Live data from Hacker News

Tillitis Key – Mullvad spin-off inspired by measured boot and DICE

tillitis.se

11–20 of 123 posts

Re: Tillitis Key – Mullvad spin-off inspired by measured boot and DICE

#11
post #7

Good VPN company (one of the best) and good idea (sounds like USB Armory). But the best it can do is assure that their VMs are not logging anything and keep other promises. Will they also be able to share details of their hosting setup in a way you can independently verify (because they can always have more middleware transparent traffic logging VMs)? doubt it, same goes to whomever they use for hosting. My point is,…

> Good VPN company (one of the best) and good idea (sounds like USB Armory). But the best it can do is assure that their VMs are not logging anything and keep other promises. Will they also be able to share details of their hosting setup in a way you can independently verify (because they can always have more middleware transparent traffic logging VMs)? doubt it, same goes to whomever they use for hosting.

We are working on this as part of the System Transparency project.

https://system-transparency.org/

Disclaimer: I work on this.

Beyond this Penetration Testing reports on the Mullvad infrastructure is public.

Re: Tillitis Key – Mullvad spin-off inspired by measured boot and DICE

#14
post #7

Good VPN company (one of the best) and good idea (sounds like USB Armory). But the best it can do is assure that their VMs are not logging anything and keep other promises. Will they also be able to share details of their hosting setup in a way you can independently verify (because they can always have more middleware transparent traffic logging VMs)? doubt it, same goes to whomever they use for hosting. My point is,…

> Good VPN company (one of the best) and good idea (sounds like USB Armory). But the best it can do is assure that their VMs are not logging anything and keep other promises. Will they also be able to share details of their hosting setup in a way you can independently verify (because they can always have more middleware transparent traffic logging VMs)? doubt it, same goes to whomever they use for hosting. We are wor…

I’ve always wondered what is feasible through a state-issued mandate along with a gag order to circumvent the technology for something like this.

Re: Tillitis Key – Mullvad spin-off inspired by measured boot and DICE

#15
post #8
post #4

Am I right in thinking that this is basically like a yubikey except with openness as key differentiator? Or is it’s function something else ?

Not exactly sure, but the OSFC conference page has some extra info on what it can do: https://www.osfc.io/2022/talks/tillitis-key-a-usb-security-k... Maybe it will be ~YubiKey plus extras?

So Solokey V2. Not that I'm complaining by the way. Any open competition to yubikey is a win in my book.

Re: Tillitis Key – Mullvad spin-off inspired by measured boot and DICE

#17
post #4

Am I right in thinking that this is basically like a yubikey except with openness as key differentiator? Or is it’s function something else ?

It is an FPGA, fully open both at software and hardware level. So quite a bit more futurproof, inspectable and upgradable than a yubikey.

Re: Tillitis Key – Mullvad spin-off inspired by measured boot and DICE

#18
post #14

Earlier quoted context omitted.

> Good VPN company (one of the best) and good idea (sounds like USB Armory). But the best it can do is assure that their VMs are not logging anything and keep other promises. Will they also be able to share details of their hosting setup in a way you can independently verify (because they can always have more middleware transparent traffic logging VMs)? doubt it, same goes to whomever they use for hosting. We are wor…

I’ve always wondered what is feasible through a state-issued mandate along with a gag order to circumvent the technology for something like this.

Couldn't this be solved by something like remote attestation?
Post reply on HN