It's worth noting that System Transparency is a multi-year effort to bring transparency to running computer systems. We are aiming for what we call transparent servers. Just like there's open source software and open source hardware we think there should be open source running systems.<p>That's the gist of it.<p>If you think this is interesting I can highly recommend you check out Sigsum - our transparency log design for signed checksums. We've been developing it for a few years and will most likely toggle it version 1 this spring. Here's its threat model:<p>Sigsum is designed to be secure against a powerful attacker that controls:<p>- The signer’s secret key and infrastructure
- The log’s secret key and infrastructure
- A threshold of so-called witnesses that cosign the log<p>Another project that started at Mullvad VPN and is now its own company is Tillitis. Its first product is an open source hardware USB device with unconditional measured boot and key derivation inspired by DICE. Everything from source code to Verilog and KiCad files are on GitHub. Enjoy!<p>Cheers, Fredrik Stromberg<p>(Disclosure: I cofounded Mullvad VPN, invented System Transparency, co-designed Sigsum, co-designed TKey, and cofounded Tillitis)
These are great updates. I couldn't be happier with mullvad. The VPN space is saturated with a lot of VPNs constantly advertising with borderline false claims (a VPN won't stop advertisers from targeting you for example) and adding unrelated features (like an anti-virus). But mullvad is off to the side providing a high quality, truly private, VPN service at a great price.
Wow, I had no idea "diskless infrastructure" was even a thing. Easy to imagine in theory, but this is the first time I'm hearing about it in practice, and it makes total sense in this case.<p>It makes me curious if there are any other real-world use cases for diskless. Are there any customers who would benefit from such a configuration from major cloud providers? E.g. a diskless EC2 instance type that ran off of a RAM disk?
I created a system that booted 12k+ diskless blades via PXE and running Ubuntu (it was built to scale to 30k+, but we never got there).<p>This generally works well, but I'd say there are about 0-20 blades that crash a day due to some sort of memory corruption issues.<p>Due to the fact that I was operating remotely from the hardware, I never really got a chance to resolve it... also... just a simple reboot would fix it (and the blades booted in ~60 seconds, so it wasn't a huge issue).<p>So, on large enough scale... this can be an issue to consider.
No disks doesn't mean you can't retrieve data. (<a href="https://www.youtube.com/watch?v=E6gzVVjW4yY">https://www.youtube.com/watch?v=E6gzVVjW4yY</a>).
> <i>Running the system in RAM does not prevent the possibility of logging. It does however minimise the risk of accidentally storing something that can later be retrieved.</i><p>I don't know what the threat model is, but if it involves nation states confiscating servers, then diskless is of limited help: <a href="https://en.wikipedia.org/wiki/Cold_boot_attack" rel="nofollow">https://en.wikipedia.org/wiki/Cold_boot_attack</a><p>> <i>If the computer is powered off, moved or confiscated, there is no data to retrieve.</i><p>Oh wait...
we at croit.io use PXE boot into RAM for more than 6 years on all our worldwide storage deployments.<p>It provides so many benefits and eases the server management greatly.
130 comments at the time: <a href="https://news.ycombinator.com/item?id=29903695" rel="nofollow">https://news.ycombinator.com/item?id=29903695</a>
Mullvad offers flat rate $5 (no matter 1 month or 12 months or 120 months) and never have any sales so I'm surprised to see these[1] prepaid amazon cards ARE offering discounts: 12mo @ $4.75/mo & 6mo @ $4.83/mo esp. when these are /physical/ code-card purchases<p>[1] <a href="https://www.amazon.com/Mullvad-VPN-Devices-Protect-Security/dp/B092M55HJ2?th=1" rel="nofollow">https://www.amazon.com/Mullvad-VPN-Devices-Protect-Security/...</a>
I wish I could buy shares in this company.<p>However, what makes them great and unique is that they're ideologically motivated, so of course they're not selling shares.