A bit tangential to the main post, but I'd to share a recent positive experience with Mullvad: I am a regular user of Mullvad and recently wanted to try a different VPN, that only provides Wireguard configs (i.e. no native app). I used the default setup. For some reason, my internet connection was flaky, and when it disconnected and reconnected, my traffic leaked. That never happened to me with Mullvad as the app com…
Mullvad: Diskless infrastructure using stboot in beta
81–90 of 135 posts
Re: Mullvad: Diskless infrastructure using stboot in beta
#82> If the computer is powered off, moved or confiscated, there is no data to retrieve. Don't forget to add insta-shutdown when any USB device is connected to the system!
Or disable usb in bios entirely
Re: Mullvad: Diskless infrastructure using stboot in beta
#83A bit tangential to the main post, but I'd to share a recent positive experience with Mullvad: I am a regular user of Mullvad and recently wanted to try a different VPN, that only provides Wireguard configs (i.e. no native app). I used the default setup. For some reason, my internet connection was flaky, and when it disconnected and reconnected, my traffic leaked. That never happened to me with Mullvad as the app com…
Agree, Mullvad provides really good VPN service. I faced almost zero downtimes / speed throttles. It establishes quick connection with server (maybe because it uses wireguard). Anyway, I'm a regular user and I think paying 5E worth it.
I'm actually kind of curious about what Wireguard does here. I think Wireguard says it's connected almost immediately even when it isn't, presumably holding traffic back locally while it waits for the connection to be active. I was wondering because I spent some time confused by a non-Mullvad Wireguard connection that wasn't working (turns out the server wasn't available at all) that nonetheless appeared as "connected".
Re: Mullvad: Diskless infrastructure using stboot in beta
#84Earlier quoted context omitted.
I hate to be this skeptical, but let's say this is 100% possible (I have my doubts, see previous attacks on things like TPMs and SGX, but I digress). You probably could get 90% of the logging capability by putting monitoring in front of and behind the server, and associating connections by traffic/time. It just seems like this goal of using technology to prove they're trustworthy is unlikely to actually work for a VP…
Traffic analysis and correlation analysis is indeed a powerful tool, and in general only communicating at a constant bandwidth between all nodes at all times is the only way to completely defeat it (which is what, I understand, some military systems do). That's inherently highly wasteful, however. To get around this, Mullvad offer very transparent comprehensive multi-hop routing systems [1]; you can bounce your wireg…
Re: Mullvad: Diskless infrastructure using stboot in beta
#85Earlier quoted context omitted.
This isn’t really responsive to what I’m saying or what you asked me. I didn’t make any assumptions about what Swedish law can or cannot do. Swedish laws apply to people in Sweden. If Swedish law says that you can’t use Helvetica font on your website, and the punishment is 10 years of hand-tracing a better font on stone tablets, then they’re able to apply that law to a Sweden-based web developer, regardless of whethe…
Laws that apply to companies follow different rules than laws that apply to individuals, it feels like you’re conflating the two.. Just because employees reside in Sweden doesn’t mean the company resides in Sweden, legally.
Re: Mullvad: Diskless infrastructure using stboot in beta
#86I've been following Mullvad for a long time and my impression (from countless reviews and comments here on HN) has been quite positive. But here's what I don't understand: Why are the servers located in Sweden, a country that's known for online surveillance[0] like no other country in the EU? From the Wikipedia article[1]: > The law permits the signals intelligence agency, National Defense Radio Establishment, to mon…
Thank you for asking. > Why are the servers located in Sweden, We have 762 servers spread across 38 countries. Less than 10% of our servers are located in Sweden [0]. > a country that's known for online surveillance My cofounder and I started Mullvad as a protest against the growing mass surveillance of Sweden as well as other countries. Our intent was direct political action through entrepreneurship. Incorporating t…
> Our intent was direct political action through entrepreneurship.
Again, I didn't mean to question your intent – as I said my impression of your company so far has been a very good one! :)
> We have 762 servers spread across 38 countries. Less than 10% of our servers are located in Sweden [0].
My apologies, it's been a few years since I last looked at your server locations (so I didn't remember) and I was probably getting the wrong impression from the fact that your post is only mentioning server locations in Sweden.
> Right now there is no Swedish law that can compel Mullvad to start logging [1].
But at the same time all cross-border traffic in and out of Sweden (so for anyone using Mullvad outside Sweden: virtually all traffic) is being monitored and (probably) logged, isn't it?
Re: Mullvad: Diskless infrastructure using stboot in beta
#87Earlier quoted context omitted.
> there's no security either. Dont buy that, care to elaborate?
In the same line of thinking as the parent comment, there's no 100% security either. If you loot at IT, everything can be hacked, secrets leak, intelligence agencies hoard vulnerabilities, or even have insiders in security firms or larger corporations. In the real life, no lock is invulnerable. Most can be picked, frozen, melted, etc and surely have other weaknesses too. But to achieve their goal, they don't need to…
In IT, you need both joined up offensive and defensive measures which includes self destruct if secrets need to be kept. That is at best a Check Mate.
Take a VPN, in nearly all instances I have encountered the only traffic is genuine traffic, there is no dummy traffic to muddy the waters from external Deep Packet Inspection.
Likewise routing can be used to isolate, I'll give you a real world example which you might be able to relate to.
You are travelling by car from A to B, and you can take a variety of routes to get there. Most modern cars now have built in sat nav, and all you know is when your target is leaving and they will be using the car manufacturers satnav. So you have a window (at the start of their journey) in which to manipulate the targets satnav by giving it fake traffic data to cause it to take a particular route. Ergo you have been able to isolate your target onto roads they wouldn't normally travel. Now that can be done nationally over the radio station network, or nearby using a transceiver SDR in a chase car.
What makes you think the internet is any difference? Business efficiency like JIT is a weakness as we see with the chip shortages and other problems caused by covid lockdowns. VPN companies are no different, they need to maximise profit so they dont add in fake traffic to hide their customers traffic, and by virtue of being able to choose from multiple VPN providers, users self isolate themselves into yet smaller groups. VPN providers should really organise and share networks to further muddy the waters from external entities.
Re: Mullvad: Diskless infrastructure using stboot in beta
#88I've been following Mullvad for a long time and my impression (from countless reviews and comments here on HN) has been quite positive. But here's what I don't understand: Why are the servers located in Sweden, a country that's known for online surveillance[0] like no other country in the EU? From the Wikipedia article[1]: > The law permits the signals intelligence agency, National Defense Radio Establishment, to mon…
OP's been doing a poor job of "following Mullvad for a long time" and apparently has never used Mullvad or visited its website. Heck, it's on their Wikipedia page[1].
If they had, it would be immediately apparent that Mullvad has servers all over the world. They have for many years -- perhaps since it's inception. It takes a bare minimum of effort to learn that.
Re: Mullvad: Diskless infrastructure using stboot in beta
#89Earlier quoted context omitted.
Thank you for asking. > Why are the servers located in Sweden, We have 762 servers spread across 38 countries. Less than 10% of our servers are located in Sweden [0]. > a country that's known for online surveillance My cofounder and I started Mullvad as a protest against the growing mass surveillance of Sweden as well as other countries. Our intent was direct political action through entrepreneurship. Incorporating t…
Thank you, this was the response I was looking for! > Our intent was direct political action through entrepreneurship. Again, I didn't mean to question your intent – as I said my impression of your company so far has been a very good one! :) > We have 762 servers spread across 38 countries. Less than 10% of our servers are located in Sweden [0]. My apologies, it's been a few years since I last looked at your server l…
Re: Mullvad: Diskless infrastructure using stboot in beta
#90Earlier quoted context omitted.
Agree, Mullvad provides really good VPN service. I faced almost zero downtimes / speed throttles. It establishes quick connection with server (maybe because it uses wireguard). Anyway, I'm a regular user and I think paying 5E worth it.
> It establishes quick connection with server (maybe because it uses wireguard) I'm actually kind of curious about what Wireguard does here. I think Wireguard says it's connected almost immediately even when it isn't, presumably holding traffic back locally while it waits for the connection to be active. I was wondering because I spent some time confused by a non-Mullvad Wireguard connection that wasn't working (turn…