← Back to context

Comment by ignoramous

2 years ago

> it doesn't apply to us

This is also what your website says,

  But it could be interpreted contrarily - that VPN services through, for example, encryption via signals that the VPN service itself has power over through agreements with subcontractors, etc. could possibly be seen as an electronic communications service ...

And I'm not just talking about Mullvad VPN (the "electronic communication service" provider), but Mullvad AB, which also hosts websites and builds apps (like the browser and VPN clients), too.

So, is the "law doesn't apply" a fact? If so, may want to reword this bit on your website to make that much clear:

  [Mullvad's] opinion is that the reasonable interpretation is that a VPN service is not to be considered as an electronic communications service based on previous legislative history.

If not, due to the "covert" nature of the Act, if Mullvad was coerced to co-operate with the govt, it seems Mullvad couldn't even publicly talk or hint about it (like warrant canaries, for example)?

I'm writing this on my phone and for whatever reason can't find the passages that you're quoting. Are they in the same article that I linked?

In any case, to my knowledge the law in question doesn't apply to us. If the Swedish government tried to argue otherwise we'd get our lawyers involved.

Having said all of this, I am concerned about National Security Letters and similar concepts. Technologies like reproducible builds, transparency logs, and remote attestation can help there.

  • Thanks.

    > Are they in the same article that I linked

    https://mullvad.net/en/help/new-law-for-electronic-communica... / https://archive.vn/86hGz

    > to my knowledge the law in question doesn't apply to us

    Fair. This isn't the official Mullvad position, then (which is that the law may apply)?

    The "Communication provider" part aside, another source (quoted above) makes it explicit that backdooring "websites" (Mullvad has a website) are fair game, btw.

    > If the Swedish government tried to argue otherwise we'd get our lawyers involved

    I don't doubt you would. Given the "covert" nature of the Act, Mullvad's arguments & Sweden's counter-arguments and the outcome from it (backdoors, compromises, coercion etc) will be kept a state secret. That is, there doesn't seem to be a way for the public to independently ascertain the claim that the Mullvad did fight and indeed "the law didn't apply"? [0]

    > reproducible builds, transparency logs, and remote attestation

    Much needed (:

    Per Mullvad's posts, the Act seems to grant wide-ranging powers to Swedish authorities, including installing hardware & other sorts of physical compromises (which no amount of software mitigations would thwart, I don't think).

    [0] Focusing on the premise: "Forced by government: Here I'd say look at the jurisdictions of the orgs."

    • > Fair. This isn't the official Mullvad position, then (which is that the law may apply)?

      I'm pretty sure our official position is that it doesn't apply, rather than it may apply. Note that the article on our website that I quoted is more recent than the one you quoted. I can't find a more recent legal opinion than that.

      Regarding backdooring websites, that's interesting. I'll have to ask someone about that. Thanks.

      > the outcome from it (backdoors, compromises, coercion etc) will be kept a state secret

      I am not a legal expert, but I'm pretty sure you're wrong. The first-order outcome would be a court case that says the law applies to VPNs, or not. The second-order outcome would be secret coercion in a specific criminal case, or nothing. The first-order outcome would be public. Interesting question though. I'll have to ask about this too.

      > Much needed (:

      Yes. :)

      It might interest you to know that I've spent the past six years working on things like that. My role at Mullvad since several years is only strategic, as I spend almost all of my time on applied research. See glasklarteknik.se and tillitis.se.

      > (which no amount of software mitigations would thwart, I don't think)

      Physical security is hard. However, I see no reason to limit ourselves to only software-based mitigations.

      1 reply →

It is worth noting that your second quote is from a blog posted in May 2020, and the link that kfreds posted is from their follow-up blog post, dated July 2020.