As others have pointed out, this is like Apple iCloud Private Relay, and other multi-hop privacy systems that have been built on and off over the last several decades (Tor included).
Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.
Mullvad is a Swedish company, which has stricter privacy protection laws in place.
According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.
The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?
[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/
- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).
- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.
Yeah, it's basically not possible to offer an actually secure and private service in the US. If men with guns and gag orders haven't shown up at their new york office yet, they will as soon as this VPN gets popular enough to show up on their radar. At that point if they have any integrity they'll shut their service down like Lababit did rather than allow it to be compromised by the state.
Purity politics, doesn't work sorry, just highlights hypocrisy.
I can't see how this has any bearing on the functioning of Mullvad, if they were campaigning on circumventing privacy rights it'd be a different story.
So two hops, basically. First hop sees your IP address but not the website you're going to, second hop sees website but not IP address. Similar to Private Relay: https://support.apple.com/en-us/102602.
They don't even need to. If you observe enough of them you can correlate traffic patterns between them and find out which one is used by which endpoint
side note: i really wish more companies did the no email + randomized account number flow. there is a certain popular "pro-privacy" product beloved by many here that requires an email address and refuses to offer a similar account number method, which has turned me off the product.
Yeah we thought the randomized account number flow was an ingenious idea, so we did that and made the last digit a Verhoeff checksum to check for mistypes!
Though sometimes people forget to write the number down and... There's not much we can do.
for what purpose? there is nothing to be gained from pointing fingers, and takes the discussion in an even more unrelated direction.
although i guess people's curiosity is also dragging my comment in an unrelated direction anyways. lose-lose situation.
my main point is that the account number method is really nice, and a great selling point for such privacy-conscious products. not offering it in a privacy-conscious product is enough signal that it has made me choose not to purchase the product. that's the important bit, and where i was hoping to drive the conversation.
I am a little surprised people jump to Proton as beloved by HN. Proton has a lot of detractors and tends to be a target of some conspiracy/controversy. HN darling definitely suggests Kagi, who are not significantly impressive in terms of privacy-tech which I assumed was why pro-privacy was in air quotes.
This sounds pretty neat, and I do dig the website, though I can’t help but think it’s an odd combination to have bitmap/pixelated fonts and graphics inside perfect squircles.
Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled with care. Right now it feels like the designer had a bunch of ideas and didn’t know how to bring them together in a cohesive identity.
Bonus point for the TRON reference at the end! “I fight for the users!”
I'm a sucker for retro 8-bit graphics and fun mascots, so we went with that, but when we experimented with 8-bit for actual UI and long text we immediately found it to be super unusable and unreadable :-(
> Bonus point for the TRON reference at the end! “I fight for the users!”
Ah ofc the HN poster knows the reference :-) I've had it as my email signature since high school I think.
With a name like this, I’m reminded that privacy is only as good as your entry node being used widely/not being too “obscure.”
https://www.wnycstudios.org/podcasts/otm/articles/harvard-bo... is a good example: because the person making the threat was one of the few people on the campus network using Tor at the time the threatening emails were sent, he was identified as a suspect.
If an activity is traced to the Obscura network, and your network activity shows you as one of few people using it at the time - or, if you’re using it for completely unrelated things and are unlucky enough to have accessed at the same time someone else used the network for illegal activity - you could be at risk.
I take your point, but I think Obscura's design would make this a bit more difficult. It would be difficult to distinguish Obscura users from regular Mullvad users. Firefox offers free VPN through Mullvad, so presumably it's not that distinctive to be using Mullvad's network.
Basically a middle-man for a Mullvad VPN, where if Mullvad decides to pull out of their agreement with this company, you lose your connection and are hopefully refunded.
The single point of failure for this product is Mullvad and its leadership's changing opinions.
It would be cool if there were a way to use it the other way around. A Mullvad server as the entry point and an Obscura server as the exit point. My main problem with Mullvad right now is that its servers are blocked almost everywhere or generate an excessive number of Captchas. With other VPNs, that’s been much less of an issue so far. Alternatively, a residential proxy might be a good option as an optional exit point. One way to achieve this, for example, would be through a partnership with a regular ISP from which you could then borrow IP addresses.
> My main problem with Mullvad right now is that its servers are blocked almost everywhere or generate an excessive number of Captchas
Why not buy a Low End Box and run one of the WG Setup scripts to get you going? You'll lose the anonymity, but its your box, a clean IP, significantly cheaper than a commercial vpn.
Because anonymity is the reason I use a VPN in the first place. Without anonymity, I’d have to worry about getting a cease-and-desist letter if I downloaded a torrent, or having the police raid my house if I accidentally called a politician a dick.
So like OHTTP but for UDP traffic? I suppose they are using MASQUE CONNECT-UDP?
They are careful to not exactly claim the same anonymity properties of Tor, though I think a lay reader will read that differently (ie, that they do have the same anonymity property as Tor).
That said being able to verify the inner wireguard conn to mullvad is nice. Of course you have to trust them that they aren't colluding with mullvad to share your identity/ip. But same goes for OHTTP.
This doesn't prove it. However, Obscura makes it so that there's no *single party* that if hacked or otherwise compromised would hurt your internet privacy.
Hi Carl, thanks for being here to answer questions. Two questions: Do you have any active testers in Iran right now, and secondly, how is this architected to deal with advanced DPI boxes in ISP networks that detect flows of encrypted traffic and drop it? The methods I'm seeing people use with success from within Iran right now are very different than something like a commercial mullvad or competitor VPN.
Some of them rely on people having a helpful third party in ("free") country to set up a private relay in something like Azure IP space that isn't used by any other VPN users, so it doesn't attract a level of attention (or attention by multiples of different peoples' encrypted flows) that publicly published commercial VPN services do. It's a hard problem to solve on a scale of more than a couple of people.
The multi party relay concept is great, my concerns are more with traffic detection/DPI in between the end user and the first hop in the relay.
Hi I can't really spot any information about how Obscura is funded on the website. Is it a fully self funded project or have it accepted outside investments?
Many src-dst connections but as a single logical connection. There's no way any middlebox could easy capture full data even metadata.
http2/QUIC can do something similar with frames (and hopefully multipath)
Don't place your whole stream inside a single src-dst IP connection. Demux them into many paths over the Internet. We need more variety of "traffic shapes" to combat Internet surveillance.
I'd argue it's even more effective than encryption. Split your activity and mix them, monitor traffic over a single transport is useless.
Is there anything like a generalised protocol which would allow network-privacy seekers to decide each hop? Apple iCloud+ Private Relay (2021), INVISV Relay (2022), Obscura VPN (2025, first of its kind) and so on are OK, but it would be nice if the user/customer could choose any two providers that didn't have business relationships with each other without mirimir-style proxy chaining.
Any vpn company who market itself as aiming for the anonymity of its user is essentially selling snake oil to its customers. The fact that this company pretends to be more respective of the privacy of its user because it is in America is a vast joke, companies in America are expect to collaborate with the security services, even monopolies don't escape from it.
That's really cool, but perhaps a bit overkill for the typical no-log quick access variant, so shameless plug here even if it primarily is for autonomous agents.
> Exit servers (run by Mullvad) connect you to the internet but never see your personal info. Obscura masks your real IP address when relaying to the exit server.
How is this possible? If the exit server doesn't know your IP, how does it know where to send the traffic?
i'd like to see some more info about the quic as obfuscation claim. imo this isn't really useful for people living in countries with restrictive firewalls. quic is blocked or throttled quite easily.
I hate to be the one to throw stones at an outfit that is trying to do something good, protecting people's privacy.
But the claim in Obscura's FAQ that paying with Bitcoin or Monero offers more privacy than paying with a credit card is sadly misguided. No-KYC cryptocurrency is largely a thing of the past, and outfits like Chainanalysis can associate a Lightning or Monero address to a human with near-perfect accuracy. The fact that Obscura's FAQ doesn't acknowledge this makes me feel like its author was either pretending this is not the case, or is unaware of it. Either of those is pretty bad.
Mullvad lets customers sign up for an account and pay in cash, which is a good, privacy-preserving choice. In the US, payment by postal money order or by gift card, either of which can be purchased with cash, would also be good choices. Users, and Obscura, should not be fooled by some vague association of cryptocurrency and privacy. In the age of ubiquitous KYC that ship has sailed with the possible exception of ZCash. And I wouldn't bet my life on ZCash, either.
Bisq exists, I've been using it for years to obtain Bitcoin and Monero for DNM stuff, it's pretty okay. I did prefer LocalMonero for swapping, before they shut down.
Lately Bisq's been going through some bullshit, a few months ago they had a security issue and they shut the whole network down by setting it to require a version of the software that didn't exist for weeks, and lately they've been requiring mandatory updates every week or so. It does work by having you make money transfers to total strangers, revealing your full details, but it's the best I've found.
IIRC, Bisq 2 is for buying your very first BTC in small amounts at a premium (a Matrix chatroom still also exists for this), Bisq 1 is for buying larger amounts at closer to cost but requires a security deposit first.
> Chainanalysis can associate a Monero address to a human with near-perfect accuracy
citation needed.
that said, the anonymity set in monero for the moment is 16 per transaction and isn't zero knowledge (a quantum adversary can view the transaction graph but not the amounts) which isn't ideal. they are apparently working on changing this.
The claim isn't merely that Obscura doesn't log activity. The claim is that Obscura is unable to, because it is a relay to another VPN provider Mullvad. That is distinct from other VPN providers.
As others have pointed out, this is like Apple iCloud Private Relay, and other multi-hop privacy systems that have been built on and off over the last several decades (Tor included).
We wrote a research paper on the general principle a few years ago: https://conferences.sigcomm.org/hotnets/2022/papers/hotnets2...
Discussed (just a bit) at the time:
The Decoupling Principle: A Practical Privacy Framework [pdf] - https://news.ycombinator.com/item?id=33897450 - Dec 2022 (3 comments)
Perhaps we should arrange a new thread about this?
Happy to discuss further if it's of interest.
2 replies →
Good to see you here Barath :-)
I didn't realize Chris Wood was also an author!
I don't understand the point of this.
Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.
Why should I choose this over Mullvad?
Mullvad is a Swedish company, which has stricter privacy protection laws in place.
According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.
The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?
[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/
(Carl from Obscura here)
I love folks who are also reasoning through security models! A few things to note here:
- We believe that all software running on a user's computer should be open source, so you can audit and build your own client: https://github.com/Sovereign-Engineering/obscuravpn-client
- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).
- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.
5 replies →
The EU is working to make what Mullvad is doing illegal.
https://codamail.com/articles/privacy-law-directory/internat...
"EU surveillance co-operation"
3 replies →
I wouldn't be so sure; Ex A: The terrifying expansion of Sweden’s state surveillance, https://edri.org/our-work/the-terrifying-expansion-of-sweden...
Yeah, it's basically not possible to offer an actually secure and private service in the US. If men with guns and gag orders haven't shown up at their new york office yet, they will as soon as this VPN gets popular enough to show up on their radar. At that point if they have any integrity they'll shut their service down like Lababit did rather than allow it to be compromised by the state.
Sweden was compromised years ago, Assange's case is proof.
1 reply →
We think Mullvad is a great privacy tool, which is why we partnered with them!
As for what's different: We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays): https://www.privacyguides.org/articles/2024/11/17/where-are-...
With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised. More on this here: https://obscura.com/#how
Also, all our apps are open-source as well: https://github.com/Sovereign-Engineering/obscuravpn-client
Disclaimer: I'm the creator of Obscura.
How do you compare with iCloud Private Relay (with the obvious exception that private relay only works on macOS, and in specific apps only)?
2 replies →
A lot of people are abandoning Mullvad because their CEO is directly funding a far-right political party.
As they should, IMHO.
Purity politics, doesn't work sorry, just highlights hypocrisy.
I can't see how this has any bearing on the functioning of Mullvad, if they were campaigning on circumventing privacy rights it'd be a different story.
3 replies →
That actually signals that the CEO has a legit reason for Mullvad to work really well.
1 reply →
Do you know if there are other/general replacements for their browser extension that allows choosing a server/location per domain?
Because its CEO is known as the sponsor of the Orebro party?
1.5k comments discussion for context: https://news.ycombinator.com/item?id=48717469
I still don't see the relevance. Modern purity politics is silly. Is there a conflict of interest for Mullvad? If not, I don't see the issue.
2 replies →
That indeed can be a problem for many.
6 replies →
So two hops, basically. First hop sees your IP address but not the website you're going to, second hop sees website but not IP address. Similar to Private Relay: https://support.apple.com/en-us/102602.
But if both services keep logs de-anonymization is a join.
(Carl from Obscura here)
Very true, but if even 1 of (Obscura, Mullvad) is honest, there's no de-anonymization.
For traditional Single-Party VPNs, you just need to compromise 1 party, with Two-Party Relays, you need to compromise both.
2 replies →
They don't even need to. If you observe enough of them you can correlate traffic patterns between them and find out which one is used by which endpoint
(Carl from Obscura here)
Yup, exactly!
Cool work. Can I ask: why not use MASQUE for this, instead of WireGuard-over-QUIC? Is it because it meant less changes on your partner's side?
1 reply →
i am very skeptical of most vpn companies, and while i haven't looked too hard at obscura, it is worth noting the official partnership with mullvad (https://mullvad.net/en/blog/mullvad-partnered-with-obscura-v...) which is certainly a positive signal
side note: i really wish more companies did the no email + randomized account number flow. there is a certain popular "pro-privacy" product beloved by many here that requires an email address and refuses to offer a similar account number method, which has turned me off the product.
(Carl from Obscura here)
Yeah we thought the randomized account number flow was an ingenious idea, so we did that and made the last digit a Verhoeff checksum to check for mistypes!
Though sometimes people forget to write the number down and... There's not much we can do.
> there is a certain popular "pro-privacy" product beloved by many here
Please don’t speak in riddles. Just say what you mean.
They’re almost certainly referencing Signal.
4 replies →
for what purpose? there is nothing to be gained from pointing fingers, and takes the discussion in an even more unrelated direction.
although i guess people's curiosity is also dragging my comment in an unrelated direction anyways. lose-lose situation.
my main point is that the account number method is really nice, and a great selling point for such privacy-conscious products. not offering it in a privacy-conscious product is enough signal that it has made me choose not to purchase the product. that's the important bit, and where i was hoping to drive the conversation.
11 replies →
> ... a certain popular "pro-privacy" product beloved by many here ...
If you're talking about Proton VPN, they do support "credential-less accounts" through their official apps, I believe? At least, on Android since 2024: https://www.androidpolice.com/proton-vpn-works-without-accou...
i am hesitant to really narrow it down, but it is not proton (i am a very early proton customer)
2 replies →
I am a little surprised people jump to Proton as beloved by HN. Proton has a lot of detractors and tends to be a target of some conspiracy/controversy. HN darling definitely suggests Kagi, who are not significantly impressive in terms of privacy-tech which I assumed was why pro-privacy was in air quotes.
In case you're alluding to a certain metasearch engine, they do not verify email addresses.
privacy <> anonymity
Proton VPN ensures privacy.
Privacy without anonymity is just privacy with a backdoor waiting to be unlocked.
i am not talking about proton.
This sounds pretty neat, and I do dig the website, though I can’t help but think it’s an odd combination to have bitmap/pixelated fonts and graphics inside perfect squircles.
Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled with care. Right now it feels like the designer had a bunch of ideas and didn’t know how to bring them together in a cohesive identity.
Bonus point for the TRON reference at the end! “I fight for the users!”
(Carl from Obscura here)
I'm a sucker for retro 8-bit graphics and fun mascots, so we went with that, but when we experimented with 8-bit for actual UI and long text we immediately found it to be super unusable and unreadable :-(
> Bonus point for the TRON reference at the end! “I fight for the users!”
Ah ofc the HN poster knows the reference :-) I've had it as my email signature since high school I think.
With a name like this, I’m reminded that privacy is only as good as your entry node being used widely/not being too “obscure.”
https://www.wnycstudios.org/podcasts/otm/articles/harvard-bo... is a good example: because the person making the threat was one of the few people on the campus network using Tor at the time the threatening emails were sent, he was identified as a suspect.
If an activity is traced to the Obscura network, and your network activity shows you as one of few people using it at the time - or, if you’re using it for completely unrelated things and are unlucky enough to have accessed at the same time someone else used the network for illegal activity - you could be at risk.
I take your point, but I think Obscura's design would make this a bit more difficult. It would be difficult to distinguish Obscura users from regular Mullvad users. Firefox offers free VPN through Mullvad, so presumably it's not that distinctive to be using Mullvad's network.
> the first VPN that can’t log your activity and outsmarts internet censorship.
I guess they never heard of Zero Knowledge Systems: https://en.wikipedia.org/wiki/Zero_Knowledge_Systems
Pretty sure Carl has heard of them, having worked for Adam Back with me at Blockstream...
Basically a middle-man for a Mullvad VPN, where if Mullvad decides to pull out of their agreement with this company, you lose your connection and are hopefully refunded.
The single point of failure for this product is Mullvad and its leadership's changing opinions.
Obscura itself is also a point of failure
To make that sound like a risk, not a benefit.
It would be cool if there were a way to use it the other way around. A Mullvad server as the entry point and an Obscura server as the exit point. My main problem with Mullvad right now is that its servers are blocked almost everywhere or generate an excessive number of Captchas. With other VPNs, that’s been much less of an issue so far. Alternatively, a residential proxy might be a good option as an optional exit point. One way to achieve this, for example, would be through a partnership with a regular ISP from which you could then borrow IP addresses.
> My main problem with Mullvad right now is that its servers are blocked almost everywhere or generate an excessive number of Captchas
Why not buy a Low End Box and run one of the WG Setup scripts to get you going? You'll lose the anonymity, but its your box, a clean IP, significantly cheaper than a commercial vpn.
Because anonymity is the reason I use a VPN in the first place. Without anonymity, I’d have to worry about getting a cease-and-desist letter if I downloaded a torrent, or having the police raid my house if I accidentally called a politician a dick.
So like OHTTP but for UDP traffic? I suppose they are using MASQUE CONNECT-UDP?
They are careful to not exactly claim the same anonymity properties of Tor, though I think a lay reader will read that differently (ie, that they do have the same anonymity property as Tor).
That said being able to verify the inner wireguard conn to mullvad is nice. Of course you have to trust them that they aren't colluding with mullvad to share your identity/ip. But same goes for OHTTP.
(Carl from Obscura here)
Actually it's WireGuard over QUIC Unreliable Datagrams!
See: https://obscura.com/blog/bootstrapping-trust/
How does this prove Obscura and Mullvad can't just both gather tracking data and then just combine it on demand?
(Carl from Obscura here)
This doesn't prove it. However, Obscura makes it so that there's no *single party* that if hacked or otherwise compromised would hurt your internet privacy.
and how is it better than just connecting to mullvad over nordvpn or something?
If you're already a Tailscale user, seems like this solution is nearly identical to using Mullvad as an exit node.
You would go with this solution if you don't trust Tailscale or NordVPN, I guess.
4 replies →
(Carl from Obscura here)
Other than the obvious hassle? XP
If you connect to Mullvad over NordVPN:
- You're giving both Mullvad and Nord some payment information (with Obscura you only give that to us, Mullvad has no idea)
- You don't get our QUIC-based obfuscation (see more here: https://obscura.com/blog/bootstrapping-trust/)
Carl from Obscura here
Happy to answer any questions y’all might have!
Also, the technical folks may be more interested in our original post: https://obscura.com/blog/bootstrapping-trust/
Hi Carl, thanks for being here to answer questions. Two questions: Do you have any active testers in Iran right now, and secondly, how is this architected to deal with advanced DPI boxes in ISP networks that detect flows of encrypted traffic and drop it? The methods I'm seeing people use with success from within Iran right now are very different than something like a commercial mullvad or competitor VPN.
Some of them rely on people having a helpful third party in ("free") country to set up a private relay in something like Azure IP space that isn't used by any other VPN users, so it doesn't attract a level of attention (or attention by multiples of different peoples' encrypted flows) that publicly published commercial VPN services do. It's a hard problem to solve on a scale of more than a couple of people.
The multi party relay concept is great, my concerns are more with traffic detection/DPI in between the end user and the first hop in the relay.
Can't speak to Iran, but we use QUIC for transport (with an experimental TCP/TLS mode).
I believe QUIC has been harder to block for censors, esp with Chaos Protection on by default in Chrome. See: https://gfw.report/publications/usenixsecurity25/en/
Hi I can't really spot any information about how Obscura is funded on the website. Is it a fully self funded project or have it accepted outside investments?
https://obscura.com/check/ does this page know the difference between a direct mullvad user and an obscura user, if so, how?
Packet padding but no docs about this?
> https://obscura.com/check/ does this page know the difference between a direct mullvad user and an obscura user, if so, how?
We don't actually, try visiting it with Mullvad turned on!
> Packet padding but no docs about this?
Yeah it's an experimental feature, we're not 100% happy about how we implemented it so we've left it experimental and are working on a v2.
I hope MPTCP would be more popular
Many src-dst connections but as a single logical connection. There's no way any middlebox could easy capture full data even metadata.
http2/QUIC can do something similar with frames (and hopefully multipath)
Don't place your whole stream inside a single src-dst IP connection. Demux them into many paths over the Internet. We need more variety of "traffic shapes" to combat Internet surveillance.
I'd argue it's even more effective than encryption. Split your activity and mix them, monitor traffic over a single transport is useless.
(Carl from Obscura here)
Yeah it'd be a cool addition to combat internet surveillance but in practicality it may have a lot of problems:
1. Deteriorated performance if it's across unequal links (3G vs. Fibre WiFi)
2. Many countries have single exits to the global internet so they'd be able to assemble everything there
3. The most important plaintext data is probably in the TLS SNI which usually sits in a single packet for TLS in HTTP/3
> Deteriorated performance if it's across unequal links (3G vs. Fibre WiFi)
Hmm, maybe consider MPTCP-like design? It tackles exactly the problem you descrbed.
> Many countries have single exits to the global internet
Well it's f'ed anyway. But multipath makes content restoring much, much more complicated.
Is there anything like a generalised protocol which would allow network-privacy seekers to decide each hop? Apple iCloud+ Private Relay (2021), INVISV Relay (2022), Obscura VPN (2025, first of its kind) and so on are OK, but it would be nice if the user/customer could choose any two providers that didn't have business relationships with each other without mirimir-style proxy chaining.
https://news.ycombinator.com/item?id=48696800
This is where part of your money flows to (I have opinions about this).
Not sure if you are also aware of it.
Vp.net did it first: https://vp.net/l/en-US/technical#cryptography
Besides the website being complete slop, one very good reason to avoid this is that it's made by Andrew Lee (of Freenode hostile takeover fame).
I agree with you on the latter. But how come this is slop when the front page of HN is full of AI "did something great" ads?
vp.net is far from first, and is hot garbage.
Any vpn company who market itself as aiming for the anonymity of its user is essentially selling snake oil to its customers. The fact that this company pretends to be more respective of the privacy of its user because it is in America is a vast joke, companies in America are expect to collaborate with the security services, even monopolies don't escape from it.
Looks similar to Anonymized DNS, which DNS users have been using for more than seven years: https://www.ietf.org/archive/id/draft-denis-dprive-dnscrypt-...
Your traffic is still unencrypted by the VPN provider at the other end of the Wireguard connection, I am not sure how this changes that?
There are two types of VPN users: those who care about privacy and those who care about bypassing DPI.
Third: those who don’t have a British digital wanking license
Forgive my ignorance, but can we have both?
That's really cool, but perhaps a bit overkill for the typical no-log quick access variant, so shameless plug here even if it primarily is for autonomous agents.
https://x402socks.com
> Exit servers (run by Mullvad) connect you to the internet but never see your personal info. Obscura masks your real IP address when relaying to the exit server.
How is this possible? If the exit server doesn't know your IP, how does it know where to send the traffic?
(Carl from Obscura here)
Basically:
Your device <-> Obscura Relay <-> Mullvad Exit <-> Internet
So the exit server knows the IP of the Obscura Relay, but never sees your device's IP, lmk if that's clear!
I don't like 'us vs others' kinda comparisons, it's just marketing trick, which means they care more about sales than your privacy.
Secondly, Mullvad did what Obscura does now years ago.
Furthermore who needs a gamified VPN tool?
Great signup flow, except there’s an error when it comes to installing the app at the end. Worked around by installing manually via app store
I love the website, messaging and idea. Well done. if you guys need a place to host, please consider controlplane.com
Looks like an UC-3 VPN working in multi-hop, not a true UC-7 VPN.
i'd like to see some more info about the quic as obfuscation claim. imo this isn't really useful for people living in countries with restrictive firewalls. quic is blocked or throttled quite easily.
I hate to be the one to throw stones at an outfit that is trying to do something good, protecting people's privacy.
But the claim in Obscura's FAQ that paying with Bitcoin or Monero offers more privacy than paying with a credit card is sadly misguided. No-KYC cryptocurrency is largely a thing of the past, and outfits like Chainanalysis can associate a Lightning or Monero address to a human with near-perfect accuracy. The fact that Obscura's FAQ doesn't acknowledge this makes me feel like its author was either pretending this is not the case, or is unaware of it. Either of those is pretty bad.
Mullvad lets customers sign up for an account and pay in cash, which is a good, privacy-preserving choice. In the US, payment by postal money order or by gift card, either of which can be purchased with cash, would also be good choices. Users, and Obscura, should not be fooled by some vague association of cryptocurrency and privacy. In the age of ubiquitous KYC that ship has sailed with the possible exception of ZCash. And I wouldn't bet my life on ZCash, either.
Bisq exists, I've been using it for years to obtain Bitcoin and Monero for DNM stuff, it's pretty okay. I did prefer LocalMonero for swapping, before they shut down.
Lately Bisq's been going through some bullshit, a few months ago they had a security issue and they shut the whole network down by setting it to require a version of the software that didn't exist for weeks, and lately they've been requiring mandatory updates every week or so. It does work by having you make money transfers to total strangers, revealing your full details, but it's the best I've found.
IIRC, Bisq 2 is for buying your very first BTC in small amounts at a premium (a Matrix chatroom still also exists for this), Bisq 1 is for buying larger amounts at closer to cost but requires a security deposit first.
> Chainanalysis can associate a Monero address to a human with near-perfect accuracy
citation needed.
that said, the anonymity set in monero for the moment is 16 per transaction and isn't zero knowledge (a quantum adversary can view the transaction graph but not the amounts) which isn't ideal. they are apparently working on changing this.
Many VPNs don't log activity. Headline is objectively false.
The claim isn't merely that Obscura doesn't log activity. The claim is that Obscura is unable to, because it is a relay to another VPN provider Mullvad. That is distinct from other VPN providers.
a vpn company is a paid for MITM attack surface.
(Carl from Obscura here)
I totally agree for traditional Single-Party VPNs, which is why we are a Two-Party Relay. More here: https://obscura.com/blog/bootstrapping-trust/
> first
Really? XD
[dead]
[dead]
It’s often ‘impossible’ and until it happens /s