I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".
This has never made any sense to me. I'm surprised this isn't a massive red flag from anyone on HN. Running a production-grade service with zero metrics and logs? If there's an outage, or even something as mundane as a VM failing to provision, you're telling me that Mullvad developers just shrug and say "well, we can't do anything, because there's no logs!" I don't use a third party VPN, but if I wanted to, "we delib…
We have successfully completed our migration to RAM-only VPN infrastructure
51–60 of 195 posts
Re: We have successfully completed our migration to RAM-only VPN infrastructure
#52Earlier quoted context omitted.
Even if that attacks has close to 100% success rate, I'd imagine it being nigh physically impossible to execute a targeted attack, as you don't know which machine to hit for a specific user. And that seems to be the main threat model we would be concerned about for this.
Of course they know which machine to hit. How do you do customer service without such a basic function?
Re: We have successfully completed our migration to RAM-only VPN infrastructure
#53I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".
This has never made any sense to me. I'm surprised this isn't a massive red flag from anyone on HN. Running a production-grade service with zero metrics and logs? If there's an outage, or even something as mundane as a VM failing to provision, you're telling me that Mullvad developers just shrug and say "well, we can't do anything, because there's no logs!" I don't use a third party VPN, but if I wanted to, "we delib…
Ditto for logging. They claim to not log activity over the VPN itself, but I don't see any claims about not logging more mundane infra stuff like "a VM failed to provision". I think you're arguing here against claims they aren't making.
Re: We have successfully completed our migration to RAM-only VPN infrastructure
#54Earlier quoted context omitted.
you can send logs and metrics over the network. the important part to users is not logging the traffic info
Sending them over the network to where? "We don't store logs" means they certainly aren't being ingested into any persistent storage. I'm highly interested in how one can run time-series queries over /dev/null.
Re: We have successfully completed our migration to RAM-only VPN infrastructure
#55I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".
Like, how would that even work? Without a court gag order, gossip would make its way out of the building in weeks. The cell phone shit only was only quasi-secret because only police department employees were involved, something that's impossible for these VPN outfits. They don't get any of the (unjustified) privilege that the CIA or NSA (or even the FBI, sometimes) receive.
Anything I might do that could pique the curiosity of law enforcement is definitely below the level of federal intelligence agency interest. Maybe your life is more exciting though.
Re: We have successfully completed our migration to RAM-only VPN infrastructure
#56I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".
Re: We have successfully completed our migration to RAM-only VPN infrastructure
#57This is really cool, you'd expect any VPN provider that cares about security and transparency to act like Mullvad. Some pour thousands of dollars into forcing influencers to say they care about security, while others focus on actually improving security. And it's all open source btw. https://github.com/system-transparency/stboot
> Some pour thousands of dollars into forcing influencers to say they care about security, Tangential to this, it always irks me how they talk about how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in. HTTPS isn't a cure all by any means but most of the scare tactics that the big VPN compan…
Re: We have successfully completed our migration to RAM-only VPN infrastructure
#58I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".
Re: We have successfully completed our migration to RAM-only VPN infrastructure
#59Earlier quoted context omitted.
And the court of public opinion. By the time lawyers and judges are involved, unless you are very lucky, your name and photo is all over the tabloids. Any retractions published when you are later found completely innocent will be the equivalent of a column inch or two on page 17.
Simply not an issue for nearly everyone.
Re: We have successfully completed our migration to RAM-only VPN infrastructure
#60Earlier quoted context omitted.
It's essentially a PXE-boot diskless environment, what makes you think it is unusual and possibility of being unreliable?
I should say, unsuitable for certain use cases.