5 ms·
Can somebody explain in more detail - what does this mean for the user? What are pros and cons?
by mika69 3y ago
Can somebody explain in more detail - what does this mean for the user? What are pros and cons?
- dangus 3y agoThere is no disk in the servers, so there is no chance for user information to persist anywhere. I also wouldn’t be surprised if it’s a performance benefit, since RAM is far faster than any permanent storage. The cons are probably just that this is a pretty unusual architecture that they probably had to put some work into setting up and making it reliable.
- Daviey 3y agoIt's essentially a PXE-boot diskless environment, what makes you think it is unusual and possibility of being unreliable?
- dangus 3y agoI should say, unsuitable for certain use cases.
- johnklos 3y agoI have servers which have literally been running non-stop for multiple years. Unless / until the kernel itself needs to be upgraded for security issues, and so long as backup power is good, they can run indefinitely.
- justapassenger 3y agoNot a best setup to run database, yes. But stateless farm of servers that essentially forward the traffic for you? Not that much downsides.
- Brian_K_White 3y agoWhat important things do you store only in ram? Why not? Isn't it reliable? I think they just mean ephemeral.
- deleted 3y ago[deleted]
- panick21_ 3y agoWhat is unusual is the firmware that they have.
- thathndude 3y agoTechnically, researchers have proven that you can shutdown a machine, hit the RAM with a cold spray (like liquid nitrogen) and keep the bits "alive" long enough to dump them for analysis. But, obviously, that's pretty insane. Agree with everything that this is a big leap in the step of better protection for users.
- NhanH 3y agoEven if that attacks has close to 100% success rate, I'd imagine it being nigh physically impossible to execute a targeted attack, as you don't know which machine to hit for a specific user. And that seems to be the main threat model we would be concerned about for this.
- foobiekr 3y agoOf course they know which machine to hit. How do you do customer service without such a basic function?
- hiatus 3y agoMullvad gives you the option to connect to multiple servers. They offer wireguard configs for every endpoint. How does law enforcement know which server the client plans to connect to? There is no metering either, just a flat monthly rate so nothing to track there either.
- foobiekr 3y agoI find these discussions so tiring. Let me turn it around. In their position, how would you manage this? Might you hook authentication events? Why are you pretending this is hard?
- hiatus 3y agoYou can connect to mullvad via tor though. If I only ever went to the mullvad site via tor to make an account, paid in monero and only ever accessed the VPN via tor, what is there to hook into?
- densh 3y agoYou can still mount a remote networked file system to a dikless node. Lack of disks does not guarantee inability to persist data.
- Brian_K_White 3y agoIf only the system were open source so you wouldn't have to wonder about that... But we do still have to trust that they are actually running the code they posted. Unless that code somehow contains some way to verify itself? I wonder if there is some way to do that? Have the code include a hash of itself and some way to query the running service that guarantees that the running service must be running the code you are looking at? At first glance it seems any response could always be faked, but maybe there is some cryptography trick where you submit something, like an encrypted copy of the public code maybe, and it crunches and returns something, and that somehow proves that the running code you can't see must be the same as the code you can see. Depending on how the protocol for the challenge works, that could still be faked. The challenge has to somehow not be seperable from ordinary traffic so that you can't have one piece of code handle the challenge and another piece of code handle other traffic.
- c22 3y agoHomomorphic encryption: https://en.wikipedia.org/wiki/Homomorphic_encryption https://en.wikipedia.org/wiki/Homomorphic_encryption
- lanstin 3y agoI think the normal solution to this is all the prove you are the software you say you are calls is proxied to that software and all the normal services calls you want to log and duplicate or otherwise violate the contract are sent to the modified code.
- meithecatte 3y agoThere are two known ways to achieve this: - Multi-party computation. Too much overhead for something like this. - Remote attestation, as seen in e.g. Intel SGX. Usually provided by the CPU vendor. Not a cryptographic guarantee, more of a "it'd be very hard to defeat this if you're not Intel". Probably not that warrant-resistant.
- beckler 3y agohttps://mullvad.net/en/blog/2022/1/12/diskless-infrastructure-beta-system-transparency-stboot/ https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur...