Posted by Flimm 1 day ago
This doesn't prove it. However, Obscura makes it so that there's no *single party* that if hacked or otherwise compromised would hurt your internet privacy.
Other than the obvious hassle? XP
If you connect to Mullvad over NordVPN:
- You're giving both Mullvad and Nord some payment information (with Obscura you only give that to us, Mullvad has no idea)
- You don't get our QUIC-based obfuscation (see more here: https://obscura.com/blog/bootstrapping-trust/)
You would go with this solution if you don't trust Tailscale or NordVPN, I guess.
I could be wrong but in Tailscale if you use Mullvad as an exit node, the traffic flows directly from your device to Mullvad's servers.
Whereas with Obscura, your traffic flows to the Obscura relay, then the Mullvad exit.
I'm under the impression that my personal device isn't the WireGuard endpoint for the Mullvad connection, Tailscale is.
Obviously seems to be an industry-wide problem, but I hope both you and Tailscale can consider alternative endpoints for those who don't want to rely on the Mullvad infrastructure.
Diversification of endpoint providers will help insolate your company from a collapse if Mullvad decides to sell out, and make you more attractive to former Mullvad customers turned off by their Co-Founder's investment of their privacy dollars into extreme right-wing politics.
As far as I know, they don't plan to part ways with the "great replacement theory" executive staff being paid enough to be the highest contributor to the Swedish far-right party Örebropartiet. You have to question whether their highest-paid staff's loyalty to far-right politics influences Mullvad decisions and future partnerships.
Cross the Örebropartiet, and you might be issuing refunds a year from now.
Happy to answer any questions y’all might have!
Also, the technical folks may be more interested in our original post: https://obscura.com/blog/bootstrapping-trust/
Some of them rely on people having a helpful third party in ("free") country to set up a private relay in something like Azure IP space that isn't used by any other VPN users, so it doesn't attract a level of attention (or attention by multiples of different peoples' encrypted flows) that publicly published commercial VPN services do. It's a hard problem to solve on a scale of more than a couple of people.
The multi party relay concept is great, my concerns are more with traffic detection/DPI in between the end user and the first hop in the relay.
I believe QUIC has been harder to block for censors, esp with Chaos Protection on by default in Chrome. See: https://gfw.report/publications/usenixsecurity25/en/
Packet padding but no docs about this?
We don't actually, try visiting it with Mullvad turned on!
> Packet padding but no docs about this?
Yeah it's an experimental feature, we're not 100% happy about how we implemented it so we've left it experimental and are working on a v2.
Many src-dst connections but as a single logical connection. There's no way any middlebox could easy capture full data even metadata.
http2/QUIC can do something similar with frames (and hopefully multipath)
Don't place your whole stream inside a single src-dst IP connection. Demux them into many paths over the Internet. We need more variety of "traffic shapes" to combat Internet surveillance.
I'd argue it's even more effective than encryption. Split your activity and mix them, monitor traffic over a single transport is useless.
Yeah it'd be a cool addition to combat internet surveillance but in practicality it may have a lot of problems:
1. Deteriorated performance if it's across unequal links (3G vs. Fibre WiFi)
2. Many countries have single exits to the global internet so they'd be able to assemble everything there
3. The most important plaintext data is probably in the TLS SNI which usually sits in a single packet for TLS in HTTP/3
Hmm, maybe consider MPTCP-like design? It tackles exactly the problem you descrbed.
> Many countries have single exits to the global internet
Well it's f'ed anyway. But multipath makes content restoring much, much more complicated.
This is where part of your money flows to (I have opinions about this).
Not sure if you are also aware of it.