33 ms·
We have successfully completed our migration to RAM-only VPN infrastructure
- INTPenis 3y agoThis is really cool, you'd expect any VPN provider that cares about security and transparency to act like Mullvad. Some pour thousands of dollars into forcing influencers to say they care about security, while others focus on actually improving security. And it's all open source btw. https://github.com/system-transparency/stboot https://github.com/system-transparency/stboot
- flanfly 3y agoThe work on stboot and it's supporting components, including documentation was moved to it's own Gitlab: https://git.glasklar.is/system-transparency/core/stboot https://git.glasklar.is/system-transparency/core/stboot
- jjice 3y ago> Some pour thousands of dollars into forcing influencers to say they care about security, Tangential to this, it always irks me how they talk about how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in. HTTPS isn't a cure all by any means but most of the scare tactics that the big VPN companies that advertise via YouTube act like anyone will rip you credit card because you happened to be on Amazon while you were at the coffee shop. Tom Scott is the only person I've ever seen have a great video about this [0] [0] https://www.youtube.com/watch?v=WVDQEoe6ZWY https://www.youtube.com/watch?v=WVDQEoe6ZWY
- hamburglar 3y agoI’d agree with you about HTTPS providing most of the benefit that VPN advertising focuses on if I hadn’t seen repeated direct evidence that even most technical users will blithely click through HTTPS errors’ “accept the risk” bypass. It’s as if knowledgeable users think “sure, this could be a man in the middle attack, but it’s most likely just a benign cert problem, because certs are hard.” Sigh.
- noirscape 3y agoTo be frank that's also because the cause for an HTTPS certificate error ranges from "malicious hijack" to "misconfigured server setup" to "I lapsed the expiry date" to "I am using a self-signed certificate". The degree of which these should be scares is not equivalent, yet browsers will treat all of these as equivalent even though they can distinguish between them in the error page. It just results in clickthrough fatigue, where technical users just ignore the warning because it's not worthwhile to deal with even when they really should. Plus a VPN won't protect you from a malicious hijack, it just prevents them from grabbing your IP address.
- maccard 3y agoThe reason the browser doesn't differentiate between them is because the end result is the same - the cett doesn't match the browsers trusted store. The battle has beenosr on self signed certs at this point (unless you're an enterprise, at which point bundle them with your image). The difference between a misconfiguration and a compromise is intention, both should be treated as equally suspicious.
- eximius 3y agoThe problems with clicking past those errors are typically not due to network sniffing but with whatever crazy shit is on the page they are going to. The only two valid usecases of big VPNs like these are 1. Very mild security increase over public wifi 2. Shifting your risk from the ISP spying to mullvad or the VPN provider spying or slightly anonymizing if mullvad rotates IPs. (2) is a real benefit because ISPs are pretty terrible, but it's still pretty minor in the grand scheme of most people's threat models.
- digging 3y agoYeah, I hate my ISP. I am certain they sell every bit of data they can. Ergo, I use a VPN most of the time.
- zarzavat 3y ago3. You live in a country where your ISP is legally mandated to record all of your browsing history and make it available to the government. 4. You live in a country where certain websites are blocked because the government doesn’t agree with them, or because those websites don’t want to deal with your country.
- robertlagrant 3y ago> how they all act as if the majority of the websites their users are going to aren't HTTPS and they act like their main benefits are filling in the gaps that HTTPS actually fills in. I hear most of them saying "Don't want your ISP spying on where you're browsing? Use a VPN." Which HTTPS does not cover.
- deleted 3y ago[deleted]
- mmarq 3y agoProviders, at least in Europe, are much more strongly regulated than “vpN ProVidErs” re: privacy and everything else.
- robertlagrant 3y agoI imagine it's the reputation of the provider that's the main driver, not the regulation.
- mardifoufs 3y agoWhich can be a bad thing, if you want to access banned websites.
- caseyohara 3y agoWith HTTPS, ISPs can see _where_ you are browsing, but not _what_ you are browsing. Of course them seeing the top level domain still violates certain aspects of privacy, personally I’d prefer ISPs couldn’t even see that. But it’s not like they are peering into the actual content of what you are browsing.
- robertlagrant 3y agoTrue, and with the rise of CDNs it's probably even harder to figure out what's happening. But it still gives them more info than is necessary, given they like keeping logs for the powers that be.
- mika69 3y agoCan somebody explain in more detail - what does this mean for the user? What are pros and cons?
- dangus 3y agoThere is no disk in the servers, so there is no chance for user information to persist anywhere. I also wouldn’t be surprised if it’s a performance benefit, since RAM is far faster than any permanent storage. The cons are probably just that this is a pretty unusual architecture that they probably had to put some work into setting up and making it reliable.
- Daviey 3y agoIt's essentially a PXE-boot diskless environment, what makes you think it is unusual and possibility of being unreliable?
- dangus 3y agoI should say, unsuitable for certain use cases.
- johnklos 3y agoI have servers which have literally been running non-stop for multiple years. Unless / until the kernel itself needs to be upgraded for security issues, and so long as backup power is good, they can run indefinitely.
- justapassenger 3y agoNot a best setup to run database, yes. But stateless farm of servers that essentially forward the traffic for you? Not that much downsides.
- Brian_K_White 3y agoWhat important things do you store only in ram? Why not? Isn't it reliable? I think they just mean ephemeral.
- kwanbix 3y agoOne thing that I always wondered from VPNs. Let's say a pedophile uses Mullvad to get forbidden images, isn't the VPN liable? I mean, the law enforcement will see that the IP was from Mullvad's office, so I assume they are the ones doing it? How do they avoid this? It is a real doubt. Maybe stupid, but real.
- jameskilton 3y agoI am not a lawyer, but my understanding is that this generally falls under Section 230, as you can make the same argument about Comcast, AT&T, et.al. who lets the bytes go over their infrastructure.
- kwanbix 3y agoBut the difference is that Comcast, AT&T, et.al can say, jameskilton was using this IP. The VPN is saying, I don't know.
- manishsharan 3y agoand then suppose you login to that VPN and are looking up children's sweaters for your kids and keep the session on .. while law enforcement is looking up the ip address associated with the earlier activity which is now assigned to you . Good luck explaining to the the cops about VPNs and IP addresses. This is my fear.
- flkenosad 3y ago
- HPsquared 3y agoI wonder about those VPNs that say "we don't log or store anything". That may be the case, but they probably just send a continuous stream of data to the law enforcement / intelligence services or whoever instead of storing it themselves. They can then correctly say "WE don't log".
- aaomidi 3y agohttps://www.assured.se/publications/Assured_Mullvad_relay_server_audit_report_2022.pdf https://www.assured.se/publications/Assured_Mullvad_relay_se... Honestly I don’t think audits are worth anything. But it’d be a huge conspiracy to mess with so many parties.
- foobiekr 3y agoThis is a sec eval. It doesn’t eval what the service can do.
- Ajedi32 3y agoSections 2.1.1 and 3.1.18
- verandaguy 3y agoAudits are IMO worthwhile, but end users should be aware of the scope of an audit. In the context of commercial VPN providers, it's usually just a code security audit -- are there any memory leaks? Is sensitive data being passed around a little bit too loosely? Is there some way for unprivileged users to gain privilege escalation by crafting a malicious request against one of your services? In this sense, they're valuable. As someone working in software, I can figure out if the bugs were subtle or blatant, which is often a good proxy metric for the competence of the team behind the product. Are the same bugs cropping up year after year, even if they've already been previously fixed in other parts of the code? Again, a good red flag to use there. Audits do not and often cannot cover things like "is the company reselling connection/user metadata to other companies," though, and in most cases consumers will care that there is an audit rather than caring what's in the audit.
- PaulHoule 3y ago"They" will just spray the machines with liquid nitrogen, pull them out of the rack, put the DRAM in a thermos w/ LN2 and read the data at their leisure. https://ieeexplore.ieee.org/document/8388826 https://ieeexplore.ieee.org/document/8388826
- sneak 3y agoWith modern encryption protocols, this yields you nothing. The feature is called Perfect Forward Secrecy, and protects past flows from later key compromise. Wireguard supports this, which is what Mullvad uses. (For some reason, speculation about which is an exercise left to the reader, WPA in Wi-Fi still does not.)
- woodruffw 3y agoNot exactly nothing, just not ongoing compromise. TLS session keys can be pretty long-lived; I don’t know how long-lived Wireguard’s equivalent keys are, but even a relatively conservative few minutes can yield valuable traffic and metadata. (That being said, I think having your RAM frozen to extract ephemeral secrets is firmly in the “fully hosed” threat model, and is not a realistic model for 99.9% of users to plan for.)
- maccard 3y agoThat seems like significantly more work, and significantly more error prone than pulling an SSD out of a machine and reading from a log file
- skeaker 3y agoThe word "just" is doing some heavy lifting here... To "just" do this, the agent would need to more or less completely take over the building infrastructure before Mullvad could react which is a lot easier said than done. Even if it were trivial it's still quite a few cuts above any competing VPN service.
- Cyphase 3y agoIANAL, but I think "reacting" to a warrant in the way you're implying might be illegal in some places.
- nodesocket 3y agoGreat point brought up in the comments that VM’s allow for snapshotting of entire memory state as well. So something to be aware of.
- infofarmer 3y agoNot to provoke predictable responses, but I find it interesting that the tech-talented VPN providers are not using BSD in favor of Linux, especially with requirements like diskless operation, kernel customization, and tighter security.
- latchkey 3y agoFor me, the pool of people to hire that know Linux inside and out would be much larger. This is worth any perceived security issues. In terms of diskless, I've run 25k+ iPXE deployments on diskless blade servers using a highly customized Ubuntu, and it was fantastic. Regardless of OS choice, being diskless is also quite nice... if there was a security issue or you need an upgrade of some sort, you just reboot. Only thing is that it takes a while to reboot 25k servers... even on gigE. It was a bit of work to build the scheduling system to make that happen reliably, but it worked out quite well.
- infofarmer 3y agoNot sure the actual authors of the various overlapping Linux network subsystems even know the comprehensive picture "inside and out" for chronic lack of consistent documentation. Last time I managed a small «supercomputer», 50x IBM blades running Suse, it wouldn't support PXE/NFS without kernel customization, but that would void support contracts and finicky third-party software. Made a switch to FreeBSD, where everything worked out of the box one hour later. That was over 15 years ago, I have no idea how much the situation changed.
- latchkey 3y agoThings have improved and ubuntu is better than suse. =) This was effectively 25k PS5's... much more powerful now.
- ckdarby 3y agoI guess that is some of their focus around why they got their image down to 200MB. Even better if you had boxes with 10 gigE and the smaller image. Would take your times down from like 6-10 hours to 1.5 hours. Also, I doubt a full 25k restart all at once you probably had underlying applications that expected rolling, blue/green or even % or nodes that can go offline at once.
- nashashmi 3y ago> All of our VPN servers continue to use our custom and extensively slimmed down Linux kernel, where we follow the mainline branch of kernel development. The custom server is a niche security point. While every server is continously researched and patched, we cannot expect the same from a a server like this. If someone were to find a security hole, an attacker would purchase it and no one else would ever know the system was compromised.
- dheera 3y ago> freshly built kernel, no traces of any log files, and a fully patched OS Wouldn't using a disk in read-only mode accomplish the same thing?
- altairprime 3y agoDisks don’t always have a readonly switch these days, though I do still miss the physical notch on floppy disks, and no third-party auditing could exist for proving that switch to be set correctly.
- dheera 3y agoNo third-party auditing could exist that proves you only have RAM in the system and don't have a secret disk in there with a magnetic reed switch in-line with the SATA power cable such that without sticking a magnet on the case the disk doesn't show up. Or that you aren't booting off a USB drive that you plug in only after the auditors leave. Third-party audits are a scam to begin with and don't prove anything.
- altairprime 3y agoA third-party audit can prove that the system functions as shown without a hard drive, and a third-party auditor can, using contractually-authorized random unscheduled spot checks, physically inspect the live deployed servers to confirm the absence of any disk media. Third-party audits prove something. They don't prove everything.
- Brian_K_White 3y agoIf they claim that they possess no data, and after some years and some nontrivial attempts no one has succeeded in extracting data from them, that is not nothing, even if it is not proof.
- crabbone 3y agoDoes pmem count as RAM?
- Nevermark 3y agoNice work! But, if anything should be a decentralized anonymous crypto-paid service, it should be a VPN network. Centralized VPNs are still a single point of failure privacy risk. We have to trust they don't share our identity/account info and activity. I am surprised dVPNs are not THE first rationale given for crypto. I.e. since separately and together they (ideally) have a clear comparative advantage over other alternatives for strong privacy. A performant global open-standard dVPN could become an indispensable layer of web access.
- Spoom 3y agoI wasn't sure what a decentralized VPN would look like, so I searched and found https://surfshark.com/blog/decentralized-vpn https://surfshark.com/blog/decentralized-vpn . Obvious bias coming from a VPN provider, but if they are stating the technology correctly, then I think it's important to determine if this is correct: > A decentralized VPN is a distributed VPN service where volunteers supply your VPN servers instead of a single company – but paid by crypto. Like with regular VPNs, you have to trust that the VPN server isn’t monitoring your data. But instead of there being a single VPN provider company behind it all, you have to trust that none of the thousands of server volunteers are spying on you. Is this a correct understanding of dVPNs? Is there a rebuttal, especially to that last sentence?
- KomoD 3y agoYes, that is correct. It's great for getting residential IPs, but connection quality is much worse
- Nevermark 3y agoNo that isn't accurate. You have a network of VPN point providers. As you communicate, data can be sent through any series of points. Data is encrypted end-to-end, and the addresses for the point providers are also encrypted so that each point can only decrypt and see the next point to forward data to. So each point knows where data last came from, and where they are sending it. But they don't know: 1. Which step of a chain of points the data is at. 2. If they are the first in the chain (i.e. the "from" is the source) 3. If they are the last in the chain (i.e. the "to" is the destination) And (as long as two or more points are traversed, which would be always), no point ever has access to: 4. Both source and destination info. Finally, since payments to each point are handled through a combination of peer-to-peer point bookkeeping, and a crypto block chain account, no point ever knows: 5. Any identity information about who uses the VPN. 6. Any way to identify activity over time that is related. Acting as a point, as well as using the network, serves to further cloak activity, as being from you vs. passed through you. And an alternative to crypto payments, would be earning usage by providing point service. EDIT: > so I searched and found https://surfshark.com/ https://surfshark.com/[...] Any VPN provider that is claiming decentralized VPNs are a greater risk is either misinformed, or willing to misinform users. I wouldn't trust a VPN provider from either category. Actual reasons to not use a dVPN might be that it is a work in progress, not supported well, its source code is not open, or not yet vetted by experts, too slow, not many points yet, etc.
- tamimio 3y agoStill doesn’t protect you against hardware based backdoors, or other types of backdoors like memory injection or supply chain, to get data on the fly > When servers are rebooted or provisioned for the first time, we can be safe in the knowledge that we get a freshly built kernel Any info what’s the period of time doing so? Do you provision them every day, week? An hour maybe? The more the period the less chance of some attack vectors.
- w1nst0nsm1th 3y agoIn north america and europe, VPN are required by law to keep logs of your use of vpn (site you visit, inscription email,...) for 1 or 2 years. Most VPN company advertise they do not keep logs of your browsing... Which would be in infraction with european and american laws. So I don't what to think of diskless VPN.
- Nellyz 3y ago[dead]
- heyraghab 3y ago1.1.1.1?