A week or so ago, a blog post was posted in this Community calling out Mullvad for using GMail as their email provider. Wasn’t the greatest blog post in the world and didn’t approach Mullvad for comment or explanation. Anyway, looks like Mullvad heard about it and responded.

  • Snot Flickerman@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    9
    ·
    5 months ago

    Mullvad doesn’t mention a blog post, I think this has been in the works a lot longer than that blog post was.

    These servers run from RAM, with fully encrypted disks mounted to store the backend PostgreSQL database. We cannot fully run our servers from RAM due to requiring a persistent database, but that was a trade-off we had to make.

    These servers run the same OS and kernel configuration as the rest of our infrastructure that runs from RAM, and we have had this service audited pre-production by Assured AB. The issues found by Assured have since been resolved.

    Auditing takes time, as does fixing issues found during audits. This wasn’t in response to a blog post. This was because Mullvad is a company that is trying to do right by their customers (a shocker, I know).