Rendered at 17:26:12 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
barathr 21 hours ago [-]
As others have pointed out, this is like Apple iCloud Private Relay, and other multi-hop privacy systems that have been built on and off over the last several decades (Tor included).
Perhaps we should arrange a new thread about this?
barathr 1 hours ago [-]
Happy to discuss further if it's of interest.
dang 23 minutes ago [-]
Sure! We should just wait long enough (perhaps a couple of months) so the effects of the current thread wear off and it won't feel like a follow-up anymore. If you want to, you'd be welcome to email us then and we could arrange a new thread - similar to what I said at https://news.ycombinator.com/item?id=49807631 (on a completely different topic of course!)
dongcarl 21 hours ago [-]
Good to see you here Barath :-)
I didn't realize Chris Wood was also an author!
maxloh 21 hours ago [-]
I don't understand the point of this.
Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.
Why should I choose this over Mullvad?
maxloh 21 hours ago [-]
Mullvad is a Swedish company, which has stricter privacy protection laws in place.
According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.
The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?
[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/
dongcarl 20 hours ago [-]
(Carl from Obscura here)
I love folks who are also reasoning through security models! A few things to note here:
- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).
- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.
maxloh 19 hours ago [-]
The "Obscura and Mullvad" argument actually makes sense. Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.
Another question: How does the Obscura client get the Mullvad exit server’s public key? Are they hardcoded at compile time, fetched from Mullvad's server, or fetched from Obscura's server?
The latter seems to be dangerous if there isn't some kind of signature verification done on the client side before using the key.
traceroute66 10 hours ago [-]
> Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.
Its just very, very, very unfortunate that they chose the US for Obscura.
Of all the jurisdictions in the world you chose the one that has become exponentially untrustworthy in the eyes of non-US users ....
voakbasda 9 hours ago [-]
… as well as in the eyes of many of its own citizens.
dongcarl 17 hours ago [-]
Good question! It's the latter right now (which is not ideal), but I think Mullvad is going to sign their server pubkeys pretty soon and we'll switch to that.
We do currently show it in the app and there's an easily clickable link so you can verify against Mullvad's website for the pubkey
miohtama 21 hours ago [-]
The EU is working to make what Mullvad is doing illegal.
> The EU is working to make what Mullvad is doing illegal.
In other news, it has been demonstrated in a court of law that Mullvad "no logs" means no logs.
TL;DR: Six police officers turned up at Mullvad offices with a search warrant for logs and data. Mullvad said "take a look for yourself". They went home with nothing.
Lots of people on HN and elsewhere are spreading a lot of FUD about the EU and what the EU MIGHT do – remember MIGHT .... politicians discuss a lot of stuff, and a lot of it never gets implemented.
It is the job of politicians to discuss issues of the day and potential ways to deal with them.
One thing that is clear. The EU is not a dicatorship. They have a long history of listening and acting on what industry experts tell them. Even if it means "watering down" ideas being discussed by the politicians.
I have a lot of faith that Mullvad (and, frankly, all the other VPN providers) would make a lot of noise if any of this EU FUD people are spreading actually ever became reality.
Until then, I suggest people put the EU FUD tin-foil hat to one side.
World used to believe companies used to care for them, before snowden showed up. Even now people are still surprised, when companies like LG get caught doing illegal stuff. How long before there is a scandal in EU? Fool me once...
As much as i like to believe EU "cares" about the consumer, its really stupid for someone to blindly put their faith in Mullvad. Zero trust. When you are online, you are on your own.
autoexec 20 hours ago [-]
Yeah, it's basically not possible to offer an actually secure and private service in the US. If men with guns and gag orders haven't shown up at their new york office yet, they will as soon as this VPN gets popular enough to show up on their radar. At that point if they have any integrity they'll shut their service down like Lababit did rather than allow it to be compromised by the state.
NordStreamYacht 15 hours ago [-]
Sweden was compromised years ago, Assange's case is proof.
- We allow you to choose an exit location (I believe iCloud Private Relay restricts you to the same location)
- Our exit hop is Mullvad instead of Cloudflare+Fastly+Akamai
- We use QUIC for transport instead of HTTP/3 (which is built on QUIC and has a bit more overhead)
Barbing 20 hours ago [-]
Same country at least - the iCloud Private Relay options, iOS:
“1: Maintain general location
2: Use country and time zone
Maintain your general location to receive localized content, or enhance your privacy by using a broader IP address based on your country and time zone.
Safari Private Browsing always uses an IP location from your country and time zone.”
bossyTeacher 21 hours ago [-]
Because its CEO is known as the sponsor of the Orebro party?
I still don't see the relevance. Modern purity politics is silly. Is there a conflict of interest for Mullvad? If not, I don't see the issue.
bossyTeacher 3 hours ago [-]
Many people also don't see the relevance of reducing reliance in services from Russian companies or using Chinese software for critical matters either. Newsflash, not everyone has the same opinion.
KoolKat23 1 hours ago [-]
That's a slightly different thing. Individuals versus country. This is a company not an individual.
omnimus 19 hours ago [-]
That indeed can be a problem for many.
fwn 9 hours ago [-]
Calls for ethical purity are usually very selective, serving to protect incumbents.
For example, every big tech company supports the current US administration in some capacity, either with funds, their surveillance stack or both.
Almost noone has stopped using big tech products and services because of that. (Unfortunately!)
But beware! There is someone in one tiny, privacy-preserving company who is doing something that not everyone agrees with!
That is a big problem, right? I think this is a big problem, everyone!
You see those comments in every Mullvad thread, but not necessarily in every thread about big tech products or services.
omnimus 6 hours ago [-]
Let's not have perfect to be enemy of good (or ok, or better than nothing).
In case of Mullvad it's a niche product with many alternatives. Using something else is viable and it is interesting to many in the niche because their ties to far right was secret up until recently.
It might be harder with something like Basecamp or Figma if your job requires it.
It is almost impossible with things like Google.
Yes we should have these comments in every thread about big tech. It doesn't mean we shouldn't do something about Mullvad.
shafyy 9 hours ago [-]
I think many people have absolutely stopped giving money to US corporations that are run by fascists like Musk or DHH. Of course, this is and will never be the majority (many people don't care or don't know), but I am certain it's a non-trivial number of people.
fwn 9 hours ago [-]
I am sure there are quite a few people out there who have avoided getting a mainstream smartphone setup or other big tech services.
As you wrote yourself, this is not the majority. Quite the understatement.
However, this is only a tangential notion in my comment. What do you think of my (probably not unique or novel) observation that calls for ethical purity seem to be very selective in a way that (in effect!) benefits big tech?
For example: The other person in this very thread who pointed out that Mullvad is not perfectly pure recommended iCloud in their previous HN comment three days ago. Did their attitude change in this three days? Unlikely.
iCloud is a service from a company that deplatforms ICE transparency apps, among many other things. Its then CEO, Tim Cook, personally gifted one million USD to Donald Trump for his inauguration. (The very thing they criticized: "... their CEO is directly funding a far-right ...")
Humans are rarely pure or heavenly. Double standards help incumbents.
Plont 7 hours ago [-]
I'm not interested in generalising "calls for moral purity" as if all ethical concerns are equivalent.
There is a difference, also, between saying, "I am not morally okay with this, so I am going to do X", vs. "If you don't also do X, you are a Bad Person."
To me, after reading up on the platform of the right-wing party in question and Mullvad's CEO's level of involvement with it, the situation with Mullvad is worse. And because it is a much smaller company, a much greater percentage of my money would go to that CEO in particular. And my choice to pay or not has much more influence on Mullvad than it ever could have on Apple.
Others are free to feel otherwise, and to use their money as they please.
Besides, there are plenty of small company alternatives, like IVPN, which was recommended widely around the time this news broke. And I think that people who found out about Mullvad are likely often the sort to put thought and research into their choice of VPN, rather than just buying NordVPN or whatever based on name recognition only.
A single data point is pretty meaningless. If there were actually data to be found on how the customer base numbers or growth rates of the various VPN companies have or haven't shifted since the news broke, that would be interesting.
Ultimately though, what other people do or don't choose to do is irrelevant to my own choice. Moral purity, as you call it, is impossible. The world is not simple. I am going to do my best to make ethical choices anyway.
shafyy 4 hours ago [-]
Agree fully. Also, using another VPN is simple and possible. Using another mobile platform than iOS or Android is virtually impossible or only possible with a lot of real limitations in your daily life.
And to reply to the parent of this comment: I also wouldn't judge others just because they are a Mullvad customer or whatever.
LeoPanthera 11 hours ago [-]
A lot of people are abandoning Mullvad because their CEO is directly funding a far-right political party.
As they should, IMHO.
KoolKat23 5 hours ago [-]
Purity politics, doesn't work sorry, just highlights hypocrisy.
I can't see how this has any bearing on the functioning of Mullvad, if they were campaigning on circumventing privacy rights it'd be a different story.
duskdozer 5 hours ago [-]
Sometimes people don't want to financially support people or companies that engage in certain behaviors they consider unethical. Whether or not the product functions is irrelevant in such a situation.
KoolKat23 1 hours ago [-]
It's more the soapboxing that's the issue.
I long for the days when not everything in life is given a political twist. This is a relatively recent phenomenon.
duskdozer 5 hours ago [-]
Do you know if there are other/general replacements for their browser extension that allows choosing a server/location per domain?
mephju 10 hours ago [-]
That actually signals that the CEO has a legit reason for Mullvad to work really well.
Plont 8 hours ago [-]
Sure. But the political party in question has an explicit goal of rounding up and "deporting" all immigrants and all the children of immigrants (including those who grew up in Sweden and are citizens).
Besides being reprehensible, that kind of mass trafficking requires mass surveillance. It simply can't be done without it.
This kind of surveillance is antithetical to what Mullvad promises.
There of course could be a "privacy for me and my customers, but not for thee" thing in their minds.
But I don't trust that CEO whatsoever, and I don't trust the rest of Mullvad's leadership either because their response to the backlash was mealy mouthed "everyone is entitled to their opinion, let's all be civil" minimization schlock. They didn't give a fuck; they just wanted the PR problem to go away.
Mullvad's VPN service might continue to be trustworthy, but... I have other options. And it could be enshittified over time, just like so many other things. At least one CEO has a motivation to enable mass surveillance.
I'm also just not going to knowingly put money into the hands of someone I know will use it for evil, if and when I have a choice, which in this case I do.
skaul 21 hours ago [-]
So two hops, basically. First hop sees your IP address but not the website you're going to, second hop sees website but not IP address. Similar to Private Relay: https://support.apple.com/en-us/102602.
dongcarl 21 hours ago [-]
(Carl from Obscura here)
Yup, exactly!
skaul 17 hours ago [-]
Cool work. Can I ask: why not use MASQUE for this, instead of WireGuard-over-QUIC? Is it because it meant less changes on your partner's side?
dongcarl 14 hours ago [-]
(Carl from Obscura here)
Yup! Mostly less changes on Mullvad's side. Also QUIC has less overhead than MASQUE by definition.
mulmen 21 hours ago [-]
But if both services keep logs de-anonymization is a join.
dongcarl 20 hours ago [-]
(Carl from Obscura here)
Very true, but if even 1 of (Obscura, Mullvad) is honest, there's no de-anonymization.
For traditional Single-Party VPNs, you just need to compromise 1 party, with Two-Party Relays, you need to compromise both.
ignoramous 10 hours ago [-]
> Very true, but if even 1 of (Obscura, Mullvad) is honest
Unless something has changed in Obscura's architecture, the interface with Mullvad is under Obscura's control, and thus it can compromise client's credentials. This is unlike iCloud Private Relay where the guarantees are cryptographic in nature and not merely based on promises.
15 hours ago [-]
PunchyHamster 21 hours ago [-]
They don't even need to. If you observe enough of them you can correlate traffic patterns between them and find out which one is used by which endpoint
side note: i really wish more companies did the no email + randomized account number flow. there is a certain popular "pro-privacy" product beloved by many here that requires an email address and refuses to offer a similar account number method, which has turned me off the product.
dongcarl 20 hours ago [-]
(Carl from Obscura here)
Yeah we thought the randomized account number flow was an ingenious idea, so we did that and made the last digit a Verhoeff checksum to check for mistypes!
Though sometimes people forget to write the number down and... There's not much we can do.
dustyharddrive 12 hours ago [-]
In case you're alluding to a certain metasearch engine, they do not verify email addresses.
mulmen 21 hours ago [-]
> there is a certain popular "pro-privacy" product beloved by many here
Please don’t speak in riddles. Just say what you mean.
t-writescode 21 hours ago [-]
They’re almost certainly referencing Signal.
duskdozer 5 hours ago [-]
Signal is worse, with phone numbers, no?
8 hours ago [-]
10 hours ago [-]
john_strinlai 21 hours ago [-]
for what purpose? there is nothing to be gained from pointing fingers, and takes the discussion in an even more unrelated direction.
although i guess people's curiosity is also dragging my comment in an unrelated direction anyways. lose-lose situation.
my main point is that the account number method is really nice, and a great selling point for such privacy-conscious products. not offering it in a privacy-conscious product is enough signal that it has made me choose not to purchase the product. that's the important bit, and where i was hoping to drive the conversation.
bityard 21 hours ago [-]
There is even less to be gained by issuing vague unactionable warnings and/or accusations...
john_strinlai 21 hours ago [-]
it's not a warning or accusation...
this isn't some hidden feature you get caught with your pants down over. if you try to sign up to something and it doesn't offer an account number, you know that it doesn't offer an account number instantly.
no time wasted for you. it's not some nefarious plot by the company.
it's just a business decision. i was hoping to talk about the business decision of that particular sign up flow.
PunchyHamster 21 hours ago [-]
Incorrect. Pointing out bad products is a warning to other people to not waste time on it. We should be doing it more, not less.
I also have no idea what company/service you're talking about
mulmen 21 hours ago [-]
Because it creates confusion as proven by the responses mistakenly assuming that you were referring to proton.
john_strinlai 21 hours ago [-]
and if i mention the company, the responses are all about the company instead of the feature.
next time i will just keep my thoughts to myself and we'll all be happy.
_bernd 19 hours ago [-]
Yeap :/
mulmen 17 hours ago [-]
You could have just ended your comment at:
> side note: i really wish more companies did the no email + randomized account number flow.
Everything you said after that added confusion and this tangent instead of the conversation you wanted to have.
16 hours ago [-]
mulmen 14 hours ago [-]
If you made that comment face to face I would assume you want me to ask what the company is. You could just not do that and talk about the signup flow instead. If you don’t want to talk about something don’t bring it up.
_bernd 10 hours ago [-]
No. Sometimes you just want to make a reference without derailing the conversation.
And all of you derailed happily.
mulmen 8 hours ago [-]
Am I out of touch?
No, it is the children^W commenters who are wrong.
ignoramous 21 hours ago [-]
> ... a certain popular "pro-privacy" product beloved by many here ...
i am hesitant to really narrow it down, but it is not proton (i am a very early proton customer)
mulmen 21 hours ago [-]
Then why comment at all? This is the danger of speaking in riddles.
21 hours ago [-]
baal80spam 21 hours ago [-]
privacy <> anonymity
Proton VPN ensures privacy.
water-drummer 21 hours ago [-]
Privacy without anonymity is just privacy with a backdoor waiting to be unlocked.
john_strinlai 21 hours ago [-]
i am not talking about proton.
RandomGerm4n 10 hours ago [-]
It would be cool if there were a way to use it the other way around. A Mullvad server as the entry point and an Obscura server as the exit point. My main problem with Mullvad right now is that its servers are blocked almost everywhere or generate an excessive number of Captchas. With other VPNs, that’s been much less of an issue so far. Alternatively, a residential proxy might be a good option as an optional exit point. One way to achieve this, for example, would be through a partnership with a regular ISP from which you could then borrow IP addresses.
c16 10 hours ago [-]
> My main problem with Mullvad right now is that its servers are blocked almost everywhere or generate an excessive number of Captchas
Why not buy a Low End Box and run one of the WG Setup scripts to get you going? You'll lose the anonymity, but its your box, a clean IP, significantly cheaper than a commercial vpn.
RandomGerm4n 8 hours ago [-]
Because anonymity is the reason I use a VPN in the first place. Without anonymity, I’d have to worry about getting a cease-and-desist letter if I downloaded a torrent, or having the police raid my house if I accidentally called a politician a dick.
wahern 21 hours ago [-]
> the first VPN that can’t log your activity
and outsmarts internet censorship.
Pretty sure Carl has heard of them, having worked for Adam Back with me at Blockstream...
railka 7 hours ago [-]
There are two types of VPN users: those who care about privacy and those who care about bypassing DPI.
cedws 6 hours ago [-]
Third: those who don’t have a British digital wanking license
workfromspace 6 hours ago [-]
Forgive my ignorance, but can we have both?
osnxkwmxkwnd 21 hours ago [-]
This sounds pretty neat, and I do dig the website, though I can’t help but think it’s an odd combination to have bitmap/pixelated fonts and graphics inside perfect squircles.
Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled with care. Right now it feels like the designer had a bunch of ideas and didn’t know how to bring them together in a cohesive identity.
Bonus point for the TRON reference at the end! “I fight for the users!”
dongcarl 20 hours ago [-]
(Carl from Obscura here)
I'm a sucker for retro 8-bit graphics and fun mascots, so we went with that, but when we experimented with 8-bit for actual UI and long text we immediately found it to be super unusable and unreadable :-(
> Bonus point for the TRON reference at the end! “I fight for the users!”
Ah ofc the HN poster knows the reference :-) I've had it as my email signature since high school I think.
10 hours ago [-]
hehdtyjjoj 21 hours ago [-]
How does this prove Obscura and Mullvad can't just both gather tracking data and then just combine it on demand?
dongcarl 20 hours ago [-]
(Carl from Obscura here)
This doesn't prove it. However, Obscura makes it so that there's no *single party* that if hacked or otherwise compromised would hurt your internet privacy.
woah 21 hours ago [-]
and how is it better than just connecting to mullvad over nordvpn or something?
dongcarl 20 hours ago [-]
(Carl from Obscura here)
Other than the obvious hassle? XP
If you connect to Mullvad over NordVPN:
- You're giving both Mullvad and Nord some payment information (with Obscura you only give that to us, Mullvad has no idea)
If you're already a Tailscale user, seems like this solution is nearly identical to using Mullvad as an exit node.
You would go with this solution if you don't trust Tailscale or NordVPN, I guess.
dongcarl 20 hours ago [-]
(Carl from Obscura here)
I could be wrong but in Tailscale if you use Mullvad as an exit node, the traffic flows directly from your device to Mullvad's servers.
Whereas with Obscura, your traffic flows to the Obscura relay, then the Mullvad exit.
iAMkenough 20 hours ago [-]
Yes, but your tailnet IP is what is provided to Mullvad's servers. Not your public IP or personally identifiable information (according to Tailscale).
I'm under the impression that my personal device isn't the WireGuard endpoint for the Mullvad connection, Tailscale is.
dongcarl 20 hours ago [-]
I believe if your device connects directly to Mullvad they will have your real IP (to know where to send reply packets)
iAMkenough 13 hours ago [-]
After further research, I was under the wrong understanding. You are correct that Mullvad still receives your public IP even if routed through Tailscale.
Obviously seems to be an industry-wide problem, but I hope both you and Tailscale can consider alternative endpoints for those who don't want to rely on the Mullvad infrastructure.
Diversification of endpoint providers will help insolate your company from a collapse if Mullvad decides to sell out, and make you more attractive to former Mullvad customers turned off by their Co-Founder's investment of their privacy dollars into extreme right-wing politics.
As far as I know, they don't plan to part ways with the "great replacement theory" executive staff being paid enough to be the highest contributor to the Swedish far-right party Örebropartiet. You have to question whether their highest-paid staff's loyalty to far-right politics influences Mullvad decisions and future partnerships.
Cross the Örebropartiet, and you might be issuing refunds a year from now.
est 16 hours ago [-]
I hope MPTCP would be more popular
Many src-dst connections but as a single logical connection. There's no way any middlebox could easy capture full data even metadata.
http2/QUIC can do something similar with frames (and hopefully multipath)
Don't place your whole stream inside a single src-dst IP connection. Demux them into many paths over the Internet. We need more variety of "traffic shapes" to combat Internet surveillance.
I'd argue it's even more effective than encryption. Split your activity and mix them, monitor traffic over a single transport is useless.
dongcarl 14 hours ago [-]
(Carl from Obscura here)
Yeah it'd be a cool addition to combat internet surveillance but in practicality it may have a lot of problems:
1. Deteriorated performance if it's across unequal links (3G vs. Fibre WiFi)
2. Many countries have single exits to the global internet so they'd be able to assemble everything there
3. The most important plaintext data is probably in the TLS SNI which usually sits in a single packet for TLS in HTTP/3
est 12 hours ago [-]
> Deteriorated performance if it's across unequal links (3G vs. Fibre WiFi)
Hmm, maybe consider MPTCP-like design? It tackles exactly the problem you descrbed.
> Many countries have single exits to the global internet
Well it's f'ed anyway. But multipath makes content restoring much, much more complicated.
Hi I can't really spot any information about how Obscura is funded on the website. Is it a fully self funded project or have it accepted outside investments?
walrus01 20 hours ago [-]
Hi Carl, thanks for being here to answer questions. Two questions: Do you have any active testers in Iran right now, and secondly, how is this architected to deal with advanced DPI boxes in ISP networks that detect flows of encrypted traffic and drop it? The methods I'm seeing people use with success from within Iran right now are very different than something like a commercial mullvad or competitor VPN.
Some of them rely on people having a helpful third party in ("free") country to set up a private relay in something like Azure IP space that isn't used by any other VPN users, so it doesn't attract a level of attention (or attention by multiples of different peoples' encrypted flows) that publicly published commercial VPN services do. It's a hard problem to solve on a scale of more than a couple of people.
The multi party relay concept is great, my concerns are more with traffic detection/DPI in between the end user and the first hop in the relay.
dongcarl 20 hours ago [-]
Can't speak to Iran, but we use QUIC for transport (with an experimental TCP/TLS mode).
https://obscura.com/check/
does this page know the difference between a direct mullvad user and an obscura user, if so, how?
Packet padding but no docs about this?
dongcarl 14 hours ago [-]
> https://obscura.com/check/ does this page know the difference between a direct mullvad user and an obscura user, if so, how?
We don't actually, try visiting it with Mullvad turned on!
> Packet padding but no docs about this?
Yeah it's an experimental feature, we're not 100% happy about how we implemented it so we've left it experimental and are working on a v2.
tbtech_vn 10 hours ago [-]
That's really cool, but perhaps a bit overkill for the typical no-log quick access variant, so shameless plug here even if it primarily is for autonomous agents.
Besides the website being complete slop, one very good reason to avoid this is that it's made by Andrew Lee (of Freenode hostile takeover fame).
jiveturkey 34 minutes ago [-]
vp.net is far from first, and is hot garbage.
ramblurr 21 hours ago [-]
So like OHTTP but for UDP traffic? I suppose they are using MASQUE CONNECT-UDP?
They are careful to not exactly claim the same anonymity properties of Tor, though I think a lay reader will read that differently (ie, that they do have the same anonymity property as Tor).
That said being able to verify the inner wireguard conn to mullvad is nice. Of course you have to trust them that they aren't colluding with mullvad to share your identity/ip. But same goes for OHTTP.
dongcarl 20 hours ago [-]
(Carl from Obscura here)
Actually it's WireGuard over QUIC Unreliable Datagrams!
> Exit servers (run by Mullvad) connect you to the internet but never see your personal info. Obscura masks your real IP address when relaying to the exit server.
How is this possible? If the exit server doesn't know your IP, how does it know where to send the traffic?
dongcarl 14 hours ago [-]
(Carl from Obscura here)
Basically:
Your device <-> Obscura Relay <-> Mullvad Exit <-> Internet
So the exit server knows the IP of the Obscura Relay, but never sees your device's IP, lmk if that's clear!
ChocolateGod 21 hours ago [-]
Your traffic is still unencrypted by the VPN provider at the other end of the Wireguard connection, I am not sure how this changes that?
skyzoidbroczky 14 hours ago [-]
Any vpn company who market itself as aiming for the anonymity of its user is essentially selling snake oil to its customers. The fact that this company pretends to be more respective of the privacy of its user because it is in America is a vast joke, companies in America are expect to collaborate with the security services, even monopolies don't escape from it.
abbracadabbra 19 hours ago [-]
Great signup flow, except there’s an error when it comes to installing the app at the end. Worked around by installing manually via app store
saligne 13 hours ago [-]
i'd like to see some more info about the quic as obfuscation claim. imo this isn't really useful for people living in countries with restrictive firewalls. quic is blocked or throttled quite easily.
MassPikeMike 13 hours ago [-]
I hate to be the one to throw stones at an outfit that is trying to do something good, protecting people's privacy.
But the claim in Obscura's FAQ that paying with Bitcoin or Monero offers more privacy than paying with a credit card is sadly misguided. No-KYC cryptocurrency is largely a thing of the past, and outfits like Chainanalysis can associate a Lightning or Monero address to a human with near-perfect accuracy. The fact that Obscura's FAQ doesn't acknowledge this makes me feel like its author was either pretending this is not the case, or is unaware of it. Either of those is pretty bad.
Mullvad lets customers sign up for an account and pay in cash, which is a good, privacy-preserving choice. In the US, payment by postal money order or by gift card, either of which can be purchased with cash, would also be good choices. Users, and Obscura, should not be fooled by some vague association of cryptocurrency and privacy. In the age of ubiquitous KYC that ship has sailed with the possible exception of ZCash. And I wouldn't bet my life on ZCash, either.
LoganDark 4 hours ago [-]
Bisq exists, I've been using it for years to obtain Bitcoin and Monero for DNM stuff, it's pretty okay. I did prefer LocalMonero for swapping, before they shut down.
Lately Bisq's been going through some bullshit, a few months ago they had a security issue and they shut the whole network down by setting it to require a version of the software that didn't exist for weeks, and lately they've been requiring mandatory updates every week or so. It does work by having you make money transfers to total strangers, revealing your full details, but it's the best I've found.
IIRC, Bisq 2 is for buying your very first BTC in small amounts at a premium (a Matrix chatroom still also exists for this), Bisq 1 is for buying larger amounts at closer to cost but requires a security deposit first.
teravor 12 hours ago [-]
> Chainanalysis can associate a Monero address to a human with near-perfect accuracy
citation needed.
that said, the anonymity set in monero for the moment is 16 per transaction and isn't zero knowledge (a quantum adversary can view the transaction graph but not the amounts) which isn't ideal. they are apparently working on changing this.
dorongrinstein 21 hours ago [-]
I love the website, messaging and idea. Well done.
if you guys need a place to host, please consider controlplane.com
VCFundedGenYer 19 hours ago [-]
Many VPNs don't log activity. Headline is objectively false.
Flimm 12 hours ago [-]
The claim isn't merely that Obscura doesn't log activity. The claim is that Obscura is unable to, because it is a relay to another VPN provider Mullvad. That is distinct from other VPN providers.
iAMkenough 21 hours ago [-]
Basically a middle-man for a Mullvad VPN, where if Mullvad decides to pull out of their agreement with this company, you lose your connection and are hopefully refunded.
The single point of failure for this product is Mullvad and its leadership's changing opinions.
We wrote a research paper on the general principle a few years ago: https://conferences.sigcomm.org/hotnets/2022/papers/hotnets2...
The Decoupling Principle: A Practical Privacy Framework [pdf] - https://news.ycombinator.com/item?id=33897450 - Dec 2022 (3 comments)
Perhaps we should arrange a new thread about this?
I didn't realize Chris Wood was also an author!
Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.
Why should I choose this over Mullvad?
According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.
The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?
[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/
I love folks who are also reasoning through security models! A few things to note here:
- We believe that all software running on a user's computer should be open source, so you can audit and build your own client: https://github.com/Sovereign-Engineering/obscuravpn-client
- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).
- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.
Another question: How does the Obscura client get the Mullvad exit server’s public key? Are they hardcoded at compile time, fetched from Mullvad's server, or fetched from Obscura's server?
The latter seems to be dangerous if there isn't some kind of signature verification done on the client side before using the key.
Its just very, very, very unfortunate that they chose the US for Obscura.
Of all the jurisdictions in the world you chose the one that has become exponentially untrustworthy in the eyes of non-US users ....
We do currently show it in the app and there's an easily clickable link so you can verify against Mullvad's website for the pubkey
https://codamail.com/articles/privacy-law-directory/internat...
"EU surveillance co-operation"
In other news, it has been demonstrated in a court of law that Mullvad "no logs" means no logs.
TL;DR: Six police officers turned up at Mullvad offices with a search warrant for logs and data. Mullvad said "take a look for yourself". They went home with nothing.
Lots of people on HN and elsewhere are spreading a lot of FUD about the EU and what the EU MIGHT do – remember MIGHT .... politicians discuss a lot of stuff, and a lot of it never gets implemented.
It is the job of politicians to discuss issues of the day and potential ways to deal with them.
One thing that is clear. The EU is not a dicatorship. They have a long history of listening and acting on what industry experts tell them. Even if it means "watering down" ideas being discussed by the politicians.
I have a lot of faith that Mullvad (and, frankly, all the other VPN providers) would make a lot of noise if any of this EU FUD people are spreading actually ever became reality.
Until then, I suggest people put the EU FUD tin-foil hat to one side.
[1] https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec... [2] https://mullvad.net/en/blog/update-the-swedish-authorities-a...
[1] - lobbying by leather industry to exempt them from EU Deforestation Regulation - https://news.mongabay.com/2026/09/now-exempt-from-eu-defores...
[2] - lobbying to remove due diligence on human rights violation in supply chain in certain industry sectors - https://www.business-humanrights.org/en/latest-news/eu-csddd...
> They have a long history of listening and acting on what industry experts tell them
Yes, most famously the diesel gate, european automakers cheating emission tests, [3] because EU invited companies to self regulate their lab tests.
[3] - https://corporateeurope.org/sites/default/files/driving_into...
World used to believe companies used to care for them, before snowden showed up. Even now people are still surprised, when companies like LG get caught doing illegal stuff. How long before there is a scandal in EU? Fool me once...
As much as i like to believe EU "cares" about the consumer, its really stupid for someone to blindly put their faith in Mullvad. Zero trust. When you are online, you are on your own.
As for what's different: We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays): https://www.privacyguides.org/articles/2024/11/17/where-are-...
With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised. More on this here: https://obscura.com/#how
Also, all our apps are open-source as well: https://github.com/Sovereign-Engineering/obscuravpn-client
Disclaimer: I'm the creator of Obscura.
The differences are:
- We allow you to choose an exit location (I believe iCloud Private Relay restricts you to the same location)
- Our exit hop is Mullvad instead of Cloudflare+Fastly+Akamai
- We use QUIC for transport instead of HTTP/3 (which is built on QUIC and has a bit more overhead)
“1: Maintain general location
2: Use country and time zone
Maintain your general location to receive localized content, or enhance your privacy by using a broader IP address based on your country and time zone.
Safari Private Browsing always uses an IP location from your country and time zone.”
1.5k comments discussion for context: https://news.ycombinator.com/item?id=48717469
For example, every big tech company supports the current US administration in some capacity, either with funds, their surveillance stack or both.
Almost noone has stopped using big tech products and services because of that. (Unfortunately!)
But beware! There is someone in one tiny, privacy-preserving company who is doing something that not everyone agrees with!
That is a big problem, right? I think this is a big problem, everyone!
You see those comments in every Mullvad thread, but not necessarily in every thread about big tech products or services.
In case of Mullvad it's a niche product with many alternatives. Using something else is viable and it is interesting to many in the niche because their ties to far right was secret up until recently.
It might be harder with something like Basecamp or Figma if your job requires it.
It is almost impossible with things like Google.
Yes we should have these comments in every thread about big tech. It doesn't mean we shouldn't do something about Mullvad.
As you wrote yourself, this is not the majority. Quite the understatement.
However, this is only a tangential notion in my comment. What do you think of my (probably not unique or novel) observation that calls for ethical purity seem to be very selective in a way that (in effect!) benefits big tech?
For example: The other person in this very thread who pointed out that Mullvad is not perfectly pure recommended iCloud in their previous HN comment three days ago. Did their attitude change in this three days? Unlikely.
iCloud is a service from a company that deplatforms ICE transparency apps, among many other things. Its then CEO, Tim Cook, personally gifted one million USD to Donald Trump for his inauguration. (The very thing they criticized: "... their CEO is directly funding a far-right ...")
Humans are rarely pure or heavenly. Double standards help incumbents.
There is a difference, also, between saying, "I am not morally okay with this, so I am going to do X", vs. "If you don't also do X, you are a Bad Person."
To me, after reading up on the platform of the right-wing party in question and Mullvad's CEO's level of involvement with it, the situation with Mullvad is worse. And because it is a much smaller company, a much greater percentage of my money would go to that CEO in particular. And my choice to pay or not has much more influence on Mullvad than it ever could have on Apple.
Others are free to feel otherwise, and to use their money as they please.
Besides, there are plenty of small company alternatives, like IVPN, which was recommended widely around the time this news broke. And I think that people who found out about Mullvad are likely often the sort to put thought and research into their choice of VPN, rather than just buying NordVPN or whatever based on name recognition only.
A single data point is pretty meaningless. If there were actually data to be found on how the customer base numbers or growth rates of the various VPN companies have or haven't shifted since the news broke, that would be interesting.
Ultimately though, what other people do or don't choose to do is irrelevant to my own choice. Moral purity, as you call it, is impossible. The world is not simple. I am going to do my best to make ethical choices anyway.
And to reply to the parent of this comment: I also wouldn't judge others just because they are a Mullvad customer or whatever.
As they should, IMHO.
I can't see how this has any bearing on the functioning of Mullvad, if they were campaigning on circumventing privacy rights it'd be a different story.
Besides being reprehensible, that kind of mass trafficking requires mass surveillance. It simply can't be done without it.
This kind of surveillance is antithetical to what Mullvad promises.
There of course could be a "privacy for me and my customers, but not for thee" thing in their minds.
But I don't trust that CEO whatsoever, and I don't trust the rest of Mullvad's leadership either because their response to the backlash was mealy mouthed "everyone is entitled to their opinion, let's all be civil" minimization schlock. They didn't give a fuck; they just wanted the PR problem to go away.
Mullvad's VPN service might continue to be trustworthy, but... I have other options. And it could be enshittified over time, just like so many other things. At least one CEO has a motivation to enable mass surveillance.
I'm also just not going to knowingly put money into the hands of someone I know will use it for evil, if and when I have a choice, which in this case I do.
Yup, exactly!
Yup! Mostly less changes on Mullvad's side. Also QUIC has less overhead than MASQUE by definition.
Very true, but if even 1 of (Obscura, Mullvad) is honest, there's no de-anonymization.
For traditional Single-Party VPNs, you just need to compromise 1 party, with Two-Party Relays, you need to compromise both.
Just Obscura's compromise is enough, as pointed out previously: https://news.ycombinator.com/item?id=43016574
Unless something has changed in Obscura's architecture, the interface with Mullvad is under Obscura's control, and thus it can compromise client's credentials. This is unlike iCloud Private Relay where the guarantees are cryptographic in nature and not merely based on promises.
side note: i really wish more companies did the no email + randomized account number flow. there is a certain popular "pro-privacy" product beloved by many here that requires an email address and refuses to offer a similar account number method, which has turned me off the product.
Yeah we thought the randomized account number flow was an ingenious idea, so we did that and made the last digit a Verhoeff checksum to check for mistypes!
Though sometimes people forget to write the number down and... There's not much we can do.
Please don’t speak in riddles. Just say what you mean.
although i guess people's curiosity is also dragging my comment in an unrelated direction anyways. lose-lose situation.
my main point is that the account number method is really nice, and a great selling point for such privacy-conscious products. not offering it in a privacy-conscious product is enough signal that it has made me choose not to purchase the product. that's the important bit, and where i was hoping to drive the conversation.
this isn't some hidden feature you get caught with your pants down over. if you try to sign up to something and it doesn't offer an account number, you know that it doesn't offer an account number instantly.
no time wasted for you. it's not some nefarious plot by the company.
it's just a business decision. i was hoping to talk about the business decision of that particular sign up flow.
I also have no idea what company/service you're talking about
next time i will just keep my thoughts to myself and we'll all be happy.
> side note: i really wish more companies did the no email + randomized account number flow.
Everything you said after that added confusion and this tangent instead of the conversation you wanted to have.
No, it is the children^W commenters who are wrong.
If you're talking about Proton VPN, they do support "credential-less accounts" through their official apps, I believe? At least, on Android since 2024: https://www.androidpolice.com/proton-vpn-works-without-accou...
Proton VPN ensures privacy.
Why not buy a Low End Box and run one of the WG Setup scripts to get you going? You'll lose the anonymity, but its your box, a clean IP, significantly cheaper than a commercial vpn.
I guess they never heard of Zero Knowledge Systems: https://en.wikipedia.org/wiki/Zero_Knowledge_Systems
Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled with care. Right now it feels like the designer had a bunch of ideas and didn’t know how to bring them together in a cohesive identity.
Bonus point for the TRON reference at the end! “I fight for the users!”
I'm a sucker for retro 8-bit graphics and fun mascots, so we went with that, but when we experimented with 8-bit for actual UI and long text we immediately found it to be super unusable and unreadable :-(
> Bonus point for the TRON reference at the end! “I fight for the users!”
Ah ofc the HN poster knows the reference :-) I've had it as my email signature since high school I think.
This doesn't prove it. However, Obscura makes it so that there's no *single party* that if hacked or otherwise compromised would hurt your internet privacy.
Other than the obvious hassle? XP
If you connect to Mullvad over NordVPN:
- You're giving both Mullvad and Nord some payment information (with Obscura you only give that to us, Mullvad has no idea)
- You don't get our QUIC-based obfuscation (see more here: https://obscura.com/blog/bootstrapping-trust/)
You would go with this solution if you don't trust Tailscale or NordVPN, I guess.
I could be wrong but in Tailscale if you use Mullvad as an exit node, the traffic flows directly from your device to Mullvad's servers.
Whereas with Obscura, your traffic flows to the Obscura relay, then the Mullvad exit.
I'm under the impression that my personal device isn't the WireGuard endpoint for the Mullvad connection, Tailscale is.
Obviously seems to be an industry-wide problem, but I hope both you and Tailscale can consider alternative endpoints for those who don't want to rely on the Mullvad infrastructure.
Diversification of endpoint providers will help insolate your company from a collapse if Mullvad decides to sell out, and make you more attractive to former Mullvad customers turned off by their Co-Founder's investment of their privacy dollars into extreme right-wing politics.
As far as I know, they don't plan to part ways with the "great replacement theory" executive staff being paid enough to be the highest contributor to the Swedish far-right party Örebropartiet. You have to question whether their highest-paid staff's loyalty to far-right politics influences Mullvad decisions and future partnerships.
Cross the Örebropartiet, and you might be issuing refunds a year from now.
Many src-dst connections but as a single logical connection. There's no way any middlebox could easy capture full data even metadata.
http2/QUIC can do something similar with frames (and hopefully multipath)
Don't place your whole stream inside a single src-dst IP connection. Demux them into many paths over the Internet. We need more variety of "traffic shapes" to combat Internet surveillance.
I'd argue it's even more effective than encryption. Split your activity and mix them, monitor traffic over a single transport is useless.
Yeah it'd be a cool addition to combat internet surveillance but in practicality it may have a lot of problems:
1. Deteriorated performance if it's across unequal links (3G vs. Fibre WiFi)
2. Many countries have single exits to the global internet so they'd be able to assemble everything there
3. The most important plaintext data is probably in the TLS SNI which usually sits in a single packet for TLS in HTTP/3
Hmm, maybe consider MPTCP-like design? It tackles exactly the problem you descrbed.
> Many countries have single exits to the global internet
Well it's f'ed anyway. But multipath makes content restoring much, much more complicated.
Happy to answer any questions y’all might have!
Also, the technical folks may be more interested in our original post: https://obscura.com/blog/bootstrapping-trust/
Some of them rely on people having a helpful third party in ("free") country to set up a private relay in something like Azure IP space that isn't used by any other VPN users, so it doesn't attract a level of attention (or attention by multiples of different peoples' encrypted flows) that publicly published commercial VPN services do. It's a hard problem to solve on a scale of more than a couple of people.
The multi party relay concept is great, my concerns are more with traffic detection/DPI in between the end user and the first hop in the relay.
I believe QUIC has been harder to block for censors, esp with Chaos Protection on by default in Chrome. See: https://gfw.report/publications/usenixsecurity25/en/
Packet padding but no docs about this?
We don't actually, try visiting it with Mullvad turned on!
> Packet padding but no docs about this?
Yeah it's an experimental feature, we're not 100% happy about how we implemented it so we've left it experimental and are working on a v2.
https://x402socks.com
This is where part of your money flows to (I have opinions about this).
Not sure if you are also aware of it.
They are careful to not exactly claim the same anonymity properties of Tor, though I think a lay reader will read that differently (ie, that they do have the same anonymity property as Tor).
That said being able to verify the inner wireguard conn to mullvad is nice. Of course you have to trust them that they aren't colluding with mullvad to share your identity/ip. But same goes for OHTTP.
Actually it's WireGuard over QUIC Unreliable Datagrams!
See: https://obscura.com/blog/bootstrapping-trust/
How is this possible? If the exit server doesn't know your IP, how does it know where to send the traffic?
Basically:
Your device <-> Obscura Relay <-> Mullvad Exit <-> Internet
So the exit server knows the IP of the Obscura Relay, but never sees your device's IP, lmk if that's clear!
But the claim in Obscura's FAQ that paying with Bitcoin or Monero offers more privacy than paying with a credit card is sadly misguided. No-KYC cryptocurrency is largely a thing of the past, and outfits like Chainanalysis can associate a Lightning or Monero address to a human with near-perfect accuracy. The fact that Obscura's FAQ doesn't acknowledge this makes me feel like its author was either pretending this is not the case, or is unaware of it. Either of those is pretty bad.
Mullvad lets customers sign up for an account and pay in cash, which is a good, privacy-preserving choice. In the US, payment by postal money order or by gift card, either of which can be purchased with cash, would also be good choices. Users, and Obscura, should not be fooled by some vague association of cryptocurrency and privacy. In the age of ubiquitous KYC that ship has sailed with the possible exception of ZCash. And I wouldn't bet my life on ZCash, either.
Lately Bisq's been going through some bullshit, a few months ago they had a security issue and they shut the whole network down by setting it to require a version of the software that didn't exist for weeks, and lately they've been requiring mandatory updates every week or so. It does work by having you make money transfers to total strangers, revealing your full details, but it's the best I've found.
IIRC, Bisq 2 is for buying your very first BTC in small amounts at a premium (a Matrix chatroom still also exists for this), Bisq 1 is for buying larger amounts at closer to cost but requires a security deposit first.
citation needed.
that said, the anonymity set in monero for the moment is 16 per transaction and isn't zero knowledge (a quantum adversary can view the transaction graph but not the amounts) which isn't ideal. they are apparently working on changing this.
The single point of failure for this product is Mullvad and its leadership's changing opinions.
Secondly, Mullvad did what Obscura does now years ago.
Furthermore who needs a gamified VPN tool?
I totally agree for traditional Single-Party VPNs, which is why we are a Two-Party Relay. More here: https://obscura.com/blog/bootstrapping-trust/
Really? XD