TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Diskless infrastructure in beta (System Transparency: stboot) (2022)

129 pointsby lysergiaover 2 years ago

13 comments

kfredsover 2 years ago
It&#x27;s worth noting that System Transparency is a multi-year effort to bring transparency to running computer systems. We are aiming for what we call transparent servers. Just like there&#x27;s open source software and open source hardware we think there should be open source running systems.<p>That&#x27;s the gist of it.<p>If you think this is interesting I can highly recommend you check out Sigsum - our transparency log design for signed checksums. We&#x27;ve been developing it for a few years and will most likely toggle it version 1 this spring. Here&#x27;s its threat model:<p>Sigsum is designed to be secure against a powerful attacker that controls:<p>- The signer’s secret key and infrastructure - The log’s secret key and infrastructure - A threshold of so-called witnesses that cosign the log<p>Another project that started at Mullvad VPN and is now its own company is Tillitis. Its first product is an open source hardware USB device with unconditional measured boot and key derivation inspired by DICE. Everything from source code to Verilog and KiCad files are on GitHub. Enjoy!<p>Cheers, Fredrik Stromberg<p>(Disclosure: I cofounded Mullvad VPN, invented System Transparency, co-designed Sigsum, co-designed TKey, and cofounded Tillitis)
评论 #34418468 未加载
morsecodistover 2 years ago
These are great updates. I couldn&#x27;t be happier with mullvad. The VPN space is saturated with a lot of VPNs constantly advertising with borderline false claims (a VPN won&#x27;t stop advertisers from targeting you for example) and adding unrelated features (like an anti-virus). But mullvad is off to the side providing a high quality, truly private, VPN service at a great price.
评论 #34418387 未加载
评论 #34417594 未加载
crazygringoover 2 years ago
Wow, I had no idea &quot;diskless infrastructure&quot; was even a thing. Easy to imagine in theory, but this is the first time I&#x27;m hearing about it in practice, and it makes total sense in this case.<p>It makes me curious if there are any other real-world use cases for diskless. Are there any customers who would benefit from such a configuration from major cloud providers? E.g. a diskless EC2 instance type that ran off of a RAM disk?
评论 #34416779 未加载
评论 #34416738 未加载
评论 #34416635 未加载
评论 #34419572 未加载
评论 #34416642 未加载
评论 #34417549 未加载
评论 #34416718 未加载
评论 #34418962 未加载
评论 #34416000 未加载
latchkeyover 2 years ago
I created a system that booted 12k+ diskless blades via PXE and running Ubuntu (it was built to scale to 30k+, but we never got there).<p>This generally works well, but I&#x27;d say there are about 0-20 blades that crash a day due to some sort of memory corruption issues.<p>Due to the fact that I was operating remotely from the hardware, I never really got a chance to resolve it... also... just a simple reboot would fix it (and the blades booted in ~60 seconds, so it wasn&#x27;t a huge issue).<p>So, on large enough scale... this can be an issue to consider.
评论 #34419304 未加载
siliconc0wover 2 years ago
No disks doesn&#x27;t mean you can&#x27;t retrieve data. (<a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=E6gzVVjW4yY">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=E6gzVVjW4yY</a>).
ignoramousover 2 years ago
&gt; <i>Running the system in RAM does not prevent the possibility of logging. It does however minimise the risk of accidentally storing something that can later be retrieved.</i><p>I don&#x27;t know what the threat model is, but if it involves nation states confiscating servers, then diskless is of limited help: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Cold_boot_attack" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Cold_boot_attack</a><p>&gt; <i>If the computer is powered off, moved or confiscated, there is no data to retrieve.</i><p>Oh wait...
Mave83over 2 years ago
we at croit.io use PXE boot into RAM for more than 6 years on all our worldwide storage deployments.<p>It provides so many benefits and eases the server management greatly.
评论 #34419529 未加载
zpplnover 2 years ago
I could see some defence companies being paranoid enough for this (although they&#x27;d be more skeptical about the cloud provider part).
Semaphorover 2 years ago
130 comments at the time: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29903695" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29903695</a>
l2silverover 2 years ago
Anyone else read &quot;dickless&quot; first?
patrakovover 2 years ago
(2022), approximately a year ago.
评论 #34416634 未加载
RVRXover 2 years ago
Mullvad offers flat rate $5 (no matter 1 month or 12 months or 120 months) and never have any sales so I&#x27;m surprised to see these[1] prepaid amazon cards ARE offering discounts: 12mo @ $4.75&#x2F;mo &amp; 6mo @ $4.83&#x2F;mo esp. when these are &#x2F;physical&#x2F; code-card purchases<p>[1] <a href="https:&#x2F;&#x2F;www.amazon.com&#x2F;Mullvad-VPN-Devices-Protect-Security&#x2F;dp&#x2F;B092M55HJ2?th=1" rel="nofollow">https:&#x2F;&#x2F;www.amazon.com&#x2F;Mullvad-VPN-Devices-Protect-Security&#x2F;...</a>
评论 #34415997 未加载
评论 #34416105 未加载
评论 #34415899 未加载
warinukraineover 2 years ago
I wish I could buy shares in this company.<p>However, what makes them great and unique is that they&#x27;re ideologically motivated, so of course they&#x27;re not selling shares.