Live data from Hacker News

We have successfully completed our migration to RAM-only VPN infrastructure

mullvad.net

41–50 of 195 posts

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#41

Earlier quoted context omitted.

IANAL but my understanding of current case law is that it IP address does not automatically mean a particular person.

Pretty sure if they live by themself and nobody else comes into their dwelling and there is no other name attachef to their subscriber info it does

Nope... wardriving? Spoofing? Too much uncertainty to convict with. Basis for a warrant on the property? Yes, probably.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#42
post #2

This is really cool, you'd expect any VPN provider that cares about security and transparency to act like Mullvad. Some pour thousands of dollars into forcing influencers to say they care about security, while others focus on actually improving security. And it's all open source btw. https://github.com/system-transparency/stboot

> Some pour thousands of dollars into forcing influencers to say they care about security,

Tangential to this, it always irks me how they talk about how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in.

HTTPS isn't a cure all by any means but most of the scare tactics that the big VPN companies that advertise via YouTube act like anyone will rip you credit card because you happened to be on Amazon while you were at the coffee shop.

Tom Scott is the only person I've ever seen have a great video about this [0]

[0] https://www.youtube.com/watch?v=WVDQEoe6ZWY

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#43

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

This has never made any sense to me. I'm surprised this isn't a massive red flag from anyone on HN.

Running a production-grade service with zero metrics and logs? If there's an outage, or even something as mundane as a VM failing to provision, you're telling me that Mullvad developers just shrug and say "well, we can't do anything, because there's no logs!"

I don't use a third party VPN, but if I wanted to, "we deliberately eschew all observability" is not a positive selling point.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#44

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

This has never made any sense to me. I'm surprised this isn't a massive red flag from anyone on HN. Running a production-grade service with zero metrics and logs? If there's an outage, or even something as mundane as a VM failing to provision, you're telling me that Mullvad developers just shrug and say "well, we can't do anything, because there's no logs!" I don't use a third party VPN, but if I wanted to, "we delib…

you can send logs and metrics over the network. the important part to users is not logging the traffic info

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#45
post #44

Earlier quoted context omitted.

This has never made any sense to me. I'm surprised this isn't a massive red flag from anyone on HN. Running a production-grade service with zero metrics and logs? If there's an outage, or even something as mundane as a VM failing to provision, you're telling me that Mullvad developers just shrug and say "well, we can't do anything, because there's no logs!" I don't use a third party VPN, but if I wanted to, "we delib…

you can send logs and metrics over the network. the important part to users is not logging the traffic info

Sending them over the network to where? "We don't store logs" means they certainly aren't being ingested into any persistent storage. I'm highly interested in how one can run time-series queries over /dev/null.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#46

Earlier quoted context omitted.

All this would do would be to lead the investigation to get a warrant/subpoena to have the VPN service provide user details about the account and anything else relevant like logs. This is where the "we don't log shit" bullet points comes into play as well as running only from RAM. If the warrant allows for removal of hardware, all data is lost once power is removed. LEOs would have to bring lots of batteries.

or liquid nitrogen. https://en.wikipedia.org/wiki/Cold_boot_attack

If the feds have physical access and considering the high likelihood that these are VMs and not physical, it would be a whole lot easier to get the hypervisor to just snapshot the VM w/ its memory and perform forensics against that file(s).

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#47

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

To claim such a thing you should put up some evidence. I think they are actually streaming all data to the Martians.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#48

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

Given the ridiculous number of VPN providers that say that, how are they keeping the secret exactly?

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#49

Earlier quoted context omitted.

You don't have to explain anything to cops. You explain it to lawyers and judges.

And the court of public opinion. By the time lawyers and judges are involved, unless you are very lucky, your name and photo is all over the tabloids. Any retractions published when you are later found completely innocent will be the equivalent of a column inch or two on page 17.

Maybe if you live in Florida.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#50

Earlier quoted context omitted.

Technically, researchers have proven that you can shutdown a machine, hit the RAM with a cold spray (like liquid nitrogen) and keep the bits "alive" long enough to dump them for analysis. But, obviously, that's pretty insane. Agree with everything that this is a big leap in the step of better protection for users.

The likelihood of them showing and doing that is low. However, the likelihood of them showing up with a set of USB drives and just running rsync/cp/dd is higher.

Normally you unplug the drives and take them to a lab. Never let the host operating system continue running with those disks!
Post reply on HN