Top
Best
New

Posted by Flimm 1 day ago

Obscura: VPN that can't log your activity(obscura.com)
192 points | 139 commentspage 2
hehdtyjjoj 1 day ago|
How does this prove Obscura and Mullvad can't just both gather tracking data and then just combine it on demand?
dongcarl 1 day ago||
(Carl from Obscura here)

This doesn't prove it. However, Obscura makes it so that there's no *single party* that if hacked or otherwise compromised would hurt your internet privacy.

woah 1 day ago||
and how is it better than just connecting to mullvad over nordvpn or something?
dongcarl 1 day ago|||
(Carl from Obscura here)

Other than the obvious hassle? XP

If you connect to Mullvad over NordVPN:

- You're giving both Mullvad and Nord some payment information (with Obscura you only give that to us, Mullvad has no idea)

- You don't get our QUIC-based obfuscation (see more here: https://obscura.com/blog/bootstrapping-trust/)

iAMkenough 1 day ago|||
If you're already a Tailscale user, seems like this solution is nearly identical to using Mullvad as an exit node.

You would go with this solution if you don't trust Tailscale or NordVPN, I guess.

dongcarl 1 day ago||
(Carl from Obscura here)

I could be wrong but in Tailscale if you use Mullvad as an exit node, the traffic flows directly from your device to Mullvad's servers.

Whereas with Obscura, your traffic flows to the Obscura relay, then the Mullvad exit.

iAMkenough 1 day ago||
Yes, but your tailnet IP is what is provided to Mullvad's servers. Not your public IP or personally identifiable information (according to Tailscale).

I'm under the impression that my personal device isn't the WireGuard endpoint for the Mullvad connection, Tailscale is.

dongcarl 1 day ago||
I believe if your device connects directly to Mullvad they will have your real IP (to know where to send reply packets)
iAMkenough 1 day ago||
After further research, I was under the wrong understanding. You are correct that Mullvad still receives your public IP even if routed through Tailscale.

Obviously seems to be an industry-wide problem, but I hope both you and Tailscale can consider alternative endpoints for those who don't want to rely on the Mullvad infrastructure.

Diversification of endpoint providers will help insolate your company from a collapse if Mullvad decides to sell out, and make you more attractive to former Mullvad customers turned off by their Co-Founder's investment of their privacy dollars into extreme right-wing politics.

As far as I know, they don't plan to part ways with the "great replacement theory" executive staff being paid enough to be the highest contributor to the Swedish far-right party Örebropartiet. You have to question whether their highest-paid staff's loyalty to far-right politics influences Mullvad decisions and future partnerships.

Cross the Örebropartiet, and you might be issuing refunds a year from now.

dongcarl 1 day ago||
Carl from Obscura here

Happy to answer any questions y’all might have!

Also, the technical folks may be more interested in our original post: https://obscura.com/blog/bootstrapping-trust/

walrus01 1 day ago||
Hi Carl, thanks for being here to answer questions. Two questions: Do you have any active testers in Iran right now, and secondly, how is this architected to deal with advanced DPI boxes in ISP networks that detect flows of encrypted traffic and drop it? The methods I'm seeing people use with success from within Iran right now are very different than something like a commercial mullvad or competitor VPN.

Some of them rely on people having a helpful third party in ("free") country to set up a private relay in something like Azure IP space that isn't used by any other VPN users, so it doesn't attract a level of attention (or attention by multiples of different peoples' encrypted flows) that publicly published commercial VPN services do. It's a hard problem to solve on a scale of more than a couple of people.

The multi party relay concept is great, my concerns are more with traffic detection/DPI in between the end user and the first hop in the relay.

dongcarl 1 day ago||
Can't speak to Iran, but we use QUIC for transport (with an experimental TCP/TLS mode).

I believe QUIC has been harder to block for censors, esp with Chaos Protection on by default in Chrome. See: https://gfw.report/publications/usenixsecurity25/en/

erk__ 1 day ago||
Hi I can't really spot any information about how Obscura is funded on the website. Is it a fully self funded project or have it accepted outside investments?
fh67 1 day ago||
https://obscura.com/check/ does this page know the difference between a direct mullvad user and an obscura user, if so, how?

Packet padding but no docs about this?

dongcarl 1 day ago|
> https://obscura.com/check/ does this page know the difference between a direct mullvad user and an obscura user, if so, how?

We don't actually, try visiting it with Mullvad turned on!

> Packet padding but no docs about this?

Yeah it's an experimental feature, we're not 100% happy about how we implemented it so we've left it experimental and are working on a v2.

est 1 day ago||
I hope MPTCP would be more popular

Many src-dst connections but as a single logical connection. There's no way any middlebox could easy capture full data even metadata.

http2/QUIC can do something similar with frames (and hopefully multipath)

Don't place your whole stream inside a single src-dst IP connection. Demux them into many paths over the Internet. We need more variety of "traffic shapes" to combat Internet surveillance.

I'd argue it's even more effective than encryption. Split your activity and mix them, monitor traffic over a single transport is useless.

dongcarl 1 day ago|
(Carl from Obscura here)

Yeah it'd be a cool addition to combat internet surveillance but in practicality it may have a lot of problems:

1. Deteriorated performance if it's across unequal links (3G vs. Fibre WiFi)

2. Many countries have single exits to the global internet so they'd be able to assemble everything there

3. The most important plaintext data is probably in the TLS SNI which usually sits in a single packet for TLS in HTTP/3

est 1 day ago||
> Deteriorated performance if it's across unequal links (3G vs. Fibre WiFi)

Hmm, maybe consider MPTCP-like design? It tackles exactly the problem you descrbed.

> Many countries have single exits to the global internet

Well it's f'ed anyway. But multipath makes content restoring much, much more complicated.

hp197 1 day ago||
https://news.ycombinator.com/item?id=48696800

This is where part of your money flows to (I have opinions about this).

Not sure if you are also aware of it.

floro 1 day ago||
Vp.net did it first: https://vp.net/l/en-US/technical#cryptography
mzajc 1 day ago||
Besides the website being complete slop, one very good reason to avoid this is that it's made by Andrew Lee (of Freenode hostile takeover fame).
floro 19 hours ago||
I agree with you on the latter. But how come this is slop when the front page of HN is full of AI "did something great" ads?
jiveturkey 1 day ago||
vp.net is far from first, and is hot garbage.
railka 1 day ago||
There are two types of VPN users: those who care about privacy and those who care about bypassing DPI.
cedws 1 day ago||
Third: those who don’t have a British digital wanking license
workfromspace 1 day ago||
Forgive my ignorance, but can we have both?
skyzoidbroczky 1 day ago||
Any vpn company who market itself as aiming for the anonymity of its user is essentially selling snake oil to its customers. The fact that this company pretends to be more respective of the privacy of its user because it is in America is a vast joke, companies in America are expect to collaborate with the security services, even monopolies don't escape from it.
anticensor 12 hours ago|
Looks like an UC-3 VPN working in multi-hop, not a true UC-7 VPN.
More comments...