The attack surface is far larger than what you specified. Any networking equipment sotting between the client and server(s) can pick up and log IP addresses.
Knowing the online services one uses, and the times (to the millisecond) they used them goes a long way to deanonymize individuals. Correlating Internet routing events is very effective when combined with other data sources, like physical surveillance and knowing the exact times the target got home, or interacted with their phone after getting a DM alert.
The vulnerability enables clustering outgoing Mullvad traffic into user-sized buckets based on metadata analysis alone.
Clustering, in turn, allows time-based deanonymization[1], against the users assumptions of being sufficiently anonymized.
Adversaries who do not enjoy a backbone-traffic MitM vantage point cannot exploit this vulnerability, which makes it appear NOBUS-y.
1. Any *aaS, forum, or board, when given a (Mullvad!) IP address and series of request timestamps, and a subpoena, can yield PII on the real identity (email, phone, billing address)
but, to cluster this traffic, wouldn’t you need equipment between each and every mullvad exit node and each and every server the user access? Or at least a large proportion of it?
IP addresses are metadata - and don't require search warrants, meaning they are fair game for dragnet surveillance. Tapping into a backbone, a la Room 641A, can be used to cross-reference timestamped public posts on an anonymous message board to other data sources (e.g. subpoena Netflix for payer based of Netflix's access logs from VPN exit IPs)
please read the thread again. The parent said “it is not a high bar to own a website where a user is entering personal data”. I strongly disagree, although “high” is obviously not measurable.
Maybe I should again be more specific, again.
high bar for me is, you need to be a state sponsored hacker basically, or a large criminal organisation. Or a single, very skilled and high motivated person maybe.
Let me specify: The user must have entered his data on one site which the attacker has control of. That is a high bar still.