WireGuard Servers Running from RAM
mullvad.net
mullvad.net
> Running the system in RAM does not prevent the possibility of logging. It does however minimise the risk of accidentally storing something that can later be retrieved.
This doesn’t mean you can’t be logged. Running in RAM just means that any system level logging is transient and largely accidental. But if there were a need to specific logging, data could always be sent to a different node with disks. From Mullvad’s point of view, there is a reliability benefit to having diskless nodes. But from a privacy point of view, your access could still be logged, if required. But it would probably require more “active” monitoring than “passive”/accidental logging.
https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur...
Things like AMD SEV/SEV-ES are designed to mitigate that aspect, the implementation of which can be proven to end-users of the VM by remote attestation.
There is just no saying that they don’t swap gear out for the auditors or for the disk less servers or whatever it is.
I like that they say the right things. But I think the current models of Facebook and Google show just how much money there is in data, so it’s just faith that the VPN provider won’t fall to temptation.
But.
Mullvad is more trustworthy that most, and possibly more trustworthy than all other public VPN providers. They have a good history, and are regularly audited: https://mullvad.net/en/blog/tag/audits/
Don't get me wrong, you still have to believe them. But they're easier to believe than others.
In short: auditors audit providers against their own privacy policies. If there is a loophole, the result, with some auditors, might still be a legitimate "pass" - e.g. because exfiltration is not logging, and the privacy policy says only "we don't log".
P.S. Mullvad's privacy policy falls into the same bucket: "we never store any activity logs of any kind". Sending data to a third party who stores it would be 100% compliant. Mullvad, please fix the wording.
> In regards to information leakage and logging of customer data the configuration is sound
I cannot imagine this could ever mean that Mullvad sends data to third parties.
Ontop of that many of us here in Sweden know people at Mullvad and can attest to them being conscious of privacy issues.
Me for example, I can vouch for them if that matters to anyone, but it's the same problem isn't it, if people can't trust Mullvad on their word, why should they trust two random HN users they've never met or conversed with before?
Trust in IT systems is super complicated.
You are mostly connecting to the VPN with a same or similar IP. So right there; you are back to having to trust they aren’t logging or leaking.
If they are, it doesn’t matter Mull is missing your name, you are already correlated from ISP to endpoint in this case.
Likewise, if they aren’t logging, what does it matter if they have your name and account info?
As many VPNs are sketchy (and even the best one might get bought out or otherwise get compromised) relying on one might seriously reduce your privacy. Especially considering that in many jurisdictions your ISP has much higher legal requirements on integrity and privacy.
But if the VPN don't know who you are the absolute worst case is that you fall back to your ISP. Whether that is good enough for you is something you have to check against your threat model. But in a world where adding a VPN in many cases threatens to reduce your privacy it is massive win.
Most VPNs are run by small and relatively non-transparent private companies. It would be trivial and in fact the obvious thing to do for law enforcement and similar agencies to setup VPN companies and advertise them to their targets.
ISPs are actually more transparent and their business model does not fundamentally relies on exploiting customer data.
And yet they do, largely because many people _can't_ vote with their dollars. I can move which VPN provider I use. Also, VPN's are a big benefit on filtered wifi if that's something you have to deal with.
To be fair this applies to VPNs too. Their customers give them money, and that should make their business sustainable without needing to spy on people.
To be honest I trust Mullvad way more than I trust my ISP not to sell my DNS queries.
On one hand, they won’t be able intercept encrypted VPN traffic, but on the other, they are definitely collecting IP addresses, timestamps and traffic heuristics. With enough resources to pick out patterns and bulk collection on both sides, encryption and logging might not even matter.
This was before they were bought by some shady company though, so I wouldn't rely on this policy being unchanged anymore.
They did not log, but maybe they are now. I don’t say that ovpn logs, but the 3 letter agencies can infiltrate a company.
The point of the RAM-only server is not that it ensures that everything is operating from RAM. Everything is operating from RAM already even on servers that have attached disks. The point is that RAM-only means there is no intentional or even unintentional logging to non-volatile memory or storage. Think of it as a physics enforced capability system (no disk is physically connected).
I guess there's a larger question - is it possible to construct a completely transparent architecture for customers who are trustless in you as a service provider?
The CPU essentially signs running code and API responses using a key that only the CPU manufacturer knows. That way, you can verify that your cloud services are running the binaries you told them to run.
Note the long list of vulnerabilities on that page and the removal of this feature from desktop CPUs. (Let’s be real, its only use case on desktop is DRM)
I mean, you need some kind of trust, somewhere. Maybe you don't have to trust the service provider, if it provides some type of TPM attestation traced to the key of someone you do trust.
On the other hand, they have physical access. Even with efforts at remote attestation, etc, the game is lost.
Let’s say worst case, there is an unintentional leak to a another machine, pretty likely that machine has a disk. These are very obviously highly connected machines. Sorry, but it can never be anything but faith - which is fine if you have or, or chose to.
I think that low latency can act as a proof of being close and fast, but once the apparent network latency goes up how do you know that server times are low if the server can claim the time was spent on the network?
Disclaimer: I work on this.
Do you have a better plan...?
The configuration would have to be run at the hypervisor level, so that logging couldn't simply occur by nesting the server in a VM then logging that.
Then I got it. Raid. Not RAID. Made so much more sense.
For example, all Ceph storage nodes bootet with croit.io run in RAM and have no OS installed. But you still have all logs and everything available right out of the box.
It's absolutely not foolproof but reduces the odds of them ending up on a SAN somewhere where they might be found by someone scanning free space or gaining direct access to an iSCSI bus or similar.
A better solution would be something like Apple’s private relay.
Also, either you trust the provider or you don’t.
I wouldn’t bet on it being super secure in case law enforcement comes after you, for example.
They do two hops, first to an Apple-controlled server, then to the “second relay” which is operated by Cloudflare in a lot of cases. Encryption is terminated at the second relay.
So Cloudflare sees the content (or whatever is visible in a TLS stream), and Apple sees your real IP, but neither can know both without collaboration.
It’s mostly an anti-tracking feature. But also now government needs cooperation from two companies.
On another note, WARP is a VPN. But Mullvad is preferred to WARP, because Cloudflare most likely logs connections for some time.
> A better solution would be something like Apple’s private relay.
then
> On another note, WARP is a VPN. But Mullvad is preferred to WARP
But keep in mind that private relay applies only to Safari traffic. For applications, use Mulvad.