Live data from Hacker News

We have successfully completed our migration to RAM-only VPN infrastructure

mullvad.net

131–140 of 195 posts

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#131
post #34

Earlier quoted context omitted.

https://www.assured.se/publications/Assured_Mullvad_relay_se... Honestly I don’t think audits are worth anything. But it’d be a huge conspiracy to mess with so many parties.

Audits are IMO worthwhile, but end users should be aware of the scope of an audit. In the context of commercial VPN providers, it's usually just a code security audit -- are there any memory leaks? Is sensitive data being passed around a little bit too loosely? Is there some way for unprivileged users to gain privilege escalation by crafting a malicious request against one of your services? In this sense, they're val…

Well... using PureVPN as an example. They claim that they have been audited twice.

First audit, from 2019: https://my.purevpn.com/pdf/Privacy_No_Log_Audit_Report.pdf

I tried to contact the auditor, Altius IT, in order to confirm whether exfiltrating connection data to a third party would result in the audit failure. They replied, but in a very vague way (refused to answer any questions regarding Altius IT's audit of PureVPN's environment). Well, at least they confirmed indirectly that the audit did exist.

Second audit, from 2023: https://www.purevpn.com/wp-content/uploads/2023/07/KPMG_Pure...

I tried to contact KPMG to verify the authenticity of that report, and also asked the same question - "whether deliberate real-time exfiltration of origin IP addresses, assigned VPN IP addresses, connection timestamps, or connected user activities to a third party by PureVPN, without PureVPN (as opposed to that hypothetical third party) storing anything locally in any form of logs, would have constituted a failure of the privacy assessment." Result: no reply from KPMG at all, so I cannot be sure even that the report indeed comes from KPMG and is not a fake.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#132
post #118

> freshly built kernel, no traces of any log files, and a fully patched OS Wouldn't using a disk in read-only mode accomplish the same thing?

Disks don’t always have a readonly switch these days, though I do still miss the physical notch on floppy disks, and no third-party auditing could exist for proving that switch to be set correctly.

No third-party auditing could exist that proves you only have RAM in the system and don't have a secret disk in there with a magnetic reed switch in-line with the SATA power cable such that without sticking a magnet on the case the disk doesn't show up. Or that you aren't booting off a USB drive that you plug in only after the auditors leave.

Third-party audits are a scam to begin with and don't prove anything.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#133
post #42

Earlier quoted context omitted.

> Some pour thousands of dollars into forcing influencers to say they care about security, Tangential to this, it always irks me how they talk about how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in. HTTPS isn't a cure all by any means but most of the scare tactics that the big VPN compan…

> how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in. I hear most of them saying "Don't want your ISP spying on where you're browsing? Use a VPN." Which HTTPS does not cover.

Providers, at least in Europe, are much more strongly regulated than “vpN ProVidErs” re: privacy and everything else.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#134

Earlier quoted context omitted.

Audits are IMO worthwhile, but end users should be aware of the scope of an audit. In the context of commercial VPN providers, it's usually just a code security audit -- are there any memory leaks? Is sensitive data being passed around a little bit too loosely? Is there some way for unprivileged users to gain privilege escalation by crafting a malicious request against one of your services? In this sense, they're val…

Well... using PureVPN as an example. They claim that they have been audited twice. First audit, from 2019: https://my.purevpn.com/pdf/Privacy_No_Log_Audit_Report.pdf I tried to contact the auditor, Altius IT, in order to confirm whether exfiltrating connection data to a third party would result in the audit failure. They replied, but in a very vague way (refused to answer any questions regarding Altius IT's audit of…

There are bad auditors, of course. Having had the displeasure of working with KPMG (not in a code-security-audit setting, mercifully), I genuinely don't understand how their staff can be allowed within a ten mile radius of source code.

The ideal way to authenticate audits IMO would be for the audited entity to link back to a PDF or other report hosted on the auditor's site.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#135
post #42

Earlier quoted context omitted.

> Some pour thousands of dollars into forcing influencers to say they care about security, Tangential to this, it always irks me how they talk about how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in. HTTPS isn't a cure all by any means but most of the scare tactics that the big VPN compan…

I’d agree with you about HTTPS providing most of the benefit that VPN advertising focuses on if I hadn’t seen repeated direct evidence that even most technical users will blithely click through HTTPS errors’ “accept the risk” bypass. It’s as if knowledgeable users think “sure, this could be a man in the middle attack, but it’s most likely just a benign cert problem, because certs are hard.” Sigh.

>if I hadn’t seen repeated direct evidence that even most technical users will blithely click through HTTPS errors’ “accept the risk” bypass

As far as I recall this is not possible on Chrome if you are MITM'd. If the cert presented doesn't match the cert in the HSTS cache, there is no option to bypass. If the server's cert is expired, then you do indeed see the option, but an expired certificate doesn't necessarily mean danger.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#136

Earlier quoted context omitted.

> Anyway, there's also the looming "threat" (lol) of HTTPS and encrypted DNS proliferation and improvement making the core use case for commercial VPNs obsolete For a lot of people the core use case is accessing Netflix in a different country!

If you have to pay for safe, encrypted DNS, how is that substantially different than using a VPN? Still need an external service.

You can use dns over https over tor(dohot)[1]. Safer than a vpn if you dont mind your isp knowing you go to tor. 1.https://github.com/alecmuffett/dohot

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#137

"They" will just spray the machines with liquid nitrogen, pull them out of the rack, put the DRAM in a thermos w/ LN2 and read the data at their leisure. https://ieeexplore.ieee.org/document/8388826

The word "just" is doing some heavy lifting here... To "just" do this, the agent would need to more or less completely take over the building infrastructure before Mullvad could react which is a lot easier said than done. Even if it were trivial it's still quite a few cuts above any competing VPN service.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#138
post #42

Earlier quoted context omitted.

> Some pour thousands of dollars into forcing influencers to say they care about security, Tangential to this, it always irks me how they talk about how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in. HTTPS isn't a cure all by any means but most of the scare tactics that the big VPN compan…

> how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in. I hear most of them saying "Don't want your ISP spying on where you're browsing? Use a VPN." Which HTTPS does not cover.

With HTTPS, ISPs can see _where_ you are browsing, but not _what_ you are browsing. Of course them seeing the top level domain still violates certain aspects of privacy, personally I’d prefer ISPs couldn’t even see that. But it’s not like they are peering into the actual content of what you are browsing.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#139

Earlier quoted context omitted.

3. You live in a country where your ISP is legally mandated to record all of your browsing history and make it available to the government. 4. You live in a country where certain websites are blocked because the government doesn’t agree with them, or because those websites don’t want to deal with your country.

Those countries probably block VPN services, especially the popular ones which buy all the ads.

There are some countries that block VPNs but there’s also many countries that don’t. For example, TPB is blocked in UK by court order but VPNs work just fine.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#140

Earlier quoted context omitted.

Simply not an issue for nearly everyone.

Until it happens to you.

No, even if it happened to me it would not be relevant for the vast majority.
Post reply on HN