Today we announce that we have completely removed all traces of disks being used by our VPN infrastructure!

top 50 comments

sorted by: hot top controversial new old
[–] 156 points 3 years ago

Full article:

We have successfully completed our migration to RAM-only VPN infrastructure

20 September 2023 NEWS SYSTEM TRANSPARENCY

Today we announce that we have completely removed all traces of disks being used by our VPN infrastructure!

In early 2022 we announced the beginning of our migration to using diskless infrastructure with our bootloader known as “stboot”. Completing the transition to diskless infrastructure

Our VPN infrastructure has since been audited with this configuration twice (2023, 2022), and all future audits of our VPN servers will focus solely on RAM-only deployments.

All of our VPN servers continue to use our custom and extensively slimmed down Linux kernel, where we follow the mainline branch of kernel development. This has allowed us to pull in the latest version so that we can stay up to date with new features and performance improvements, as well as tune and completely remove unnecessary bloat in the kernel.

The result is that the operating system that we boot, prior to being deployed weighs in at just over 200MB. When servers are rebooted or provisioned for the first time, we can be safe in the knowledge that we get a freshly built kernel, no traces of any log files, and a fully patched OS.

  • source
  • [–] 127 points 3 years ago (15 children)

    It's a good day to be a Mullvad user. Switched over from Surfshark a while ago, and I love it.

  • source
  • hideshow 15 child comments
  • load more comments (15 replies)
    [–] 91 points 3 years ago (3 children)

    Why is their logo a Mole when Mullvad is The Goat

  • source
  • hideshow 5 child comments
  • load more comments (1 reply)
    [–] 85 points 3 years ago (2 children)

    Wow, that is very impressive. I've been a subscriber for a few years and I couldn't be happier with their service.

  • source
  • hideshow 3 child comments
  • [–] 58 points 3 years ago (6 children)

    Except with the removal of port forwarding

  • source
  • parent
  • hideshow 7 child comments
  • load more comments (5 replies)
  • load more comments (1 reply)
    [–] 63 points 3 years ago

    Mullvad is good, definitely my go-to VPN these days.

  • source
  • [–] 48 points 3 years ago (7 children)

    I find the "Mullvad VPN scratch cards" interesting. If a store near you has them you could buy one and be totally anonymous. What I find a bit odd is that you can buy them on amazon as well but sold directly by mullvad. Doesn't that defeat the purpose? The idea of the card is a decoupling of your real identity from the vpn user but when you buy the card in their store doesn't it negate that?

    I am probably just missing something here. Does anyone have more insight?

  • source
  • hideshow 11 child comments
  • [–] 13 points 3 years ago

    Probably not because they still dont know who bought that card since the scratch card is linked to the money but that card could be used by anyone. Nothing stop you from buying them and giving them to a friend

  • source
  • parent
  • load more comments (3 replies)
    [–] 46 points 3 years ago (10 children)

    Interesting what’s going happening with mullvad. For the best part of 10’years, you hear nothing.

    Does anyone know why they are recently noisy?

  • source
  • hideshow 14 child comments
  • load more comments (6 replies)
    [–] 46 points 3 years ago

    Mullvad is such a good company. I just bought another month yesterday, but guess I'll go and add another year to that!

  • source
  • [–] 32 points 3 years ago (17 children)

    They're amazing. I don't torrent anymore so I'll definitely be renewing.

  • source
  • hideshow 17 child comments
  • load more comments (17 replies)
    [–] 28 points 3 years ago (4 children)

    Of only they'd kept port forwarding.

  • source
  • hideshow 6 child comments
  • [–] [S] 84 points 3 years ago (3 children)

    Didn't really have a choice:

    ...Regrettably individuals have frequently used this feature to host undesirable content and malicious services from ports that are forwarded from our VPN servers. This has led to law enforcement contacting us, our IPs getting blacklisted, and hosting providers cancelling us.

    Blog post

    Big issue there is hosting providers cancelling them. Can't operate a business without that.

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (3 replies)
  • [–] 17 points 3 years ago

    Agreed. Seems like they were in a super tough spot with that and kind of had to drop it. All the sudden they seem to be doing some new cool stuff to try to keep their edge which I really appreciate / respect. That being said, I've dumped them and switched to a service that still port forwards as it gives me better torrenting throughput. Sorry Mullvad.

  • source
  • parent
  • load more comments (2 replies)
    [–] 25 points 3 years ago (7 children)

    From what I read in the article, there is still one part of the boot sequence that does require some sort of storage: the part where the bootloader fetches the network boot image and verifies it against the checksum signature. But I think that can be performed by booting from a pendrive and then removing it. The problem will come if law enforcement gets a hold of said pendrive...

  • source
  • hideshow 10 child comments
  • [–] 75 points 3 years ago

    Why would that be a problem? A boot image should only contain the commands to get the main system started after POST. It shouldn't contain any kind of logs, traffic data, or user data. In fact it should be read-only.

  • source
  • parent
  • load more comments (4 replies)
    load more comments
    view more: next ›