Live data from Hacker News

We have successfully completed our migration to RAM-only VPN infrastructure

mullvad.net

111–120 of 195 posts

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#111
post #42

Earlier quoted context omitted.

> Some pour thousands of dollars into forcing influencers to say they care about security, Tangential to this, it always irks me how they talk about how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in. HTTPS isn't a cure all by any means but most of the scare tactics that the big VPN compan…

> how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in. I hear most of them saying "Don't want your ISP spying on where you're browsing? Use a VPN." Which HTTPS does not cover.

[deleted]

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#112
> All of our VPN servers continue to use our custom and extensively slimmed down Linux kernel, where we follow the mainline branch of kernel development.

The custom server is a niche security point. While every server is continously researched and patched, we cannot expect the same from a a server like this. If someone were to find a security hole, an attacker would purchase it and no one else would ever know the system was compromised.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#113

Earlier quoted context omitted.

I formerly worked for a somewhat-older mainstream consumer VPN provider for a few years, to the extent that you can take my word for it, this is not industry-standard practice at least as far as the provider is able to control it. Commercial VPNs typically run on rental servers -- usually a mix of the major cloud providers and smaller hosting providers -- and in my former company's case, using dedicated hosting (bare…

> Anyway, there's also the looming "threat" (lol) of HTTPS and encrypted DNS proliferation and improvement making the core use case for commercial VPNs obsolete For a lot of people the core use case is accessing Netflix in a different country!

If you have to pay for safe, encrypted DNS, how is that substantially different than using a VPN? Still need an external service.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#114

Earlier quoted context omitted.

I formerly worked for a somewhat-older mainstream consumer VPN provider for a few years, to the extent that you can take my word for it, this is not industry-standard practice at least as far as the provider is able to control it. Commercial VPNs typically run on rental servers -- usually a mix of the major cloud providers and smaller hosting providers -- and in my former company's case, using dedicated hosting (bare…

> Anyway, there's also the looming "threat" (lol) of HTTPS and encrypted DNS proliferation and improvement making the core use case for commercial VPNs obsolete For a lot of people the core use case is accessing Netflix in a different country!

I'm constantly amazed VPNs get away with advertising that, more specifically the ones that advertise lower prices for subscriptions/products. I guess Netflix themselves won't really care if you switch regions for different shows and might write off discounted subscriptions as alternative to piracy, but the companies that license content by region don't care?

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#115

Earlier quoted context omitted.

> Anyway, there's also the looming "threat" (lol) of HTTPS and encrypted DNS proliferation and improvement making the core use case for commercial VPNs obsolete For a lot of people the core use case is accessing Netflix in a different country!

If you have to pay for safe, encrypted DNS, how is that substantially different than using a VPN? Still need an external service.

I'm not sure how this relates to the parent comment, but there are free encrypted DNS services out there, though the same can't be said for encrypted and anonymous ones (which is, frankly, a hard problem to solve, realistically speaking).

With encrypted DNS you're just shifting the burden of data privacy away from the local network to the DNS operator. How you determine which operators to trust will probably vary from person to person.

Anyway, the major difference here would be that a VPN will encrypt all traffic in a tunnel, from your DNS requests to your actual followup web requests. On the flipside, you may use encrypted DNS to look up records for a domain that serves content over an unencrypted connection.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#116

Not to provoke predictable responses, but I find it interesting that the tech-talented VPN providers are not using BSD in favor of Linux, especially with requirements like diskless operation, kernel customization, and tighter security.

For me, the pool of people to hire that know Linux inside and out would be much larger. This is worth any perceived security issues.

In terms of diskless, I've run 25k+ iPXE deployments on diskless blade servers using a highly customized Ubuntu, and it was fantastic.

Regardless of OS choice, being diskless is also quite nice... if there was a security issue or you need an upgrade of some sort, you just reboot. Only thing is that it takes a while to reboot 25k servers... even on gigE. It was a bit of work to build the scheduling system to make that happen reliably, but it worked out quite well.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#117
post #84

Earlier quoted context omitted.

I can just imagine EFF drooling over such a prospect.

The EFF wants a world where this kind of BS, and consequent litigation, is a thing of the past. If there's water running down their face, it's tears, not drool. We deserve a better world.

You get there by either getting congress to pass laws or by setting legal precedent in the court. That’s the goal of the legal arm. Not to fight every bullshit civil liberties case, but to fight the last one that doesn’t get thrown out in court.

If you don’t think they look forward to those cases, I think you’re the one who has read them wrong, not me.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#120
post #34

Earlier quoted context omitted.

https://www.assured.se/publications/Assured_Mullvad_relay_se... Honestly I don’t think audits are worth anything. But it’d be a huge conspiracy to mess with so many parties.

This is a sec eval. It doesn’t eval what the service can do.

Sections 2.1.1 and 3.1.18
Post reply on HN