Live data from Hacker News

We have successfully completed our migration to RAM-only VPN infrastructure

mullvad.net

1–10 of 195 posts

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#2
This is really cool, you'd expect any VPN provider that cares about security and transparency to act like Mullvad. Some pour thousands of dollars into forcing influencers to say they care about security, while others focus on actually improving security.

And it's all open source btw. https://github.com/system-transparency/stboot

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#4
post #3

Can somebody explain in more detail - what does this mean for the user? What are pros and cons?

There is no disk in the servers, so there is no chance for user information to persist anywhere.

I also wouldn’t be surprised if it’s a performance benefit, since RAM is far faster than any permanent storage.

The cons are probably just that this is a pretty unusual architecture that they probably had to put some work into setting up and making it reliable.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#6
post #4
post #3

Can somebody explain in more detail - what does this mean for the user? What are pros and cons?

There is no disk in the servers, so there is no chance for user information to persist anywhere. I also wouldn’t be surprised if it’s a performance benefit, since RAM is far faster than any permanent storage. The cons are probably just that this is a pretty unusual architecture that they probably had to put some work into setting up and making it reliable.

It's essentially a PXE-boot diskless environment, what makes you think it is unusual and possibility of being unreliable?

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#7
post #4
post #3

Can somebody explain in more detail - what does this mean for the user? What are pros and cons?

There is no disk in the servers, so there is no chance for user information to persist anywhere. I also wouldn’t be surprised if it’s a performance benefit, since RAM is far faster than any permanent storage. The cons are probably just that this is a pretty unusual architecture that they probably had to put some work into setting up and making it reliable.

Technically, researchers have proven that you can shutdown a machine, hit the RAM with a cold spray (like liquid nitrogen) and keep the bits "alive" long enough to dump them for analysis.

But, obviously, that's pretty insane. Agree with everything that this is a big leap in the step of better protection for users.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#8
One thing that I always wondered from VPNs.

Let's say a pedophile uses Mullvad to get forbidden images, isn't the VPN liable?

I mean, the law enforcement will see that the IP was from Mullvad's office, so I assume they are the ones doing it? How do they avoid this?

It is a real doubt. Maybe stupid, but real.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#9
post #4

Earlier quoted context omitted.

There is no disk in the servers, so there is no chance for user information to persist anywhere. I also wouldn’t be surprised if it’s a performance benefit, since RAM is far faster than any permanent storage. The cons are probably just that this is a pretty unusual architecture that they probably had to put some work into setting up and making it reliable.

Technically, researchers have proven that you can shutdown a machine, hit the RAM with a cold spray (like liquid nitrogen) and keep the bits "alive" long enough to dump them for analysis. But, obviously, that's pretty insane. Agree with everything that this is a big leap in the step of better protection for users.

Even if that attacks has close to 100% success rate, I'd imagine it being nigh physically impossible to execute a targeted attack, as you don't know which machine to hit for a specific user. And that seems to be the main threat model we would be concerned about for this.

Re: We have successfully completed our migration to RAM-only VPN infrastructure

#10
post #4
post #3

Can somebody explain in more detail - what does this mean for the user? What are pros and cons?

There is no disk in the servers, so there is no chance for user information to persist anywhere. I also wouldn’t be surprised if it’s a performance benefit, since RAM is far faster than any permanent storage. The cons are probably just that this is a pretty unusual architecture that they probably had to put some work into setting up and making it reliable.

You can still mount a remote networked file system to a dikless node. Lack of disks does not guarantee inability to persist data.
Post reply on HN