| Age | Commit message (Collapse) | Author | Files | Lines | |
|---|---|---|---|---|---|
| 2025-10-03 | Add a SECURITY.md security policy | Linus Färnstrand | 1 | -2/+5 | |
| 2025-07-23 | Improve security docs around TLS connection to API server | Linus Färnstrand | 1 | -1/+6 | |
| 2025-06-25 | Add Mullvad VPN loader thret at model document | David Lönnhager | 1 | -0/+3 | |
| Mention threat model in security.md Co-authored-by: Markus Pettersson <markus.pettersson@mullvad.net> | |||||
| 2024-12-12 | Enhance naming of Unix and JavaScript at security.md | LamTrinh.Dev | 1 | -2/+2 | |
| 2024-11-07 | Update documentation regarding WSL/Hyper-V | David Lönnhager | 1 | -1/+0 | |
| 2024-10-18 | Add dedicated "known issues" document | Linus Färnstrand | 1 | -19/+10 | |
| Moves some known issues out of the security document. Keeps all known issues in one place. Allows the security document to be more focused on the app threat model and how it intend to solve that threat model. The security document is a more static document that should rarely change. While the known issues document will grow and shrink as new special cases are found and fixed. | |||||
| 2024-10-18 | Remove outdated statement about iOS blocked state | Linus Färnstrand | 1 | -1/+0 | |
| 2024-10-16 | Update Android security docs | David Göransson | 1 | -18/+35 | |
| 2023-03-27 | Fix many typos | Alexander Seiler | 1 | -1/+1 | |
| Signed-off-by: Alexander Seiler <seileralex@gmail.com> | |||||
| 2022-10-20 | Update security docs | Emīls Piņķis | 1 | -0/+8 | |
| 2022-10-04 | Document Android leaks reported in MUL22-03 | Albin | 1 | -7/+21 | |
| 2022-09-27 | Document Android shortcoming | Emīls Piņķis | 1 | -2/+2 | |
| 2022-09-27 | Update security docs | Emīls Piņķis | 1 | -5/+20 | |
| Due to recent changes to the daemon to prevent early and late boot leaks, the security docs need to be updated to reflect the new behavior. | |||||
| 2022-08-29 | Allow admin-local v4 multicast range when LAN sharing is enabled | David Lönnhager | 1 | -3/+3 | |
| 2022-04-05 | Delete all references to Shadowsocks binaries | David Lönnhager | 1 | -1/+1 | |
| 2022-01-14 | Simplify custom resolver to not leak any traffic | Emīls | 1 | -13/+0 | |
| 2021-12-13 | Allow only root to reach the API in blocked state | Emīls | 1 | -4/+5 | |
| 2021-12-10 | Update docs | Emīls | 1 | -1/+2 | |
| 2021-12-10 | Add custom-resolver docs | Emīls | 1 | -0/+13 | |
| 2021-12-08 | Update security document for allowed endpoint fix | David Lönnhager | 1 | -1/+7 | |
| 2021-10-11 | Update macOS firewall impl to closer match spec around NDP | Linus Färnstrand | 1 | -5/+0 | |
| 2021-10-11 | Update security document | David Lönnhager | 1 | -3/+7 | |
| 2021-06-07 | Update security document | David Lönnhager | 1 | -5/+2 | |
| 2021-04-16 | Update security document | David Lönnhager | 1 | -0/+5 | |
| 2020-10-22 | Describe custom DNS in the security document | David Lönnhager | 1 | -7/+9 | |
| 2020-10-12 | Explain persistent filters in the security document | David Lönnhager | 1 | -0/+15 | |
| 2020-10-12 | Rename 'Block when disconnected' in the security document | David Lönnhager | 1 | -4/+4 | |
| 2020-09-02 | Use a mark to whitelist tunnel traffic | Emīls | 1 | -2/+5 | |
| 2020-06-23 | Update security document with restrictions to allow relay rule | Linus Färnstrand | 1 | -3/+13 | |
| This fixes audit finding MUL-02-002 and MUL-02-004 | |||||
| 2020-04-03 | Allow fc00::/7 instead of fd00::/8 for unique local addresses | Linus Färnstrand | 1 | -1/+1 | |
| 2020-03-16 | Update security documentation | David Lönnhager | 1 | -5/+9 | |
| 2020-02-26 | Fix typo in docs/security.md | Chandradeep Dey | 1 | -1/+1 | |
| 2020-01-29 | Rename blocked state to its new name, error | Linus Färnstrand | 1 | -5/+9 | |
| 2020-01-29 | Clarify that the user explicitly sends problem reports | Linus Färnstrand | 1 | -1/+1 | |
| 2020-01-07 | Fix according to feedback | Linus Färnstrand | 1 | -8/+9 | |
| 2020-01-07 | Improve mobile section. Mostly iOS | Linus Färnstrand | 1 | -7/+9 | |
| 2020-01-07 | Shorten text on "kill switch" | Linus Färnstrand | 1 | -7/+4 | |
| 2020-01-07 | Add section on desktop GUI and system service | Linus Färnstrand | 1 | -1/+25 | |
| 2020-01-07 | Slightly clarify on DNS | Linus Färnstrand | 1 | -4/+4 | |
| 2020-01-07 | Mention again that firewall rules are changed atomically | Linus Färnstrand | 1 | -7/+9 | |
| 2020-01-07 | Clarify and be more exact regarding allowing traffic to VPN server | Linus Färnstrand | 1 | -6/+12 | |
| 2020-01-07 | Describe rules for IPv6 NDP better | Linus Färnstrand | 1 | -2/+3 | |
| 2020-01-07 | Clarify always allowed traffic | Linus Färnstrand | 1 | -4/+4 | |
| 2020-01-07 | Add dot | Linus Färnstrand | 1 | -1/+1 | |
| 2020-01-07 | Remove "always allowed traffic" header | Linus Färnstrand | 1 | -2/+0 | |
| 2020-01-07 | Clarify what "that" is | Linus Färnstrand | 1 | -2/+2 | |
| 2020-01-07 | Add initial macOS deviations | Linus Färnstrand | 1 | -0/+5 | |
| 2020-01-07 | Restrict DHCP rules to only allow over UDP | Linus Färnstrand | 1 | -6/+7 | |
| 2020-01-07 | Small fixes | Linus Färnstrand | 1 | -2/+2 | |
| 2020-01-07 | Add section on Android | Linus Färnstrand | 1 | -1/+10 | |
