Live data from Hacker News

We have successfully completed our migration to RAM-only VPN infrastructure

mullvad.net

91–100 of 195 posts

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#91
post #58

Earlier quoted context omitted.

If you're that compromised, wouldn't it be much easier to just log and lie about it?

this is what "warrant canaries" are for. dont use anyone who doesnt have one

There should probably be case law before anyone actually believes in warrant canaries.

'If it's illegal to advertise that you've received a court order of some kind, it's illegal to intentionally and knowingly take any action that has the effect of advertising the receipt of that order. A judge can't force you to do anything, but every lawyer I've spoken to has indicated that having a "canary" you remove or choose not to update would likely have the same legal consequences as simply posting something that explicitly says you've received something. If any lawyers have a different legal interpretation, I'd love to hear it.' --Moxie Marlinspike

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#92

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

That's an... interesting? interpretation of what logging is.

What you've described, to me, is the VPN logging customer activity and then sending it elsewhere to be stored.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#93
post #50

Earlier quoted context omitted.

The likelihood of them showing and doing that is low. However, the likelihood of them showing up with a set of USB drives and just running rsync/cp/dd is higher.

Normally you unplug the drives and take them to a lab. Never let the host operating system continue running with those disks!

Maybe in the 90s. Unplugging the drive is how you kick FDE in now. The drive only has value while mounted and running on the host OS.

Even cellphones...you want them running decrypted, but inside a Faraday cage of some kind to block remote wipes.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#94

Earlier quoted context omitted.

this is what "warrant canaries" are for. dont use anyone who doesnt have one

There should probably be case law before anyone actually believes in warrant canaries. 'If it's illegal to advertise that you've received a court order of some kind, it's illegal to intentionally and knowingly take any action that has the effect of advertising the receipt of that order. A judge can't force you to do anything, but every lawyer I've spoken to has indicated that having a "canary" you remove or choose no…

What happens when someone asks you whether you have received a court order of some kind? Are you compelled by court to lie about it?

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#95
post #56

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

What evidence makes you believe this is happening?

I inferred that they were speculating, not that they had a smoking gun piece of evidence. The word "probably" is what tipped me off, ymmv.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#96
post #50

Earlier quoted context omitted.

Normally you unplug the drives and take them to a lab. Never let the host operating system continue running with those disks!

Maybe in the 90s. Unplugging the drive is how you kick FDE in now. The drive only has value while mounted and running on the host OS. Even cellphones...you want them running decrypted, but inside a Faraday cage of some kind to block remote wipes.

I don’t know how FDE works so thanks for the correction. I’ve read stories about feds pulling out drives and asking for keys later.

But to run dd wouldn’t you need root access? And couldn’t you use that to dump the FDE keys from memory?

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#97

Earlier quoted context omitted.

You actually shouldn't even say anything to the cops. If they show up with a warrant for arrest as well as search, you're going to jail no matter what you say. If they show up with just a search warrant, they are going to take whatever they want to take whether its outside the purview of the warrant or not. It will be up to a lawyer to convince a judge it was out of scope at a later date after it has already been tak…

> You actually shouldn't even say anything to the cops. Unless you're in the UK, in which case: "You do not have to say anything. But it may harm your defense if you do not mention when questioned something which you later rely on in court. Anything you do say may be given in evidence."

As a Yank, that line always felt odd when watching BritCop dramas. How is the alleged meant to know the specifics of a defence when the full charges haven't even been levied, or how is the alleged meant to read the mind of a lawyer? It just feels like something rigging the system

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#98
post #15

Earlier quoted context omitted.

I am not a lawyer, but my understanding is that this generally falls under Section 230, as you can make the same argument about Comcast, AT&T, et.al. who lets the bytes go over their infrastructure.

But the difference is that Comcast, AT&T, et.al can say, jameskilton was using this IP. The VPN is saying, I don't know.

What if you get the same IP time and again?

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#99

I wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".

This has never made any sense to me. I'm surprised this isn't a massive red flag from anyone on HN. Running a production-grade service with zero metrics and logs? If there's an outage, or even something as mundane as a VM failing to provision, you're telling me that Mullvad developers just shrug and say "well, we can't do anything, because there's no logs!" I don't use a third party VPN, but if I wanted to, "we delib…

Metrics are mostly by nature anonymous. Things measured are CPU/Mem usage, network rate. Metrics at IP/user level aren't of much value. Companies add country/device type attr. but they can be done without.

Logs can similarly be of system events only.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#100
post #6
post #4

Earlier quoted context omitted.

There is no disk in the servers, so there is no chance for user information to persist anywhere. I also wouldn’t be surprised if it’s a performance benefit, since RAM is far faster than any permanent storage. The cons are probably just that this is a pretty unusual architecture that they probably had to put some work into setting up and making it reliable.

It's essentially a PXE-boot diskless environment, what makes you think it is unusual and possibility of being unreliable?

What is unusual is the firmware that they have.
Post reply on HN