A bit tangential to the main post, but I'd to share a recent positive experience with Mullvad: I am a regular user of Mullvad and recently wanted to try a different VPN, that only provides Wireguard configs (i.e. no native app). I used the default setup. For some reason, my internet connection was flaky, and when it disconnected and reconnected, my traffic leaked. That never happened to me with Mullvad as the app com…
Mullvad: Diskless infrastructure using stboot in beta
21–30 of 135 posts
Re: Mullvad: Diskless infrastructure using stboot in beta
#22A bit tangential to the main post, but I'd to share a recent positive experience with Mullvad: I am a regular user of Mullvad and recently wanted to try a different VPN, that only provides Wireguard configs (i.e. no native app). I used the default setup. For some reason, my internet connection was flaky, and when it disconnected and reconnected, my traffic leaked. That never happened to me with Mullvad as the app com…
Re: Mullvad: Diskless infrastructure using stboot in beta
#23Earlier quoted context omitted.
We assume it is, just like we assume CPU works as advertised. In other words, TPM is part of TCB.
So what is the point? I already assume the code on their server is not malicious by using it. What extra trust does an untrusted TPM chip give me?
Re: Mullvad: Diskless infrastructure using stboot in beta
#24Re: Mullvad: Diskless infrastructure using stboot in beta
#25Also, isn't there a law that enforces logs to be kept for n years ? How is it compatible with diskless setup ?
Re: Mullvad: Diskless infrastructure using stboot in beta
#26For people wondering how the hell a user can audit the server is diskless or whatever, the goal appears to be using TPM to provide remote attestation for all code in the boot path. See https://www.system-transparency.org/ .
Here are some additional details for those interested. We intend to make use of TPM for remote attestation of the current boot chain, reproducible builds to provide a strong link from source code to build artifacts, and a transparency log for a historical record of previously used boot chains, artifacts, WireGuard server keys, and related signatures.
As dtx1 mentioned elsewhere in this thread, diskless VPN infrastructure is currently in use by many other VPN providers. That is not a novel feature of course. What is novel is user-auditability of running VPN infrastructure. We were the first VPN provider to state our intention to make our infrastructure user-auditable AND provide a realistic roadmap with the specific technologies needed to do so. See the link above.
I believe the technologies we use in System Transparency will ultimately reshape the VPN provider industry into a highly competitive space focused on maximizing the transparency of VPN infrastructure. Or not, but at least OUR users will be able to audit us. :)
Either way we’re looking forward to the future. The opportunity for improvement is immense.
Re: Mullvad: Diskless infrastructure using stboot in beta
#27Earlier quoted context omitted.
if only there was any proof of this actually being the case and there not being some "accidental" debug log enabled, or some other network level component having "accidental" access to the keys. There's just no good answer to perfect trust-no-one private internet access. If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your ow…
> There's just no good answer to perfect trust-no-one private internet access. What about Tor?
Re: Mullvad: Diskless infrastructure using stboot in beta
#28Earlier quoted context omitted.
if only there was any proof of this actually being the case and there not being some "accidental" debug log enabled, or some other network level component having "accidental" access to the keys. There's just no good answer to perfect trust-no-one private internet access. If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your ow…
> If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your own VPN endpoint on a server you control which provides better privacy guarantees compared to a centralised commercial VPN whose business model will eventually involve selling your data (once user growth stops but shareholders demand continued revenue growth). Well not re…
Re: Mullvad: Diskless infrastructure using stboot in beta
#29Earlier quoted context omitted.
Is no-trust ever possible? I thought people create their threat models and verify they can trust those they have to trust.
> people create their threat models and verify they can trust those they have to trust What kind of people? How do you verify you can trust some company?
You verify trustworthiness by research. Who is involved? Do I trust anyone who trusts them? What are their motivations? What would cause them to take action against me? What causes them to protect my interests? What laws are they subjected to (i.e. who can coerce them)? What do they say for themselves? Where do their words fall on the credibility to BS scale? What is their reputation in the community? What do their competitors/adversaries say? What would cause their behavior to change?
I won't enumerate all my research on Mullvad. I can say Mozilla attaching their brand to Mullvad's services helped me a lot (trust by proxy). I'll also say that some of their product decisions give credibility to their anonymity claims. Lastly, I found someone who shared a competitive analysis across many providers. I found the analysis trustworthy. Mullvad has some weak points, but was still the best provider for my particular use case.
Re: Mullvad: Diskless infrastructure using stboot in beta
#30Earlier quoted context omitted.
if only there was any proof of this actually being the case and there not being some "accidental" debug log enabled, or some other network level component having "accidental" access to the keys. There's just no good answer to perfect trust-no-one private internet access. If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your ow…
> There's just no good answer to perfect trust-no-one private internet access. What about Tor?