Why Proton VPN doesn't use RAM-only VPN servers
protonvpn.com
protonvpn.com
If the machine has no persistent storage and boots from a medium that is provably read-only (i.e. a DVD or a netboot image), it's always going back to a known state every time it comes back up.
Also "we don't log" is quite far from "it doesn't matter even if we accidentally logged, because the ram has gone poof".
The ProtonVPN setup is probably quite good and more than good enough, but it is disingenuous to claim that it is actually equivalent.
Encryption and policy are not the same or just as good as does-not-exist.
What could possibly be true, and so what they could possibly say honestly is that it's close, and the operational gain is worth the security loss.
I know how my mom can fail to see the absolutly binary 180 degree night and day difference between something that is difficult and something that is impossible, and see them both as being close to each other way to one side of a slider, but I don't know how anyone who programs or administers a computer fails to see those as actually being at opposite ends of a slider with only 2 settings, possible and not-possible.
The obvious benefit of having a ram only vpn is eventually it will be shutdown or rebooted. An encrypted hard drive will have its data stored for practically the rest of time.
Nothing in this article tells me why Proton VPN is better than a Ram vpn.
https://en.wikipedia.org/wiki/Crypto_AG
And Proton does not inspire confidence.
https://expatcircle.com/cms/the-not-so-private-privacy-email...
In the case you shared, the name/address of the terrorism suspect was actually given to police by Apple, not Proton. The terror suspect added their real-life Apple email as an optional recovery address in Proton Mail. Proton can't decrypt data, but in terror cases Swiss courts can obtain recovery email. Moreover, the case concerns Proton Mail not Proton VPN, and Proton VPN's no-logs policy has been proven in both independent audits (https://protonvpn.com/blog/no-logs-audit) and in court (https://protonvpn.com/blog/transparency-report).
Only once you get to a later claim that the logs they store on local disk "contain no personal information" (they claim; even in event of error?) is the earlier claim arguable for a relevant threat model.
This does not inspire confidence, and only displays their mediocrity and technical incompetence.
Are they unaware that you can update the OS running on ramdisk just like you can with regular disk?
Ok. But that doesn't protect you from cases where it is off. Like if the hard drive is confiscated or stolen.
> Full-disk encryption achieves the same end
Not entirely. The decryption key could be compromised. Or someone might figure out may have some way to crack the decryption (unlikely, but not impossible).
> A good VPN service has no logs worth seizing anyway
That is half of a good argument. The other half would be "and we disable swap so that parts of memory don't accidentally end up on disk". But they don't mention swap.
> Location, location, location
That might help against government seizure, but what if the disk is stolen?
Autocorrect?
This is just false. If your servers are seized I guarantee they also want your disk encryption password. How to prevent it? No disk, and no way into the OS without booting it with some special arguments.
Remember, the courts consider decryption keys just like house keys, they can be demanded by the police and are not protected by the fifth amendment
*Within the USA.
Proton VPN is based in Switzerland where the fifth amendment doesn’t apply anyway as a US-specific constitutional concept. They might have stronger or weaker protections in this area, I don’t know, but not the fifth amendment.
They are based in a country with more than five amendments to its current federal constitution, but since they are unlikely to want to construct a minaret, the prohibition on doing so in the current Swiss federal constitution’s fifth amendment doesn’t affect them in any meaningful way.
Do we really assume not being in the US directly fixes everything?
When...
- Most social media used is US-based
- Phone markets like Android and iOS are US-based
- Browser stores like Chrome are US-based
- They have US-based servers
- They have US-based customers
- They have customers specifically wanting to access US-based content
The list goes on...
And they even have a .com domain, which is US-based.
Nobody said anything about fixing everything. When the US fifth amendment doesn’t apply, people have fewer protections from the US government, not more.
Also, I should correct myself slightly on when the US fifth amendment applies: in the rare case where US officials do conduct a custodial interrogation abroad, US courts will recognize the US fifth amendment protection against self-incrimination for statements made to those US officials in that context, even for statements made by foreign nationals. But US courts will not recognize those rights for statements made to foreign officials, outside of two rarely applicable exceptions. Also, of course, dealings within the US with US government officials are constitutionally protected for all nationalities.
I’ve edited my comment upthread accordingly.
With respect to Proton’s home government of Switzerland, they might have more protections or fewer protections than the US fifth amendment offers versus the US government when it does apply - I have no idea and avoided making any assertion either way about that.
Anyway, even in the US, providing a decryption key would only be protection by the fifth amendment if testimony by a human is involved - not simply, for example, turning over a USB key or even a piece of paper on which the key is printed So this question is mostly moot for the scenario we are discussing, except if information in a human mind is needed to access the key.
…there are some technical tricks to retrieve RAM values after power loss
Do these tricks still work? Did they ever work or is it more internet rumor? Modern RAM refreshes itself really quickly and I suspect signal degradation happens more quickly than historical modules.If you are worried about the gestapo seizing your servers and freezing the RAM, is there any mitigation in place?
SGX encrypted memory would work as a solution for this, probably.
I have so little trust in computer security I assume the powers that be have a USB stick with 0 days that can compromise any modern OS by just plugging into an active machine.
As far as I know they were not able to access any of the mail in his account.
But they have extradition treaties with other countries.
Unless we believe a human being is manually entering these in their hundreds of us vpn servers every time they restart?
The data is still there, so I don't consider this "no less secure".