

So multiple hops buy you defense in depth assuming it eventually gets you outside your adversary's monitoring range.

Equally ignorant response here :) How would they see that traffic? Why would the ISP be the same?