Live data from Hacker News

We have successfully completed our migration to RAM-only VPN infrastructure

mullvad.net

171–180 of 195 posts

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#171

Earlier quoted context omitted.

Pretty sure if they live by themself and nobody else comes into their dwelling and there is no other name attachef to their subscriber info it does

What if they are on cellular and that hasn't been upgraded to IPv6? Years ago I handled fraud cases for an e-commerce site with local police, at some point they started asking for IP and port numbers for the offenders, rather than just the IP. Turns out that one of the cellular phone providers had basically run out of IPv4 addresses for their 4G network and did some NAT solution. If you didn't have the port number th…

Do you know if there's a guide about all the ipv4/6 stuff and optimal internet settings for Mac or more high-level generally?

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#172

Earlier quoted context omitted.

For me, the pool of people to hire that know Linux inside and out would be much larger. This is worth any perceived security issues. In terms of diskless, I've run 25k+ iPXE deployments on diskless blade servers using a highly customized Ubuntu, and it was fantastic. Regardless of OS choice, being diskless is also quite nice... if there was a security issue or you need an upgrade of some sort, you just reboot. Only t…

I guess that is some of their focus around why they got their image down to 200MB. Even better if you had boxes with 10 gigE and the smaller image. Would take your times down from like 6-10 hours to 1.5 hours. Also, I doubt a full 25k restart all at once you probably had underlying applications that expected rolling, blue/green or even % or nodes that can go offline at once.

Full boot was around 160MB and that included AMD drivers, which were about 60MB.

I did not have a choice over the hardware design.

Each worker was individual. Underlying application didn’t care.

We had a couple full power outages. They were set to boot automatically. So yea… full restarts.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#173

Earlier quoted context omitted.

For me, the pool of people to hire that know Linux inside and out would be much larger. This is worth any perceived security issues. In terms of diskless, I've run 25k+ iPXE deployments on diskless blade servers using a highly customized Ubuntu, and it was fantastic. Regardless of OS choice, being diskless is also quite nice... if there was a security issue or you need an upgrade of some sort, you just reboot. Only t…

Not sure the actual authors of the various overlapping Linux network subsystems even know the comprehensive picture "inside and out" for chronic lack of consistent documentation. Last time I managed a small «supercomputer», 50x IBM blades running Suse, it wouldn't support PXE/NFS without kernel customization, but that would void support contracts and finicky third-party software. Made a switch to FreeBSD, where every…

Things have improved and ubuntu is better than suse. =)

This was effectively 25k PS5's... much more powerful now.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#174

Earlier quoted context omitted.

Except "no comment" is not a yes. It's a "whether we do or don't, you are not part of that process and not privy to that information either way".

The point of the canary, is to turn any non-answer into a practical, or at least a tentative, "yes". If you no longer see an explicit "no", it means "yes".

So the point of the canary is to turn a proper response into something that's flat out wrong? That seems incredibly counter-productive.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#175

Earlier quoted context omitted.

The point of the canary, is to turn any non-answer into a practical, or at least a tentative, "yes". If you no longer see an explicit "no", it means "yes".

So the point of the canary is to turn a proper response into something that's flat out wrong? That seems incredibly counter-productive.

Wrong? What do you mean?

The difference between a canary and a "no comment" is that "no comment" is an extremely common thing to say whether an allegation is true or not so it's not very suspicious, while stopping a canary is very suspicious.

So it's like the scenario you outlined earlier, but more effective.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#176
post #52

Earlier quoted context omitted.

Mullvad gives you the option to connect to multiple servers. They offer wireguard configs for every endpoint. How does law enforcement know which server the client plans to connect to? There is no metering either, just a flat monthly rate so nothing to track there either.

I find these discussions so tiring. Let me turn it around. In their position, how would you manage this? Might you hook authentication events? Why are you pretending this is hard?

You can connect to mullvad via tor though. If I only ever went to the mullvad site via tor to make an account, paid in monero and only ever accessed the VPN via tor, what is there to hook into?

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#177

Earlier quoted context omitted.

this is what "warrant canaries" are for. dont use anyone who doesnt have one

> This is what "warrant canaries" are for. dont use anyone who doesnt have one What if they have one like this quarterly canary at privacy-forward "write.as" last updated 9 months ago? It should be noted with significance if this message fails to be updated on a quarterly basis. 2023-01-05 21:06:06 UTC No warrants have ever been served to Write.as, or Write.as principals or employees. https://write.as/privacy --> htt…

That means they're either asleep at the wheel or have already been served a warrant.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#178

Earlier quoted context omitted.

So the point of the canary is to turn a proper response into something that's flat out wrong? That seems incredibly counter-productive.

Wrong? What do you mean? The difference between a canary and a "no comment" is that "no comment" is an extremely common thing to say whether an allegation is true or not so it's not very suspicious, while stopping a canary is very suspicious. So it's like the scenario you outlined earlier, but more effective.

No, it isn't. It's pretending that "no comment" means something it doesn't. Just because you want it to mean "yes" doesn't mean it means that. It means "we are not going to comment on this, because we have a sane legal department and we're not going to give you any information one way or another".

If you think "no comment" means either yes or no, you're pretending to know something you don't, and you should absolutely stop and go "wait, why am I lying to myself? And why am I believing my own lie?"

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#179

Earlier quoted context omitted.

Wrong? What do you mean? The difference between a canary and a "no comment" is that "no comment" is an extremely common thing to say whether an allegation is true or not so it's not very suspicious, while stopping a canary is very suspicious. So it's like the scenario you outlined earlier, but more effective.

No, it isn't. It's pretending that "no comment" means something it doesn't. Just because you want it to mean "yes" doesn't mean it means that . It means "we are not going to comment on this, because we have a sane legal department and we're not going to give you any information one way or another". If you think "no comment" means either yes or no, you're pretending to know something you don't, and you should absolute…

Huh?

You're the one that said no comment was suspicious! I said something weaker than that, that it's not very suspicious.

I'm not the one that said a canary failing is a yes. I said it was significantly more suspicious than a no comment.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#180
post #176

Earlier quoted context omitted.

I find these discussions so tiring. Let me turn it around. In their position, how would you manage this? Might you hook authentication events? Why are you pretending this is hard?

You can connect to mullvad via tor though. If I only ever went to the mullvad site via tor to make an account, paid in monero and only ever accessed the VPN via tor, what is there to hook into?

.. that you can connect to Mulvad via tor says nothing _at all_ about what _Mulvad_ can do which was the discussion point.
Post reply on HN