I’m aware of PXE, but in order to do so you need either of:
the boot image supplying server being in the same intranet as the rest of the other servers, or
some sort of method to point the diskless server to the correct external IP address to listen to
Since the first mode is probably too unsafe, that leaves us with the second mode. Either the operator memorizes a specific IP address and types it into the BIOS each time the server is rebooted, or the IP address (and possibly the checksum of the image) are stored in a single-use pendrive that the operator carries. I wonder which of these two methods is used in this case.
PXE is automagic being basically kind of hacky extension to DHCP stuff.
If PXE is enabled the machine will automatically find it via a DHCP relay on the network.
the boot image supplying server being in the same intranet as the rest of the other servers
…
Since the first mode is probably too unsafe, that leaves us with the second mode.
So there is still one single damning piece of information stored in the servers after all - the IP address to fetch the PXE boot image from. But hey, if Mullvad finds a way to strip even that out of the servers, that’d be great
I’m aware of PXE, but in order to do so you need either of:
Since the first mode is probably too unsafe, that leaves us with the second mode. Either the operator memorizes a specific IP address and types it into the BIOS each time the server is rebooted, or the IP address (and possibly the checksum of the image) are stored in a single-use pendrive that the operator carries. I wonder which of these two methods is used in this case.
PXE is automagic being basically kind of hacky extension to DHCP stuff.
If PXE is enabled the machine will automatically find it via a DHCP relay on the network.
Why do you think that’s unsafe?
I’ve never done this, but I believe server network cards can be configured for PXE automatically so
Bios -> network card -> PXE over network
So the storage is in the bios config, and then I guess the network card has its own kind of bios?
So there is still one single damning piece of information stored in the servers after all - the IP address to fetch the PXE boot image from. But hey, if Mullvad finds a way to strip even that out of the servers, that’d be great
Why is it damning?