I also wouldn’t be surprised if it’s a performance benefit, since RAM is far faster than any permanent storage.
The cons are probably just that this is a pretty unusual architecture that they probably had to put some work into setting up and making it reliable.
I think they just mean ephemeral.
But, obviously, that's pretty insane. Agree with everything that this is a big leap in the step of better protection for users.
Even cellphones...you want them running decrypted, but inside a Faraday cage of some kind to block remote wipes.
But to run dd wouldn’t you need root access? And couldn’t you use that to dump the FDE keys from memory?
Once DIMMs are seated, secure the ends with superglue, then brush conformal coating over the bus traces.
The second step is likely not even necessary if the motherboard is a 4 layer pcb with traces in the middle.
But we do still have to trust that they are actually running the code they posted.
Unless that code somehow contains some way to verify itself?
I wonder if there is some way to do that? Have the code include a hash of itself and some way to query the running service that guarantees that the running service must be running the code you are looking at?
At first glance it seems any response could always be faked, but maybe there is some cryptography trick where you submit something, like an encrypted copy of the public code maybe, and it crunches and returns something, and that somehow proves that the running code you can't see must be the same as the code you can see.
Depending on how the protocol for the challenge works, that could still be faked. The challenge has to somehow not be seperable from ordinary traffic so that you can't have one piece of code handle the challenge and another piece of code handle other traffic.
- Multi-party computation. Too much overhead for something like this.
- Remote attestation, as seen in e.g. Intel SGX. Usually provided by the CPU vendor. Not a cryptographic guarantee, more of a "it'd be very hard to defeat this if you're not Intel". Probably not that warrant-resistant.
Hypothetically, you can rewrite the firmware for the IPMI with a backdoor and extract data.
Hypothetically, you could kidnap the family of a developer and force them to add a surreptitious side channel for exfiltrating data.
Hypothetically, you could run the universe in a simulator and use the simulator's controls to read data from RAM in the simulated Mullvad servers on the simulated Earth.