Live data from Hacker News

We have successfully completed our migration to RAM-only VPN infrastructure

mullvad.net

81–90 of 195 posts

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#81

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

I formerly worked for a somewhat-older mainstream consumer VPN provider for a few years, to the extent that you can take my word for it, this is not industry-standard practice at least as far as the provider is able to control it. Commercial VPNs typically run on rental servers -- usually a mix of the major cloud providers and smaller hosting providers -- and in my former company's case, using dedicated hosting (bare…

> Anyway, there's also the looming "threat" (lol) of HTTPS and encrypted DNS proliferation and improvement making the core use case for commercial VPNs obsolete

For a lot of people the core use case is accessing Netflix in a different country!

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#82
post #56

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

What evidence makes you believe this is happening?

Historical: Room 641A at AT&T in the US.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#83
post #42
post #2

This is really cool, you'd expect any VPN provider that cares about security and transparency to act like Mullvad. Some pour thousands of dollars into forcing influencers to say they care about security, while others focus on actually improving security. And it's all open source btw. https://github.com/system-transparency/stboot

> Some pour thousands of dollars into forcing influencers to say they care about security, Tangential to this, it always irks me how they talk about how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in. HTTPS isn't a cure all by any means but most of the scare tactics that the big VPN compan…

> how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in.

I hear most of them saying "Don't want your ISP spying on where you're browsing? Use a VPN." Which HTTPS does not cover.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#84
post #58

Earlier quoted context omitted.

If you're that compromised, wouldn't it be much easier to just log and lie about it?

Lying about it opens you up to potential litigation and being exposed through discovery. It makes less sense to outwardly lie to paying customers rather than simply lie by omission.

I can just imagine EFF drooling over such a prospect.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#85

Earlier quoted context omitted.

I formerly worked for a somewhat-older mainstream consumer VPN provider for a few years, to the extent that you can take my word for it, this is not industry-standard practice at least as far as the provider is able to control it. Commercial VPNs typically run on rental servers -- usually a mix of the major cloud providers and smaller hosting providers -- and in my former company's case, using dedicated hosting (bare…

> Anyway, there's also the looming "threat" (lol) of HTTPS and encrypted DNS proliferation and improvement making the core use case for commercial VPNs obsolete For a lot of people the core use case is accessing Netflix in a different country!

This is also true and shockingly difficult to do reliably.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#86

Earlier quoted context omitted.

You don't have to explain anything to cops. You explain it to lawyers and judges.

You actually shouldn't even say anything to the cops. If they show up with a warrant for arrest as well as search, you're going to jail no matter what you say. If they show up with just a search warrant, they are going to take whatever they want to take whether its outside the purview of the warrant or not. It will be up to a lawyer to convince a judge it was out of scope at a later date after it has already been tak…

> You actually shouldn't even say anything to the cops.

Unless you're in the UK, in which case: "You do not have to say anything. But it may harm your defense if you do not mention when questioned something which you later rely on in court. Anything you do say may be given in evidence."

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#87
post #4

Earlier quoted context omitted.

There is no disk in the servers, so there is no chance for user information to persist anywhere. I also wouldn’t be surprised if it’s a performance benefit, since RAM is far faster than any permanent storage. The cons are probably just that this is a pretty unusual architecture that they probably had to put some work into setting up and making it reliable.

Technically, researchers have proven that you can shutdown a machine, hit the RAM with a cold spray (like liquid nitrogen) and keep the bits "alive" long enough to dump them for analysis. But, obviously, that's pretty insane. Agree with everything that this is a big leap in the step of better protection for users.

There's a fairly easy physical mitigation for this.

Once DIMMs are seated, secure the ends with superglue, then brush conformal coating over the bus traces.

The second step is likely not even necessary if the motherboard is a 4 layer pcb with traces in the middle.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#88
post #56

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

What evidence makes you believe this is happening?

[deleted]

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#89

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

Even with an honest company, the pressures on them are twofold – security and legal. Their systems can be compromised through security vulnerabilities and social engineering (including coercion – money, ideology, compromise, ego – classic psyops playbook). Or they can get legal government orders - which pretty much every government in the world have laws on books and operational practices to force any actor to hand-over data in the name of fighting money laundering and terrorism (AML/CFT). It is very expensive to put up strong defenses against these. I don't see a viable business model charging $5/month that covers regular operational expenses and covers these types of events.

Edit: Forgot to mention backdoors built into basic technologies they may already be using – like the Cavium HSM thing that came to light earlier this week.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#90
post #58

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

If you're that compromised, wouldn't it be much easier to just log and lie about it?

this is what "warrant canaries" are for. dont use anyone who doesnt have one
Post reply on HN