Live data from Hacker News

Mullvad: Diskless infrastructure using stboot in beta

mullvad.net

61–70 of 135 posts

Re: Mullvad: Diskless infrastructure using stboot in beta

#61
post #54

Earlier quoted context omitted.

I think you’re overthinking this. The people who run the company are based in Sweden. So they registered the company in Sweden, because that’s where they are. Then they hosted the servers in Sweden, because that’s where they are and where the company is registered. Registering the company somewhere else wouldn’t do them any good when they’re living in Sweden, because the legal system isn’t fooled by sleight of hand l…

You are allowed to start companies in other countries, and thereby avoid local laws, without moving i.e. changing you country of residence. If you believe any different, please say why so. Just "wouldn’t do them any good" is pretty meaningless.

I assumed it was pretty clear why it wouldn’t do them any good:

All of their executives and their staff are in Sweden. It doesn’t matter if the company is registered on Mars, the Swedish government can come knock on their doors, because Swedish laws apply to people in Sweden.

The most mundane way to demonstrate this is to imagine they don’t register a company at all. If a bunch of Swedish people get together and start doing business w/o registering a company, it’s clear that Swedish law applies to them. Why would filing some paperwork with a foreign entity grant them immunity from the laws in the country they live and work from?

Re: Mullvad: Diskless infrastructure using stboot in beta

#63
post #26

Earlier quoted context omitted.

Correct! Thank you for highlighting that. Here are some additional details for those interested. We intend to make use of TPM for remote attestation of the current boot chain, reproducible builds to provide a strong link from source code to build artifacts, and a transparency log for a historical record of previously used boot chains, artifacts, WireGuard server keys, and related signatures. As dtx1 mentioned elsewhe…

This all sounds very exciting. Where will you draw the line between public and private – at the moment your consumer-facing app is on github, but less "server side" stuff (in common with many other VPN providers). I understand that probably you want to keep the database of "active numbers" private, but if I understand you correctly, you want to move to a model where anyone can download your in-memory image, run it in…

> Where will you draw the line between public and private – at the moment your consumer-facing app is on github, but less "server side" stuff (in common with many other VPN providers).

All source code for all software on our VPN servers must eventually be public, and all build artifacts must be reproducible by 3rd parties.

> I understand that probably you want to keep the database of "active numbers" private, but if I understand you correctly, you want to move to a model where anyone can download your in-memory image, run it in a VM, and audit it independently.

Exactly, but we will also have to measure each artifact in the boot chain into the platform TPM, and allow anyone to issue a challenge to the TPM to get a signed quote of the boot chain measurements.

> I would welcome this. I'm particularly interested in how you maintain access to your bare-metal machines (e.g. do you have ssh / a serial console enabled)

We’ll have to constrain our own ability to access the VPN servers. We cannot be allowed arbitrary root access as that would make the TPM measurements meaningless from an audit perspective. Well, you’d be able to conclude we have root access, so not totally meaningless.

Re: Mullvad: Diskless infrastructure using stboot in beta

#64
I love the concept and I even wrote a blog post about how to set up a fully pxe bootable server environment using Alpine Linux [1] (which by default boots from RAM) in 2019. I still use it and it's one of those things that makes recovery or testing so much faster because I don't even need a usb thumb drive

[1] https://blog.haschek.at/2019/build-your-own-datacenter-with-...

Re: Mullvad: Diskless infrastructure using stboot in beta

#65
Some information that could be of interest to those running VPN servers.

I live in Kazakhstan and recently our government decided to shut down the Internet. But apparently there were ways to get out: they did not filter two TCP ports. My guess it was some "backdoor" put by employees who had to obey the orders but wanted to provide people some way to get around those blocks. Those ports were used to run VPN software. I used Outline VPN on my VPS and it allowed me and my friends to have a working Internet.

TLDR: allow specifying port and protocol (TCP/UDP) as some kind of advanced option for those users who need it for some reason.

Right now we've got Internet back and it works fine, but who knows when our government will decide to shut it down again.

PS mullvad.net website apparently is blocked in Kazakhstan as well. I know that they block popular VPN provider websites, so that should not come as a surprise, but still. I have no idea whether actual VPN subnets are blocked or not.

Re: Mullvad: Diskless infrastructure using stboot in beta

#66
post #61

Earlier quoted context omitted.

You are allowed to start companies in other countries, and thereby avoid local laws, without moving i.e. changing you country of residence. If you believe any different, please say why so. Just "wouldn’t do them any good" is pretty meaningless.

I assumed it was pretty clear why it wouldn’t do them any good: All of their executives and their staff are in Sweden. It doesn’t matter if the company is registered on Mars, the Swedish government can come knock on their doors, because Swedish laws apply to people in Sweden. The most mundane way to demonstrate this is to imagine they don’t register a company at all. If a bunch of Swedish people get together and star…

A server in Sweden cannot easily be raided by the Swedish, is the first reason.

The second reason is "Swedish laws apply to people in Sweden" seem to make assumptions about what the government can force people to do, or specifically, punish people for not doing. In many cases, authorities just threaten/raid the data-centers so never have to bother take that route.

Lastly, I'm not sure this is true: "Swedish laws apply to people in Sweden" - I'm not sure this applies to Swedes working for foreign corps, there are a whole load of laws that apply to local corps only. In fact, that are laws that apply to Swedish corps even when their staff reside abroad - unless "government can come knock on their doors" is a reference to physical coercion.

Re: Mullvad: Diskless infrastructure using stboot in beta

#67
post #61

Earlier quoted context omitted.

I assumed it was pretty clear why it wouldn’t do them any good: All of their executives and their staff are in Sweden. It doesn’t matter if the company is registered on Mars, the Swedish government can come knock on their doors, because Swedish laws apply to people in Sweden. The most mundane way to demonstrate this is to imagine they don’t register a company at all. If a bunch of Swedish people get together and star…

A server in Sweden cannot easily be raided by the Swedish, is the first reason. The second reason is "Swedish laws apply to people in Sweden" seem to make assumptions about what the government can force people to do, or specifically, punish people for not doing. In many cases, authorities just threaten/raid the data-centers so never have to bother take that route. Lastly, I'm not sure this is true: "Swedish laws appl…

This isn’t really responsive to what I’m saying or what you asked me.

I didn’t make any assumptions about what Swedish law can or cannot do. Swedish laws apply to people in Sweden. If Swedish law says that you can’t use Helvetica font on your website, and the punishment is 10 years of hand-tracing a better font on stone tablets, then they’re able to apply that law to a Sweden-based web developer, regardless of whether or not he works for a company that’s registered in Spain.

Likewise, yes, the Swedish government surely has many laws with carve outs for different use cases. Taxes are a great example here: there are laws that apply only to activities of foreign corporations, and laws that apply only to local corporations. But the Swedish government gets to make those laws and determine which apply to whom. Likewise, you are correct that Sweden can make laws that apply to Swedish corporations even when their staff reside abroad. This is because by registering in Sweden, the business has given the Swedish government a measure of control over their activities.

Re: Mullvad: Diskless infrastructure using stboot in beta

#68

Earlier quoted context omitted.

>There is no privacy! I think this is a good message. In the same vein, there's no security either. All you can do is make your and your adversaries' life harder, and balance the different tradeoffs.

> there's no security either. Dont buy that, care to elaborate?

In the same line of thinking as the parent comment, there's no 100% security either. If you loot at IT, everything can be hacked, secrets leak, intelligence agencies hoard vulnerabilities, or even have insiders in security firms or larger corporations.

In the real life, no lock is invulnerable. Most can be picked, frozen, melted, etc and surely have other weaknesses too.

But to achieve their goal, they don't need to perfect. Just reasonably good. And so, I wish for people to be mindful about the nature of these. That they are not perfect, they are not hidder, nor secure. Just, maybe, reasonably so.

Re: Mullvad: Diskless infrastructure using stboot in beta

#69
post #16

A bit tangential to the main post, but I'd to share a recent positive experience with Mullvad: I am a regular user of Mullvad and recently wanted to try a different VPN, that only provides Wireguard configs (i.e. no native app). I used the default setup. For some reason, my internet connection was flaky, and when it disconnected and reconnected, my traffic leaked. That never happened to me with Mullvad as the app com…

On linux you can create a network namespace exposing only the wireguard network device, so that applications in that namespace cannot leak traffic. Setting this up, however, is quite fiddly in my experience.

I would suggest vopono to do this automatically.

Re: Mullvad: Diskless infrastructure using stboot in beta

#70
post #9

Earlier quoted context omitted.

which is true until one or more of their owners decide to sell their shares.

my grocer down the road is a nice fella and has tasty vegetables from sustainable sources, but he might get bought up by a big supermarket chain, so I'm not going to buy from him

your grocer does not have the ability to retroactively change the food you've bought from them.

A VPN provider can "accidentally" enable logging prior to the sale

Post reply on HN