Posted by Flimm 1 day ago
We wrote a research paper on the general principle a few years ago: https://conferences.sigcomm.org/hotnets/2022/papers/hotnets2...
The Decoupling Principle: A Practical Privacy Framework [pdf] - https://news.ycombinator.com/item?id=33897450 - Dec 2022 (3 comments)
Perhaps we should arrange a new thread about this?
I didn't realize Chris Wood was also an author!
Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.
Why should I choose this over Mullvad?
According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.
The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?
[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/
I love folks who are also reasoning through security models! A few things to note here:
- We believe that all software running on a user's computer should be open source, so you can audit and build your own client: https://github.com/Sovereign-Engineering/obscuravpn-client
- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).
- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.
Another question: How does the Obscura client get the Mullvad exit server’s public key? Are they hardcoded at compile time, fetched from Mullvad's server, or fetched from Obscura's server?
The latter seems to be dangerous if there isn't some kind of signature verification done on the client side before using the key.
Its just very, very, very unfortunate that they chose the US for Obscura.
Of all the jurisdictions in the world you chose the one that has become exponentially untrustworthy in the eyes of non-US users ....
We do currently show it in the app and there's an easily clickable link so you can verify against Mullvad's website for the pubkey
https://codamail.com/articles/privacy-law-directory/internat...
"EU surveillance co-operation"
In other news, it has been demonstrated in a court of law that Mullvad "no logs" means no logs.
TL;DR: Six police officers turned up at Mullvad offices with a search warrant for logs and data. Mullvad said "take a look for yourself". They went home with nothing.
Lots of people on HN and elsewhere are spreading a lot of FUD about the EU and what the EU MIGHT do – remember MIGHT .... politicians discuss a lot of stuff, and a lot of it never gets implemented.
It is the job of politicians to discuss issues of the day and potential ways to deal with them.
One thing that is clear. The EU is not a dicatorship. They have a long history of listening and acting on what industry experts tell them. Even if it means "watering down" ideas being discussed by the politicians.
I have a lot of faith that Mullvad (and, frankly, all the other VPN providers) would make a lot of noise if any of this EU FUD people are spreading actually ever became reality.
Until then, I suggest people put the EU FUD tin-foil hat to one side.
[1] https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec... [2] https://mullvad.net/en/blog/update-the-swedish-authorities-a...
[1] - lobbying by leather industry to exempt them from EU Deforestation Regulation - https://news.mongabay.com/2026/09/now-exempt-from-eu-defores...
[2] - lobbying to remove due diligence on human rights violation in supply chain in certain industry sectors - https://www.business-humanrights.org/en/latest-news/eu-csddd...
> They have a long history of listening and acting on what industry experts tell them
Yes, most famously the diesel gate, european automakers cheating emission tests, [3] because EU invited companies to self regulate their lab tests.
[3] - https://corporateeurope.org/sites/default/files/driving_into...
World used to believe companies used to care for them, before snowden showed up. Even now people are still surprised, when companies like LG get caught doing illegal stuff. How long before there is a scandal in EU? Fool me once...
As much as i like to believe EU "cares" about the consumer, its really stupid for someone to blindly put their faith in Mullvad. Zero trust. When you are online, you are on your own.
As for what's different: We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays): https://www.privacyguides.org/articles/2024/11/17/where-are-...
With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised. More on this here: https://obscura.com/#how
Also, all our apps are open-source as well: https://github.com/Sovereign-Engineering/obscuravpn-client
Disclaimer: I'm the creator of Obscura.
The differences are:
- We allow you to choose an exit location (I believe iCloud Private Relay restricts you to the same location)
- Our exit hop is Mullvad instead of Cloudflare+Fastly+Akamai
- We use QUIC for transport instead of HTTP/3 (which is built on QUIC and has a bit more overhead)
“1: Maintain general location
2: Use country and time zone
Maintain your general location to receive localized content, or enhance your privacy by using a broader IP address based on your country and time zone.
Safari Private Browsing always uses an IP location from your country and time zone.”
As they should, IMHO.
I can't see how this has any bearing on the functioning of Mullvad, if they were campaigning on circumventing privacy rights it'd be a different story.
Besides being reprehensible, that kind of mass trafficking requires mass surveillance. It simply can't be done without it.
This kind of surveillance is antithetical to what Mullvad promises.
There of course could be a "privacy for me and my customers, but not for thee" thing in their minds.
But I don't trust that CEO whatsoever, and I don't trust the rest of Mullvad's leadership either because their response to the backlash was mealy mouthed "everyone is entitled to their opinion, let's all be civil" minimization schlock. They didn't give a fuck; they just wanted the PR problem to go away.
Mullvad's VPN service might continue to be trustworthy, but... I have other options. And it could be enshittified over time, just like so many other things. At least one CEO has a motivation to enable mass surveillance.
I'm also just not going to knowingly put money into the hands of someone I know will use it for evil, if and when I have a choice, which in this case I do.
1.5k comments discussion for context: https://news.ycombinator.com/item?id=48717469
For example, every big tech company supports the current US administration in some capacity, either with funds, their surveillance stack or both.
Almost noone has stopped using big tech products and services because of that. (Unfortunately!)
But beware! There is someone in one tiny, privacy-preserving company who is doing something that not everyone agrees with!
That is a big problem, right? I think this is a big problem, everyone!
You see those comments in every Mullvad thread, but not necessarily in every thread about big tech products or services.
In case of Mullvad it's a niche product with many alternatives. Using something else is viable and it is interesting to many in the niche because their ties to far right was secret up until recently.
It might be harder with something like Basecamp or Figma if your job requires it.
It is almost impossible with things like Google.
Yes we should have these comments in every thread about big tech. It doesn't mean we shouldn't do something about Mullvad.
As you wrote yourself, this is not the majority. Quite the understatement.
However, this is only a tangential notion in my comment. What do you think of my (probably not unique or novel) observation that calls for ethical purity seem to be very selective in a way that (in effect!) benefits big tech?
For example: The other person in this very thread who pointed out that Mullvad is not perfectly pure recommended iCloud in their previous HN comment three days ago. Did their attitude change in this three days? Unlikely.
iCloud is a service from a company that deplatforms ICE transparency apps, among many other things. Its then CEO, Tim Cook, personally gifted one million USD to Donald Trump for his inauguration. (The very thing they criticized: "... their CEO is directly funding a far-right ...")
Humans are rarely pure or heavenly. Double standards help incumbents.
There is a difference, also, between saying, "I am not morally okay with this, so I am going to do X", vs. "If you don't also do X, you are a Bad Person."
To me, after reading up on the platform of the right-wing party in question and Mullvad's CEO's level of involvement with it, the situation with Mullvad is worse. And because it is a much smaller company, a much greater percentage of my money would go to that CEO in particular. And my choice to pay or not has much more influence on Mullvad than it ever could have on Apple.
Others are free to feel otherwise, and to use their money as they please.
Besides, there are plenty of small company alternatives, like IVPN, which was recommended widely around the time this news broke. And I think that people who found out about Mullvad are likely often the sort to put thought and research into their choice of VPN, rather than just buying NordVPN or whatever based on name recognition only.
A single data point is pretty meaningless. If there were actually data to be found on how the customer base numbers or growth rates of the various VPN companies have or haven't shifted since the news broke, that would be interesting.
Ultimately though, what other people do or don't choose to do is irrelevant to my own choice. Moral purity, as you call it, is impossible. The world is not simple. I am going to do my best to make ethical choices anyway.
And to reply to the parent of this comment: I also wouldn't judge others just because they are a Mullvad customer or whatever.
Yup, exactly!
Yup! Mostly less changes on Mullvad's side. Also QUIC has less overhead than MASQUE by definition.
Very true, but if even 1 of (Obscura, Mullvad) is honest, there's no de-anonymization.
For traditional Single-Party VPNs, you just need to compromise 1 party, with Two-Party Relays, you need to compromise both.
Just Obscura's compromise is enough, as pointed out previously: https://news.ycombinator.com/item?id=43016574
Unless something has changed in Obscura's architecture, the interface with Mullvad is under Obscura's control, and thus it can compromise client's credentials. This is unlike iCloud Private Relay where the guarantees are cryptographic in nature and not merely based on promises.
side note: i really wish more companies did the no email + randomized account number flow. there is a certain popular "pro-privacy" product beloved by many here that requires an email address and refuses to offer a similar account number method, which has turned me off the product.
Yeah we thought the randomized account number flow was an ingenious idea, so we did that and made the last digit a Verhoeff checksum to check for mistypes!
Though sometimes people forget to write the number down and... There's not much we can do.
Please don’t speak in riddles. Just say what you mean.
although i guess people's curiosity is also dragging my comment in an unrelated direction anyways. lose-lose situation.
my main point is that the account number method is really nice, and a great selling point for such privacy-conscious products. not offering it in a privacy-conscious product is enough signal that it has made me choose not to purchase the product. that's the important bit, and where i was hoping to drive the conversation.
this isn't some hidden feature you get caught with your pants down over. if you try to sign up to something and it doesn't offer an account number, you know that it doesn't offer an account number instantly.
no time wasted for you. it's not some nefarious plot by the company.
it's just a business decision. i was hoping to talk about the business decision of that particular sign up flow.
I also have no idea what company/service you're talking about
next time i will just keep my thoughts to myself and we'll all be happy.
> side note: i really wish more companies did the no email + randomized account number flow.
Everything you said after that added confusion and this tangent instead of the conversation you wanted to have.
Proton VPN ensures privacy.
If you're talking about Proton VPN, they do support "credential-less accounts" through their official apps, I believe? At least, on Android since 2024: https://www.androidpolice.com/proton-vpn-works-without-accou...
https://www.wnycstudios.org/podcasts/otm/articles/harvard-bo... is a good example: because the person making the threat was one of the few people on the campus network using Tor at the time the threatening emails were sent, he was identified as a suspect.
If an activity is traced to the Obscura network, and your network activity shows you as one of few people using it at the time - or, if you’re using it for completely unrelated things and are unlucky enough to have accessed at the same time someone else used the network for illegal activity - you could be at risk.
Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled with care. Right now it feels like the designer had a bunch of ideas and didn’t know how to bring them together in a cohesive identity.
Bonus point for the TRON reference at the end! “I fight for the users!”
I'm a sucker for retro 8-bit graphics and fun mascots, so we went with that, but when we experimented with 8-bit for actual UI and long text we immediately found it to be super unusable and unreadable :-(
> Bonus point for the TRON reference at the end! “I fight for the users!”
Ah ofc the HN poster knows the reference :-) I've had it as my email signature since high school I think.
I guess they never heard of Zero Knowledge Systems: https://en.wikipedia.org/wiki/Zero_Knowledge_Systems
Why not buy a Low End Box and run one of the WG Setup scripts to get you going? You'll lose the anonymity, but its your box, a clean IP, significantly cheaper than a commercial vpn.
They are careful to not exactly claim the same anonymity properties of Tor, though I think a lay reader will read that differently (ie, that they do have the same anonymity property as Tor).
That said being able to verify the inner wireguard conn to mullvad is nice. Of course you have to trust them that they aren't colluding with mullvad to share your identity/ip. But same goes for OHTTP.
Actually it's WireGuard over QUIC Unreliable Datagrams!