A bit tangential to the main post, but I'd to share a recent positive experience with Mullvad: I am a regular user of Mullvad and recently wanted to try a different VPN, that only provides Wireguard configs (i.e. no native app). I used the default setup. For some reason, my internet connection was flaky, and when it disconnected and reconnected, my traffic leaked. That never happened to me with Mullvad as the app com…
Mullvad: Diskless infrastructure using stboot in beta
41–50 of 135 posts
Re: Mullvad: Diskless infrastructure using stboot in beta
#42For people wondering how the hell a user can audit the server is diskless or whatever, the goal appears to be using TPM to provide remote attestation for all code in the boot path. See https://www.system-transparency.org/ .
Correct! Thank you for highlighting that. Here are some additional details for those interested. We intend to make use of TPM for remote attestation of the current boot chain, reproducible builds to provide a strong link from source code to build artifacts, and a transparency log for a historical record of previously used boot chains, artifacts, WireGuard server keys, and related signatures. As dtx1 mentioned elsewhe…
I had one technical support question, and I got an immediate response from an actual person who knew this problem, gave me a simple workaround (toggle between wireless connection and not), and told me that a permanent fix was in the works. Likely that fix rolled out because I haven't seen the issue in months.
The idea of an account that doesn't need a password because there's no critical information saved is such a nice one, too.
Keep up the good work - I recommend you to everyone.
Re: Mullvad: Diskless infrastructure using stboot in beta
#43For people wondering how the hell a user can audit the server is diskless or whatever, the goal appears to be using TPM to provide remote attestation for all code in the boot path. See https://www.system-transparency.org/ .
Correct! Thank you for highlighting that. Here are some additional details for those interested. We intend to make use of TPM for remote attestation of the current boot chain, reproducible builds to provide a strong link from source code to build artifacts, and a transparency log for a historical record of previously used boot chains, artifacts, WireGuard server keys, and related signatures. As dtx1 mentioned elsewhe…
I think I could get behind more of this use!
Re: Mullvad: Diskless infrastructure using stboot in beta
#44Earlier quoted context omitted.
I stopped pirating music a while ago when spotify became better than what the trackers i was on delivered. That being said, i have recently started looking into it again since spotify is dragging their asses on high quality streaming and their app support on linux started to annoy me. The alternative streaming services barely support linux at all so they aren't really an alternative for me. But you are right it's mos…
Have you tried youtube music (via youtube premium)? I'm not sure about the high quality audio part because I only listen via bluetooth. The recommendations, general app UX and the fact that I can listen via website on desktop have made me cancel spotify.
Generally I don't care much about the UI of any of the services offered and being browser based doesn't really make it any better for me. I can do that with spotify and most other services as well. What I would like to have is a simple paid service with high quality flacs that has an open enough API that i can use many of the great open source tools available and download music for offline use on my phone (data caps and all) without jumping through a lot of hoops. It's not music management is an unsolved problem and for local music i have tons of great options on all my devices from TUI applications to applications with great desktop integration to great open source phone apps. With Spotify there are at least some projects that work somewhat but not really well and certainly nothing that i can easily integrate into my desktop or phone without relying on proprietary clients.
But honestly before I go around trying endless services to get a decent experience I'd rather just take the red music tracker test [1] and build a local collection that "just works" and be done with it.
Re: Mullvad: Diskless infrastructure using stboot in beta
#45> The law permits the signals intelligence agency, National Defense Radio Establishment, to monitor the content of all cross-border cable-based Internet traffic to combat "external threats" such as terrorism and organized crime.
[0]: https://www.opendemocracy.net/en/can-europe-make-it/didier-b...
[1]: https://en.wikipedia.org/wiki/Internet_in_Sweden#Internet_ce...
Re: Mullvad: Diskless infrastructure using stboot in beta
#46> If the computer is powered off, moved or confiscated, there is no data to retrieve. Don't forget to add insta-shutdown when any USB device is connected to the system!
Re: Mullvad: Diskless infrastructure using stboot in beta
#47I've been following Mullvad for a long time and my impression (from countless reviews and comments here on HN) has been quite positive. But here's what I don't understand: Why are the servers located in Sweden, a country that's known for online surveillance[0] like no other country in the EU? From the Wikipedia article[1]: > The law permits the signals intelligence agency, National Defense Radio Establishment, to mon…
Re: Mullvad: Diskless infrastructure using stboot in beta
#48Earlier quoted context omitted.
> There's just no good answer to perfect trust-no-one private internet access. What about Tor?
I think that if enough exit nodes would be owned by let's say government agencies they would be able to correlate requested domains with actual requester IP.
Re: Mullvad: Diskless infrastructure using stboot in beta
#49A bit tangential to the main post, but I'd to share a recent positive experience with Mullvad: I am a regular user of Mullvad and recently wanted to try a different VPN, that only provides Wireguard configs (i.e. no native app). I used the default setup. For some reason, my internet connection was flaky, and when it disconnected and reconnected, my traffic leaked. That never happened to me with Mullvad as the app com…
On linux you can create a network namespace exposing only the wireguard network device, so that applications in that namespace cannot leak traffic. Setting this up, however, is quite fiddly in my experience.
Re: Mullvad: Diskless infrastructure using stboot in beta
#50Earlier quoted context omitted.
>> If you need to hide all of your traffic from other users in your local network, you can accomplish that in a trust-no-one fashion by running your own VPN endpoint on a server you control which provides better privacy guarantees compared to a centralised commercial VPN whose business model will eventually involve selling your data (once user growth stops but shareholders demand continued revenue growth). the privac…
>ie. large number of users sharing the same IP and protects against correlation attacks Depending on where you are based in the world (see https://www.submarinecablemap.com ) realtime throttling of vpn traffic can still identify a user and where they are going in some cases. You can get a degree of privacy from visiting websites located on servers in big data centres, but nothing a search warrant couldnt find out ret…
I think this is a good message. In the same vein, there's no security either. All you can do is make your and your adversaries' life harder, and balance the different tradeoffs.