Live data from Hacker News

We have successfully completed our migration to RAM-only VPN infrastructure

mullvad.net

121–130 of 195 posts

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#121
Nice work!

But, if anything should be a decentralized anonymous crypto-paid service, it should be a VPN network.

Centralized VPNs are still a single point of failure privacy risk. We have to trust they don't share our identity/account info and activity.

I am surprised dVPNs are not THE first rationale given for crypto. I.e. since separately and together they (ideally) have a clear comparative advantage over other alternatives for strong privacy.

A performant global open-standard dVPN could become an indispensable layer of web access.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#122

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

I formerly worked for a somewhat-older mainstream consumer VPN provider for a few years, to the extent that you can take my word for it, this is not industry-standard practice at least as far as the provider is able to control it. Commercial VPNs typically run on rental servers -- usually a mix of the major cloud providers and smaller hosting providers -- and in my former company's case, using dedicated hosting (bare…

The other argument is to frustrate network correlation analysis. Many VPN providers have an internal high-bandwidth network (virtual or otherwise); you can send a packet to $VPN_SERVER_X, it sends it to $VPN_SERVER_Y possibly via other intermediate servers, and $VPN_SERVER_Y then forwards it on to your destination.

If you live in a country with detailed data retention laws, this massively changes the shape of the graph: rather than your computer connecting via HTTPS to lots of other IP addresses, it only connects to one, which a large number of other customers do too. The argument then goes that there's enough inherent jitter and generic "chaff" on the internal network to make it very hard to deterministically work out if one of your packets going in to a popular service is the same as that coming out at any moment in time; the greater the traffic of the network and the provider the better the statistical protection becomes as the packets become indistinguishable.

This, and the fact that it represents a giant "no thanks" to dragnet surveillance, is arguably a good reason to just put a VPN on your router (as many people do).

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#123

Nice work! But, if anything should be a decentralized anonymous crypto-paid service, it should be a VPN network. Centralized VPNs are still a single point of failure privacy risk. We have to trust they don't share our identity/account info and activity. I am surprised dVPNs are not THE first rationale given for crypto. I.e. since separately and together they (ideally) have a clear comparative advantage over other alt…

I wasn't sure what a decentralized VPN would look like, so I searched and found https://surfshark.com/blog/decentralized-vpn . Obvious bias coming from a VPN provider, but if they are stating the technology correctly, then I think it's important to determine if this is correct:

> A decentralized VPN is a distributed VPN service where volunteers supply your VPN servers instead of a single company – but paid by crypto. Like with regular VPNs, you have to trust that the VPN server isn’t monitoring your data. But instead of there being a single VPN provider company behind it all, you have to trust that none of the thousands of server volunteers are spying on you.

Is this a correct understanding of dVPNs? Is there a rebuttal, especially to that last sentence?

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#124
post #123

Nice work! But, if anything should be a decentralized anonymous crypto-paid service, it should be a VPN network. Centralized VPNs are still a single point of failure privacy risk. We have to trust they don't share our identity/account info and activity. I am surprised dVPNs are not THE first rationale given for crypto. I.e. since separately and together they (ideally) have a clear comparative advantage over other alt…

I wasn't sure what a decentralized VPN would look like, so I searched and found https://surfshark.com/blog/decentralized-vpn . Obvious bias coming from a VPN provider, but if they are stating the technology correctly, then I think it's important to determine if this is correct: > A decentralized VPN is a distributed VPN service where volunteers supply your VPN servers instead of a single company – but paid by crypto.…

Yes, that is correct. It's great for getting residential IPs, but connection quality is much worse

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#125

Nice work! But, if anything should be a decentralized anonymous crypto-paid service, it should be a VPN network. Centralized VPNs are still a single point of failure privacy risk. We have to trust they don't share our identity/account info and activity. I am surprised dVPNs are not THE first rationale given for crypto. I.e. since separately and together they (ideally) have a clear comparative advantage over other alt…

>But, if anything should be a decentralized anonymous crypto-paid service, it should be a VPN network

so it should be tor?

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#126

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

> but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log"

No they can't, because THEY are still logging.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#127

Nice work! But, if anything should be a decentralized anonymous crypto-paid service, it should be a VPN network. Centralized VPNs are still a single point of failure privacy risk. We have to trust they don't share our identity/account info and activity. I am surprised dVPNs are not THE first rationale given for crypto. I.e. since separately and together they (ideally) have a clear comparative advantage over other alt…

[deleted]

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#128

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

[deleted]

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#129
post #118

> freshly built kernel, no traces of any log files, and a fully patched OS Wouldn't using a disk in read-only mode accomplish the same thing?

Disks don’t always have a readonly switch these days, though I do still miss the physical notch on floppy disks, and no third-party auditing could exist for proving that switch to be set correctly.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#130
post #123

Nice work! But, if anything should be a decentralized anonymous crypto-paid service, it should be a VPN network. Centralized VPNs are still a single point of failure privacy risk. We have to trust they don't share our identity/account info and activity. I am surprised dVPNs are not THE first rationale given for crypto. I.e. since separately and together they (ideally) have a clear comparative advantage over other alt…

I wasn't sure what a decentralized VPN would look like, so I searched and found https://surfshark.com/blog/decentralized-vpn . Obvious bias coming from a VPN provider, but if they are stating the technology correctly, then I think it's important to determine if this is correct: > A decentralized VPN is a distributed VPN service where volunteers supply your VPN servers instead of a single company – but paid by crypto.…

No that isn't accurate.

You have a network of VPN point providers. As you communicate, data can be sent through any series of points.

Data is encrypted end-to-end, and the addresses for the point providers are also encrypted so that each point can only decrypt and see the next point to forward data to.

So each point knows where data last came from, and where they are sending it. But they don't know:

1. Which step of a chain of points the data is at.

2. If they are the first in the chain (i.e. the "from" is the source)

3. If they are the last in the chain (i.e. the "to" is the destination)

And (as long as two or more points are traversed, which would be always), no point ever has access to:

4. Both source and destination info.

Finally, since payments to each point are handled through a combination of peer-to-peer point bookkeeping, and a crypto block chain account, no point ever knows:

5. Any identity information about who uses the VPN.

6. Any way to identify activity over time that is related.

Acting as a point, as well as using the network, serves to further cloak activity, as being from you vs. passed through you.

And an alternative to crypto payments, would be earning usage by providing point service.

EDIT:

> so I searched and found https://surfshark.com/[...]

Any VPN provider that is claiming decentralized VPNs are a greater risk is either misinformed, or willing to misinform users.

I wouldn't trust a VPN provider from either category.

Actual reasons to not use a dVPN might be that it is a work in progress, not supported well, its source code is not open, or not yet vetted by experts, too slow, not many points yet, etc.

Post reply on HN