Live data from Hacker News

Mullvad: Diskless infrastructure using stboot in beta

mullvad.net

121–130 of 135 posts

Re: Mullvad: Diskless infrastructure using stboot in beta

#121
post #73

Earlier quoted context omitted.

Your theory is an American could start a company that violates US laws so long as they form the entity somewhere else?

GP didn't say anything like that. They were talking about > avoid[ing] local laws (i.e. legally) which is a whole different matter.

How is that different from saying Swedes can avoid Swedish law by incorporating somewhere else?

Re: Mullvad: Diskless infrastructure using stboot in beta

#122

Some information that could be of interest to those running VPN servers. I live in Kazakhstan and recently our government decided to shut down the Internet. But apparently there were ways to get out: they did not filter two TCP ports. My guess it was some "backdoor" put by employees who had to obey the orders but wanted to provide people some way to get around those blocks. Those ports were used to run VPN software.…

I think it is probably more likely those ports were the backdoor the government or their allies was using to function. Everyone always builds in a backdoor for themselves!

When I hear about things like this it makes me glad I have a simple satellite communicator - it will only do short text messages but that is a hell of a lot better than nothing. Of course one could get a full satellite based mobile internet device or phone but the plans on those get quite expensive.

Re: Mullvad: Diskless infrastructure using stboot in beta

#123

Earlier quoted context omitted.

While I agree the founder's response was informative, it does not justify the completely erroneous statement/accusation that prompted it. That most certainly should be called out -- especially when it was, at the time, the top voted comment.

People make mistakes. Maybe if you were less you combative your comments would get more upvotes.

I didn't feel like I was being combative, only pointing out OP was misinforming people. They didn't do even basic research, contrary to their statements. That negligence should be called out.

And I'm not here for upvotes. Who's being combative, again?

Re: Mullvad: Diskless infrastructure using stboot in beta

#124
post #7
post #4

Earlier quoted context omitted.

if only there was any proof of this actually being the case and there not being some "accidental" debug log enabled, or some other network level component having "accidental" access to the keys. There's just no good answer to perfect trust-no-one private internet access. If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your ow…

> There's just no good answer to perfect trust-no-one private internet access. What about Tor?

In addition to the traffic analysis mentioned in another reply, there are ways data can be leaked from Tor. One example from the crime documentary "Hunting Warhead": a white hat hacker managed to locate a darknet server running a forum software by setting his avatar image to a file hosted on a domain he controlled. The forum software retrieved the age via a regular internet route, exposing the actual host IP.

For maximum privacy, Tor should be used with software designed for Tor from the start.

Re: Mullvad: Diskless infrastructure using stboot in beta

#125
post #97

Earlier quoted context omitted.

Disabling USB in BIOS only disables the emulation of classic PS2 keyboards and IDE storage so that old OSes or bootloaders without USB stacks can work with modern equipment. As soon as the OS kernel initializes the PCI bus, USB will work again - however they could go and remove the xHCI modules from the kernel and image.

Mullvad has a custom-built bare metal UEFI implementation based on coreboot, I assume stboot is an evolution of that, which means it takes as close as you can get to full responsibility for initialization of all system components like processor, chipset, Ethernet, USB, everything. As a result they can absolutely disable USB entirely by never exposing those parts of the device tree to Linux.

x86 devices do not have device trees, and for ARM I'd take a guess and say that as long as the PCI root port is exposed to the OS, a PCI re-scan will be enough to wake the USB chipset.

Re: Mullvad: Diskless infrastructure using stboot in beta

#127
post #34

Earlier quoted context omitted.

So what is the point? I already assume the code on their server is not malicious by using it. What extra trust does an untrusted TPM chip give me?

System Transparency reduces your trust assumptions on us. As a VPN provider we are in an immense position of power over you. We aim to reduce your trust assumptions on us to a few things that we would need to explicitly lie about in order to betray you. As an example, let's say that we offered any of our users to at any time during the year show up at our office and inspect our VPN hardware, without warning us before…

> In that situation, if we wanted to betray your trust and privacy, we would need to put in a lot more effort than if we said "We have secure servers. Trust us on that. No you can't see them.". Does that make sense?

Have you ever thought about doing something like that with some big youtube personalities? Maybe have them hire some pen testers, randomly show up to one of your datacenters, and post recordings of what is done and attacks that could be possible. Since your software is open pen testers could prepare some things to try to attack days in advanced. I'd love to see something like this with Level1Techs or something.

Re: Mullvad: Diskless infrastructure using stboot in beta

#128
post #67

Earlier quoted context omitted.

A server in Sweden cannot easily be raided by the Swedish, is the first reason. The second reason is "Swedish laws apply to people in Sweden" seem to make assumptions about what the government can force people to do, or specifically, punish people for not doing. In many cases, authorities just threaten/raid the data-centers so never have to bother take that route. Lastly, I'm not sure this is true: "Swedish laws appl…

This isn’t really responsive to what I’m saying or what you asked me. I didn’t make any assumptions about what Swedish law can or cannot do. Swedish laws apply to people in Sweden. If Swedish law says that you can’t use Helvetica font on your website, and the punishment is 10 years of hand-tracing a better font on stone tablets, then they’re able to apply that law to a Sweden-based web developer, regardless of whethe…

> I didn’t make any assumptions about what Swedish law can or cannot do

> If Swedish law says ... they’re able to apply that law ...

This is a big assumption, and depends if you mean literally that they can do this, or if they can do so sustainably. Any country can violate international practise, but are unlikely to do so (at least in Europe) because of the consequence on international relations.

A law on Helvetica font would require legal authority. Very often, companies themselves are help liable for the actions of a company - laws that allow the government to punish individuals would have to specifically criminalise the act even for locals acting on behalf of those corps. These kind of laws are much rarer, at least in US/Europe, and not the kind of law we are talking about here which appear to apply to corporations. There is a good reason for this; as soon as any nation officially declares it would punish individuals like this, corps will leave - or at least no longer employ natives into decent positions.

> But the Swedish government gets to make those laws and determine which apply to whom.

Technically, but not really, they have to remain compatible with their international agreements, and their economic ambitions.

Re: Mullvad: Diskless infrastructure using stboot in beta

#129
post #121

Earlier quoted context omitted.

GP didn't say anything like that. They were talking about > avoid[ing] local laws (i.e. legally) which is a whole different matter.

How is that different from saying Swedes can avoid Swedish law by incorporating somewhere else?

This is not what you said. You were talking about "a company that violates US law" (emphasis mine).

Re: Mullvad: Diskless infrastructure using stboot in beta

#130
post #73

Earlier quoted context omitted.

You are allowed to start companies in other countries, and thereby avoid local laws, without moving i.e. changing you country of residence. If you believe any different, please say why so. Just "wouldn’t do them any good" is pretty meaningless.

Your theory is an American could start a company that violates US laws so long as they form the entity somewhere else?

Depends what you mean. US law takes into account the existence of foreign nations already; some explicitly end at the borders, others not so.

It also depends on which country, and to what extent agreements exist between those countries wrt policing their own territories. Those that don't have such agreements, are often also limited in what extent they can do business in the US.

Post reply on HN