Live data from Hacker News

Mullvad: Diskless infrastructure using stboot in beta

mullvad.net

11–20 of 135 posts

Re: Mullvad: Diskless infrastructure using stboot in beta

#11
post #4
post #3

This is hardly a new thing in VPN providers though. I know that perfect privacy[1] and azire vpn[2] both advertise this feature already. [1] https://www.perfect-privacy.com/en/features/without-logs [2] https://www.azirevpn.com/docs/environment

if only there was any proof of this actually being the case and there not being some "accidental" debug log enabled, or some other network level component having "accidental" access to the keys. There's just no good answer to perfect trust-no-one private internet access. If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your ow…

Wouldn't the ownership of the server be easy to trace back to you?

PIA has been promising a fully audited and verifiable infrastructure in the future:

https://www.privateinternetaccess.com/blog/dont-trust-verify...

Re: Mullvad: Diskless infrastructure using stboot in beta

#12
post #9
post #6

Earlier quoted context omitted.

That is the great thing about mullvad. They don't have shareholders except the actual owners. https://mullvad.net/en/blog/2021/9/16/ownership-and-future-m...

which is true until one or more of their owners decide to sell their shares.

my grocer down the road is a nice fella and has tasty vegetables from sustainable sources, but he might get bought up by a big supermarket chain, so I'm not going to buy from him

Re: Mullvad: Diskless infrastructure using stboot in beta

#13
post #4
post #3

This is hardly a new thing in VPN providers though. I know that perfect privacy[1] and azire vpn[2] both advertise this feature already. [1] https://www.perfect-privacy.com/en/features/without-logs [2] https://www.azirevpn.com/docs/environment

if only there was any proof of this actually being the case and there not being some "accidental" debug log enabled, or some other network level component having "accidental" access to the keys. There's just no good answer to perfect trust-no-one private internet access. If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your ow…

>> If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your own VPN endpoint on a server you control which provides better privacy guarantees compared to a centralised commercial VPN whose business model will eventually involve selling your data (once user growth stops but shareholders demand continued revenue growth).

the privacy protection for most people using VPNs is required against their ISP and other actors looking to analyse their traffic, not users on the local network. a commercial VPN will be better for privacy due to the crowding effects, ie. large number of users sharing the same IP and protects against correlation attacks - it's much easier to trace the activities on your own VPN endpoint back to you. of course you need to trust the operators, which is as different question.

Re: Mullvad: Diskless infrastructure using stboot in beta

#14
post #4

Earlier quoted context omitted.

if only there was any proof of this actually being the case and there not being some "accidental" debug log enabled, or some other network level component having "accidental" access to the keys. There's just no good answer to perfect trust-no-one private internet access. If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your ow…

Wouldn't the ownership of the server be easy to trace back to you? PIA has been promising a fully audited and verifiable infrastructure in the future: https://www.privateinternetaccess.com/blog/dont-trust-verify...

>Wouldn't the ownership of the server be easy to trace back to you?

yes. Which is why I said that this helps to shield your traffic from other people in your current local network (think: coffee-shop) which is one use-case of a VPN.

If you need to protect your traffic from anybody but your peer (another potential use-case of a VPN if this were possible) and you even want to hide the fact that you were talking to that peer, then you're out of luck. Period.

Re: Mullvad: Diskless infrastructure using stboot in beta

#15
post #10

For people wondering how the hell a user can audit the server is diskless or whatever, the goal appears to be using TPM to provide remote attestation for all code in the boot path. See https://www.system-transparency.org/ .

How do we audit that the TPM chip is secure? What happened when a bug in the silicone is found later?

Re: Mullvad: Diskless infrastructure using stboot in beta

#16
A bit tangential to the main post, but I'd to share a recent positive experience with Mullvad:

I am a regular user of Mullvad and recently wanted to try a different VPN, that only provides Wireguard configs (i.e. no native app). I used the default setup.

For some reason, my internet connection was flaky, and when it disconnected and reconnected, my traffic leaked.

That never happened to me with Mullvad as the app comes with an "Always require VPN" option out of the box and it has always worked reliably.

Re: Mullvad: Diskless infrastructure using stboot in beta

#17
post #10

For people wondering how the hell a user can audit the server is diskless or whatever, the goal appears to be using TPM to provide remote attestation for all code in the boot path. See https://www.system-transparency.org/ .

I hate to be this skeptical, but let's say this is 100% possible (I have my doubts, see previous attacks on things like TPMs and SGX, but I digress). You probably could get 90% of the logging capability by putting monitoring in front of and behind the server, and associating connections by traffic/time.

It just seems like this goal of using technology to prove they're trustworthy is unlikely to actually work for a VPN company due to the threat models.

Re: Mullvad: Diskless infrastructure using stboot in beta

#18
post #4
post #3

This is hardly a new thing in VPN providers though. I know that perfect privacy[1] and azire vpn[2] both advertise this feature already. [1] https://www.perfect-privacy.com/en/features/without-logs [2] https://www.azirevpn.com/docs/environment

if only there was any proof of this actually being the case and there not being some "accidental" debug log enabled, or some other network level component having "accidental" access to the keys. There's just no good answer to perfect trust-no-one private internet access. If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your ow…

> If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your own VPN endpoint on a server you control which provides better privacy guarantees compared to a centralised commercial VPN whose business model will eventually involve selling your data (once user growth stops but shareholders demand continued revenue growth).

Well not really. There was a great (german) interview with the perfect privacy founders recently [1]. They seem to be decent guys with close ties to the Chaos Computer Club and I strongly suspect they wouldn't want to work like that.

[1] https://www.youtube.com/watch?v=VMr0gJvI-6I

> But if you need to hide your traffic from anybody but your peer on the internet and you need to hide the fact that you talked to that peer, then, I'm afraid, your out of luck.

Nah, that one is easy just use an anonymous sim card or an open wifi and your good to go.

Honestly these discussions often feel pretty asinine to me. I personally use paid VPNs to pirate to my hearts content, work around my ISPs terrible networking and a little bit of geo-unblocking. Of course you can't use these services to protect yourself from three letter agency type surveillance or equally powerful threat actors but if they are "private" enough to block the music industry and their lawyers from suing you that's a pretty high standard of privacy, certainly more than any ISP alone gives you!

Re: Mullvad: Diskless infrastructure using stboot in beta

#19
post #10

For people wondering how the hell a user can audit the server is diskless or whatever, the goal appears to be using TPM to provide remote attestation for all code in the boot path. See https://www.system-transparency.org/ .

How do we audit that the TPM chip is secure? What happened when a bug in the silicone is found later?

We assume it is, just like we assume CPU works as advertised. In other words, TPM is part of TCB.

Re: Mullvad: Diskless infrastructure using stboot in beta

#20
post #19

Earlier quoted context omitted.

How do we audit that the TPM chip is secure? What happened when a bug in the silicone is found later?

We assume it is, just like we assume CPU works as advertised. In other words, TPM is part of TCB.

So what is the point? I already assume the code on their server is not malicious by using it. What extra trust does an untrusted TPM chip give me?
Post reply on HN