TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Diskless infrastructure in beta (System Transparency: stboot) (2022)

129 点作者 lysergia超过 2 年前

13 条评论

kfreds超过 2 年前
It&#x27;s worth noting that System Transparency is a multi-year effort to bring transparency to running computer systems. We are aiming for what we call transparent servers. Just like there&#x27;s open source software and open source hardware we think there should be open source running systems.<p>That&#x27;s the gist of it.<p>If you think this is interesting I can highly recommend you check out Sigsum - our transparency log design for signed checksums. We&#x27;ve been developing it for a few years and will most likely toggle it version 1 this spring. Here&#x27;s its threat model:<p>Sigsum is designed to be secure against a powerful attacker that controls:<p>- The signer’s secret key and infrastructure - The log’s secret key and infrastructure - A threshold of so-called witnesses that cosign the log<p>Another project that started at Mullvad VPN and is now its own company is Tillitis. Its first product is an open source hardware USB device with unconditional measured boot and key derivation inspired by DICE. Everything from source code to Verilog and KiCad files are on GitHub. Enjoy!<p>Cheers, Fredrik Stromberg<p>(Disclosure: I cofounded Mullvad VPN, invented System Transparency, co-designed Sigsum, co-designed TKey, and cofounded Tillitis)
评论 #34418468 未加载
morsecodist超过 2 年前
These are great updates. I couldn&#x27;t be happier with mullvad. The VPN space is saturated with a lot of VPNs constantly advertising with borderline false claims (a VPN won&#x27;t stop advertisers from targeting you for example) and adding unrelated features (like an anti-virus). But mullvad is off to the side providing a high quality, truly private, VPN service at a great price.
评论 #34418387 未加载
评论 #34417594 未加载
crazygringo超过 2 年前
Wow, I had no idea &quot;diskless infrastructure&quot; was even a thing. Easy to imagine in theory, but this is the first time I&#x27;m hearing about it in practice, and it makes total sense in this case.<p>It makes me curious if there are any other real-world use cases for diskless. Are there any customers who would benefit from such a configuration from major cloud providers? E.g. a diskless EC2 instance type that ran off of a RAM disk?
评论 #34416779 未加载
评论 #34416738 未加载
评论 #34416635 未加载
评论 #34419572 未加载
评论 #34416642 未加载
评论 #34417549 未加载
评论 #34416718 未加载
评论 #34418962 未加载
评论 #34416000 未加载
latchkey超过 2 年前
I created a system that booted 12k+ diskless blades via PXE and running Ubuntu (it was built to scale to 30k+, but we never got there).<p>This generally works well, but I&#x27;d say there are about 0-20 blades that crash a day due to some sort of memory corruption issues.<p>Due to the fact that I was operating remotely from the hardware, I never really got a chance to resolve it... also... just a simple reboot would fix it (and the blades booted in ~60 seconds, so it wasn&#x27;t a huge issue).<p>So, on large enough scale... this can be an issue to consider.
评论 #34419304 未加载
siliconc0w超过 2 年前
No disks doesn&#x27;t mean you can&#x27;t retrieve data. (<a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=E6gzVVjW4yY">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=E6gzVVjW4yY</a>).
ignoramous超过 2 年前
&gt; <i>Running the system in RAM does not prevent the possibility of logging. It does however minimise the risk of accidentally storing something that can later be retrieved.</i><p>I don&#x27;t know what the threat model is, but if it involves nation states confiscating servers, then diskless is of limited help: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Cold_boot_attack" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Cold_boot_attack</a><p>&gt; <i>If the computer is powered off, moved or confiscated, there is no data to retrieve.</i><p>Oh wait...
Mave83超过 2 年前
we at croit.io use PXE boot into RAM for more than 6 years on all our worldwide storage deployments.<p>It provides so many benefits and eases the server management greatly.
评论 #34419529 未加载
zppln超过 2 年前
I could see some defence companies being paranoid enough for this (although they&#x27;d be more skeptical about the cloud provider part).
Semaphor超过 2 年前
130 comments at the time: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29903695" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29903695</a>
l2silver超过 2 年前
Anyone else read &quot;dickless&quot; first?
patrakov超过 2 年前
(2022), approximately a year ago.
评论 #34416634 未加载
RVRX超过 2 年前
Mullvad offers flat rate $5 (no matter 1 month or 12 months or 120 months) and never have any sales so I&#x27;m surprised to see these[1] prepaid amazon cards ARE offering discounts: 12mo @ $4.75&#x2F;mo &amp; 6mo @ $4.83&#x2F;mo esp. when these are &#x2F;physical&#x2F; code-card purchases<p>[1] <a href="https:&#x2F;&#x2F;www.amazon.com&#x2F;Mullvad-VPN-Devices-Protect-Security&#x2F;dp&#x2F;B092M55HJ2?th=1" rel="nofollow">https:&#x2F;&#x2F;www.amazon.com&#x2F;Mullvad-VPN-Devices-Protect-Security&#x2F;...</a>
评论 #34415997 未加载
评论 #34416105 未加载
评论 #34415899 未加载
warinukraine超过 2 年前
I wish I could buy shares in this company.<p>However, what makes them great and unique is that they&#x27;re ideologically motivated, so of course they&#x27;re not selling shares.