Live data from Hacker News

We have successfully completed our migration to RAM-only VPN infrastructure

mullvad.net

151–160 of 195 posts

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#151
In north america and europe, VPN are required by law to keep logs of your use of vpn (site you visit, inscription email,...) for 1 or 2 years.

Most VPN company advertise they do not keep logs of your browsing...

Which would be in infraction with european and american laws.

So I don't what to think of diskless VPN.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#152

"They" will just spray the machines with liquid nitrogen, pull them out of the rack, put the DRAM in a thermos w/ LN2 and read the data at their leisure. https://ieeexplore.ieee.org/document/8388826

The word "just" is doing some heavy lifting here... To "just" do this, the agent would need to more or less completely take over the building infrastructure before Mullvad could react which is a lot easier said than done. Even if it were trivial it's still quite a few cuts above any competing VPN service.

IANAL, but I think "reacting" to a warrant in the way you're implying might be illegal in some places.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#153
post #58

Earlier quoted context omitted.

If you're that compromised, wouldn't it be much easier to just log and lie about it?

this is what "warrant canaries" are for. dont use anyone who doesnt have one

> This is what "warrant canaries" are for. dont use anyone who doesnt have one

What if they have one like this quarterly canary at privacy-forward "write.as" last updated 9 months ago?

    It should be noted with significance if this message 
    fails to be updated on a quarterly basis.
    
    2023-01-05 21:06:06 UTC
    
    No warrants have ever been served to Write.as, or 
    Write.as principals or employees.
https://write.as/privacy --> https://write.as/canary.txt

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#154

Earlier quoted context omitted.

3. You live in a country where your ISP is legally mandated to record all of your browsing history and make it available to the government. 4. You live in a country where certain websites are blocked because the government doesn’t agree with them, or because those websites don’t want to deal with your country.

Those countries probably block VPN services, especially the popular ones which buy all the ads.

Certain Russian news websites are DNS blocked in the EU. I haven't heard of anyone having serious issues using a VPN.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#155
post #44

Earlier quoted context omitted.

you can send logs and metrics over the network. the important part to users is not logging the traffic info

Sending them over the network to where? "We don't store logs" means they certainly aren't being ingested into any persistent storage. I'm highly interested in how one can run time-series queries over /dev/null.

you are conflating logs & metrics with user activity logs.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#156

Earlier quoted context omitted.

No that isn't accurate. You have a network of VPN point providers. As you communicate, data can be sent through any series of points. Data is encrypted end-to-end, and the addresses for the point providers are also encrypted so that each point can only decrypt and see the next point to forward data to. So each point knows where data last came from, and where they are sending it. But they don't know: 1. Which step of…

Aren't you just describing Tor?

yes but it has le heckin crypto

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#157
post #56

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

What evidence makes you believe this is happening?

Everyone said this about global surveillance before Snowden and yet. I don't see the value in questioning if this is true or not, rather I think we should assume it's true and act as such, isn't that what modern security is about? (see: HTTPS/DNSSEC/DoH etc)

I frankly wouldn't be surprised if it's actually happening.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#158

Earlier quoted context omitted.

What happens when someone asks you whether you have received a court order of some kind? Are you compelled by court to lie about it?

Why would someone have to lie? They can just say "We can't comment on that" without providing an answer. And then customers can go "sounds pretty suspicious, time to switch VPN services".

That’s kinda my point. A canary removes all the middle ground between a yes and no. Which means no comment = yes.

The parent comment implies that in such a case “no comment” is not compliant with the law, as it informs the inquirer.

Hence the only way to comply is to answer “no”, which is a lie.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#159
post #72

Earlier quoted context omitted.

Pretty sure if they live by themself and nobody else comes into their dwelling and there is no other name attachef to their subscriber info it does

Definitely not. I still am logged into my ex girlfriend wifi so if I wanted to harm her I could easily go stand outside her home at night and download malicious files. That would not make her guilty. They may investigate but that is not proof she did something unlawful.

That's remarkably—err, trusting—of her to not like change her WiFi password after finishing up with you. Yikes

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#160

Earlier quoted context omitted.

Why would someone have to lie? They can just say "We can't comment on that" without providing an answer. And then customers can go "sounds pretty suspicious, time to switch VPN services".

That’s kinda my point. A canary removes all the middle ground between a yes and no. Which means no comment = yes. The parent comment implies that in such a case “no comment” is not compliant with the law, as it informs the inquirer. Hence the only way to comply is to answer “no”, which is a lie.

Except "no comment" is not a yes. It's a "whether we do or don't, you are not part of that process and not privy to that information either way".
Post reply on HN