Live data from Hacker News

Mullvad: Diskless infrastructure using stboot in beta

mullvad.net

101–110 of 135 posts

Re: Mullvad: Diskless infrastructure using stboot in beta

#101
post #88

I've been following Mullvad for a long time and my impression (from countless reviews and comments here on HN) has been quite positive. But here's what I don't understand: Why are the servers located in Sweden, a country that's known for online surveillance[0] like no other country in the EU? From the Wikipedia article[1]: > The law permits the signals intelligence agency, National Defense Radio Establishment, to mon…

How is this nonsense the top comment? OP's been doing a poor job of "following Mullvad for a long time" and apparently has never used Mullvad or visited its website. Heck, it's on their Wikipedia page[1]. If they had, it would be immediately apparent that Mullvad has servers all over the world. They have for many years -- perhaps since it's inception. It takes a bare minimum of effort to learn that. 1. https://en.wik…

Your annoyance is understandable, and yet this question and direct response from a founder is a very informative interaction to have recorded in this thread. Much more informative than if GP had simply stated the results of their Wikipedia research.

Sometimes a mediocre question is the landing pad for a great answer. No need to begrudge the question.

Re: Mullvad: Diskless infrastructure using stboot in beta

#102
post #88

Earlier quoted context omitted.

How is this nonsense the top comment? OP's been doing a poor job of "following Mullvad for a long time" and apparently has never used Mullvad or visited its website. Heck, it's on their Wikipedia page[1]. If they had, it would be immediately apparent that Mullvad has servers all over the world. They have for many years -- perhaps since it's inception. It takes a bare minimum of effort to learn that. 1. https://en.wik…

Your annoyance is understandable, and yet this question and direct response from a founder is a very informative interaction to have recorded in this thread. Much more informative than if GP had simply stated the results of their Wikipedia research. Sometimes a mediocre question is the landing pad for a great answer. No need to begrudge the question.

While I agree the founder's response was informative, it does not justify the completely erroneous statement/accusation that prompted it.

That most certainly should be called out -- especially when it was, at the time, the top voted comment.

Re: Mullvad: Diskless infrastructure using stboot in beta

#104

Earlier quoted context omitted.

> Because it's a swedish company? I'm not sure what point you're trying to make. If online privacy is as important to them as they say, they could have easily registered their company (or a subsidiary) in a different EU member state. > They'd have to provide government access if there is a lawsuit that demands it. IANAL but I am not entirely sure this is true in the EU. Either way, my question was "Why are the server…

Really? How easy is it to create a company in another EU country. In the US, it is mostly painless to create a company in another state. Fill out some forms online and pay a few hundred. If you don’t have a presence there, you have to pay for a registered agent in the state. That’s about $100/yr. You may also need a mailing address, but you can get a post office box that will accept and scan your mail for another hun…

In the EU you will find very different laws and tax systems depending on the country. Quite large differences in regards to culture as well.

One example: If you're a cross-border worker you'll likely have to file multiple tax decelerations (one for each country), which can be quite complicated if you don't speak the local language (and even if you do).

Re: Mullvad: Diskless infrastructure using stboot in beta

#105
post #14

Earlier quoted context omitted.

Wouldn't the ownership of the server be easy to trace back to you? PIA has been promising a fully audited and verifiable infrastructure in the future: https://www.privateinternetaccess.com/blog/dont-trust-verify...

>Wouldn't the ownership of the server be easy to trace back to you? yes. Which is why I said that this helps to shield your traffic from other people in your current local network (think: coffee-shop) which is one use-case of a VPN. If you need to protect your traffic from anybody but your peer (another potential use-case of a VPN if this were possible) and you even want to hide the fact that you were talking to that…

You are ignoring the use case of protecting my data from my ISP, who is a known bad actor that wants to sell my data and had the power to strongarm my government into legalizing that data theft.

Re: Mullvad: Diskless infrastructure using stboot in beta

#106
post #89

Earlier quoted context omitted.

Thank you, this was the response I was looking for! > Our intent was direct political action through entrepreneurship. Again, I didn't mean to question your intent – as I said my impression of your company so far has been a very good one! :) > We have 762 servers spread across 38 countries. Less than 10% of our servers are located in Sweden [0]. My apologies, it's been a few years since I last looked at your server l…

I highly doubt your VPN traffic will pass Sweden if you're outside Sweden and signing onto a Mullvad VPN server located outside of Sweden. The server list may be fetched from Sweden I guess? I haven't looked at the apps traffic to be honest, I have huge respect for the Mullvad team.

Sorry, I should have been more precise: For everyone outside Sweden using Mullvad's Swedish servers. My point was just that the fact that "[r]ight now there is no Swedish law that can compel Mullvad to start logging" does not mean that Swedish intelligence agencies cannot collect any data about you (= the Mullvad user using their Swedish servers).

Re: Mullvad: Diskless infrastructure using stboot in beta

#107
post #88

I've been following Mullvad for a long time and my impression (from countless reviews and comments here on HN) has been quite positive. But here's what I don't understand: Why are the servers located in Sweden, a country that's known for online surveillance[0] like no other country in the EU? From the Wikipedia article[1]: > The law permits the signals intelligence agency, National Defense Radio Establishment, to mon…

How is this nonsense the top comment? OP's been doing a poor job of "following Mullvad for a long time" and apparently has never used Mullvad or visited its website. Heck, it's on their Wikipedia page[1]. If they had, it would be immediately apparent that Mullvad has servers all over the world. They have for many years -- perhaps since it's inception. It takes a bare minimum of effort to learn that. 1. https://en.wik…

I have apologized for the factual incorrectness of my comment and explained how I had arrived at that conclusion / brain glitch: They are only mentioning Swedish servers in their blog post and for a second I had forgotten that, like any other big VPN provider, Mullvad of course has servers in many locations around the world.

What more do you want? Upvotes are not under my control and I also cannot edit my original comment anymore. No reason to get personal.

FWIW, I still think that it's important to raise awareness for the deficiencies of Swedish privacy law (irrespective of Mullvad and where their servers are located). I suspect that at least some of the upvotes were also given because people agreed with that.

Re: Mullvad: Diskless infrastructure using stboot in beta

#108
post #89

Earlier quoted context omitted.

I highly doubt your VPN traffic will pass Sweden if you're outside Sweden and signing onto a Mullvad VPN server located outside of Sweden. The server list may be fetched from Sweden I guess? I haven't looked at the apps traffic to be honest, I have huge respect for the Mullvad team.

Sorry, I should have been more precise: For everyone outside Sweden using Mullvad's Swedish servers. My point was just that the fact that "[r]ight now there is no Swedish law that can compel Mullvad to start logging" does not mean that Swedish intelligence agencies cannot collect any data about you (= the Mullvad user using their Swedish servers).

Locating all their servers in IndependiPrivastan probably wouldn't stop intelligence agencies from collecting data. The NSA, for example, does not care even a tiny bit about the privacy of non-US citizens and sets up equipment around the world to gather and analyze internet traffic.

Re: Mullvad: Diskless infrastructure using stboot in beta

#109
post #104

Earlier quoted context omitted.

Really? How easy is it to create a company in another EU country. In the US, it is mostly painless to create a company in another state. Fill out some forms online and pay a few hundred. If you don’t have a presence there, you have to pay for a registered agent in the state. That’s about $100/yr. You may also need a mailing address, but you can get a post office box that will accept and scan your mail for another hun…

In the EU you will find very different laws and tax systems depending on the country. Quite large differences in regards to culture as well. One example: If you're a cross-border worker you'll likely have to file multiple tax decelerations (one for each country), which can be quite complicated if you don't speak the local language (and even if you do).

> If you're a cross-border worker you'll likely have to file multiple tax decelerations (one for each country)

Yes, if you have sources of income in multiple countries, you might have to. But if you're (only) working on the other side of the border and this is your only source of income, agreements on double taxation and tax harmonization between the EU member states should actually prevent that. Heck, I even worked in the US once, declared my taxes there and didn't have to do my taxes back home in the EU anymore.

Re: Mullvad: Diskless infrastructure using stboot in beta

#110
post #43
post #26

Earlier quoted context omitted.

Correct! Thank you for highlighting that. Here are some additional details for those interested. We intend to make use of TPM for remote attestation of the current boot chain, reproducible builds to provide a strong link from source code to build artifacts, and a transparency log for a historical record of previously used boot chains, artifacts, WireGuard server keys, and related signatures. As dtx1 mentioned elsewhe…

Niiice. I really love the concept of reversing the usual DRM use of remote attestation--forcing customers to prove they're running only software allowed by the megacorps. Instead of DRM, it's proving the corporation/server is trustworthy to the customer. I think I could get behind more of this use!

Check out tpm2-totp. I stumbled across it while looking for a way to store totp secrets in my tpm, and was really impressed with the clever use of totp to verify a boot chain.

https://github.com/tpm2-software/tpm2-totp

Post reply on HN