summaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
authorEmīls Piņķis <emils@mullvad.net>2022-09-26 16:19:25 +0200
committerEmīls Piņķis <emils@mullvad.net>2022-09-27 15:27:40 +0200
commitb6e6939cd5c8c4ba47a724e31f62b1c5078ac8d5 (patch)
tree993ee34471eb9f08b071445c6a71f9f67c14bfde
parent59bfcc9717cb9b9b3743c8e77b1242c296f94653 (diff)
downloadmullvadvpn-b6e6939cd5c8c4ba47a724e31f62b1c5078ac8d5.tar.xz
mullvadvpn-b6e6939cd5c8c4ba47a724e31f62b1c5078ac8d5.zip
Update security docs
Due to recent changes to the daemon to prevent early and late boot leaks, the security docs need to be updated to reflect the new behavior.
-rw-r--r--docs/security.md25
1 files changed, 20 insertions, 5 deletions
diff --git a/docs/security.md b/docs/security.md
index f8e1c511cc..95185c4b72 100644
--- a/docs/security.md
+++ b/docs/security.md
@@ -270,11 +270,19 @@ via unix domain sockets (UDS) on Linux and macOS and via named pipes on Windows.
This management interface can be reached by any process running on the device.
Locally running malicious programs are outside of the app's threat model.
-The service transitions to the [disconnected] state before exiting (i.e., normally when the OS is
-being shut down). In general, the last firewall policy is maintained when the service exits, and
-lost upon a reboot (except on Windows, see below). In other words, if the "Always require VPN"
-option is enabled, the blocking policy will be left intact when the daemon service stops.
-Otherwise, the system firewall will be reset to its original state.
+The `mullvad-daemon` transition to the [disconnected] state before exiting. To
+limit leaks during computer shutdown, it will maintain the blocking firewall
+rules upon exit in the following scenarios:
+- _Always require VPN_ is enabled
+- A user didn't explicitly request for the `mullvad-daemon` to be shut down and
+ either or both of the following are true
+ - The daemon is currently in one of the blocking states ([connected],
+ [connecting], or [error])
+ - _auto-connect_ is enabled
+
+In other cases, when the daemon process stops normally, firewall rules will be
+removed.
+
### Windows
@@ -285,6 +293,13 @@ the service has started back up again during boot, including before the BFE serv
As with "Always require VPN", enabling "Auto-connect" in the service will cause it to
enforce the blocking policy before being stopped.
+### Linux
+
+Due to the dependence on various other services, the `mullvad-daemon` is not
+started early enough to prevent leaks. To prevent this, another system unit is
+started during early boot that applies a blocking policy that persists until the
+`mullvad-daemon` is started.
+
## Desktop Electron GUI
The graphical frontend for the app on desktop is an Electron app. This app only ever loads