Live data from Hacker News

Mullvad: Diskless infrastructure using stboot in beta

mullvad.net

21–30 of 135 posts

Re: Mullvad: Diskless infrastructure using stboot in beta

#21
post #16

A bit tangential to the main post, but I'd to share a recent positive experience with Mullvad: I am a regular user of Mullvad and recently wanted to try a different VPN, that only provides Wireguard configs (i.e. no native app). I used the default setup. For some reason, my internet connection was flaky, and when it disconnected and reconnected, my traffic leaked. That never happened to me with Mullvad as the app com…

On linux you can create a network namespace exposing only the wireguard network device, so that applications in that namespace cannot leak traffic. Setting this up, however, is quite fiddly in my experience.

Re: Mullvad: Diskless infrastructure using stboot in beta

#22
post #16

A bit tangential to the main post, but I'd to share a recent positive experience with Mullvad: I am a regular user of Mullvad and recently wanted to try a different VPN, that only provides Wireguard configs (i.e. no native app). I used the default setup. For some reason, my internet connection was flaky, and when it disconnected and reconnected, my traffic leaked. That never happened to me with Mullvad as the app com…

Agree, Mullvad provides really good VPN service. I faced almost zero downtimes / speed throttles. It establishes quick connection with server (maybe because it uses wireguard). Anyway, I'm a regular user and I think paying 5E worth it.

Re: Mullvad: Diskless infrastructure using stboot in beta

#23
post #19

Earlier quoted context omitted.

We assume it is, just like we assume CPU works as advertised. In other words, TPM is part of TCB.

So what is the point? I already assume the code on their server is not malicious by using it. What extra trust does an untrusted TPM chip give me?

It reduces TCB. TPM is smaller than entire server.

Re: Mullvad: Diskless infrastructure using stboot in beta

#25
The server configuration (and therefore customers account numbers) is stored in Server OS images I suppose, right ? It shouldn't be an issue as far as inspection is concerned, should it ?

Also, isn't there a law that enforces logs to be kept for n years ? How is it compatible with diskless setup ?

Re: Mullvad: Diskless infrastructure using stboot in beta

#26
post #10

For people wondering how the hell a user can audit the server is diskless or whatever, the goal appears to be using TPM to provide remote attestation for all code in the boot path. See https://www.system-transparency.org/ .

Correct! Thank you for highlighting that.

Here are some additional details for those interested. We intend to make use of TPM for remote attestation of the current boot chain, reproducible builds to provide a strong link from source code to build artifacts, and a transparency log for a historical record of previously used boot chains, artifacts, WireGuard server keys, and related signatures.

As dtx1 mentioned elsewhere in this thread, diskless VPN infrastructure is currently in use by many other VPN providers. That is not a novel feature of course. What is novel is user-auditability of running VPN infrastructure. We were the first VPN provider to state our intention to make our infrastructure user-auditable AND provide a realistic roadmap with the specific technologies needed to do so. See the link above.

I believe the technologies we use in System Transparency will ultimately reshape the VPN provider industry into a highly competitive space focused on maximizing the transparency of VPN infrastructure. Or not, but at least OUR users will be able to audit us. :)

Either way we’re looking forward to the future. The opportunity for improvement is immense.

Re: Mullvad: Diskless infrastructure using stboot in beta

#27
post #7
post #4

Earlier quoted context omitted.

if only there was any proof of this actually being the case and there not being some "accidental" debug log enabled, or some other network level component having "accidental" access to the keys. There's just no good answer to perfect trust-no-one private internet access. If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your ow…

> There's just no good answer to perfect trust-no-one private internet access. What about Tor?

Not sure I would call Tor "perfect", but it's certainly very useful for some use-cases.

Re: Mullvad: Diskless infrastructure using stboot in beta

#28
post #18
post #4

Earlier quoted context omitted.

if only there was any proof of this actually being the case and there not being some "accidental" debug log enabled, or some other network level component having "accidental" access to the keys. There's just no good answer to perfect trust-no-one private internet access. If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your ow…

> If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your own VPN endpoint on a server you control which provides better privacy guarantees compared to a centralised commercial VPN whose business model will eventually involve selling your data (once user growth stops but shareholders demand continued revenue growth). Well not re…

Do you actually pirate music or did you give it as a general example? I feel no need to pirate music today with all the music streaming services especially since I can find all the music I want on all the streaming services which is a world of difference compared to the video streaming services

Re: Mullvad: Diskless infrastructure using stboot in beta

#29
post #8

Earlier quoted context omitted.

Is no-trust ever possible? I thought people create their threat models and verify they can trust those they have to trust.

> people create their threat models and verify they can trust those they have to trust What kind of people? How do you verify you can trust some company?

Everyone does it informally to varying degrees for varying problems (often times subconsciously). E.g. "What do I know about this person? Can I trust them around my kids?"

You verify trustworthiness by research. Who is involved? Do I trust anyone who trusts them? What are their motivations? What would cause them to take action against me? What causes them to protect my interests? What laws are they subjected to (i.e. who can coerce them)? What do they say for themselves? Where do their words fall on the credibility to BS scale? What is their reputation in the community? What do their competitors/adversaries say? What would cause their behavior to change?

I won't enumerate all my research on Mullvad. I can say Mozilla attaching their brand to Mullvad's services helped me a lot (trust by proxy). I'll also say that some of their product decisions give credibility to their anonymity claims. Lastly, I found someone who shared a competitive analysis across many providers. I found the analysis trustworthy. Mullvad has some weak points, but was still the best provider for my particular use case.

Re: Mullvad: Diskless infrastructure using stboot in beta

#30
post #7
post #4

Earlier quoted context omitted.

if only there was any proof of this actually being the case and there not being some "accidental" debug log enabled, or some other network level component having "accidental" access to the keys. There's just no good answer to perfect trust-no-one private internet access. If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your ow…

> There's just no good answer to perfect trust-no-one private internet access. What about Tor?

I think that if enough exit nodes would be owned by let's say government agencies they would be able to correlate requested domains with actual requester IP.
Post reply on HN