Comment by maxloh
5 days ago
I don't understand the point of this.
Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.
Why should I choose this over Mullvad?
Mullvad is a Swedish company, which has stricter privacy protection laws in place.
According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.
The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?
[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/
(Carl from Obscura here)
I love folks who are also reasoning through security models! A few things to note here:
- We believe that all software running on a user's computer should be open source, so you can audit and build your own client: https://github.com/Sovereign-Engineering/obscuravpn-client
- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).
- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.
The "Obscura and Mullvad" argument actually makes sense. Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.
Another question: How does the Obscura client get the Mullvad exit server’s public key? Are they hardcoded at compile time, fetched from Mullvad's server, or fetched from Obscura's server?
The latter seems to be dangerous if there isn't some kind of signature verification done on the client side before using the key.
3 replies →
Generating all of your responses with AI makes me 100% sure you are not to be trusted
The EU is working to make what Mullvad is doing illegal.
https://codamail.com/articles/privacy-law-directory/internat...
"EU surveillance co-operation"
They actually recongised Mullvad-type VPNs as UC-2 in the ETSI EN 304 620 VPN standard.
> The EU is working to make what Mullvad is doing illegal.
In other news, it has been demonstrated in a court of law that Mullvad "no logs" means no logs.
TL;DR: Six police officers turned up at Mullvad offices with a search warrant for logs and data. Mullvad said "take a look for yourself". They went home with nothing.
Lots of people on HN and elsewhere are spreading a lot of FUD about the EU and what the EU MIGHT do – remember MIGHT .... politicians discuss a lot of stuff, and a lot of it never gets implemented.
It is the job of politicians to discuss issues of the day and potential ways to deal with them.
One thing that is clear. The EU is not a dicatorship. They have a long history of listening and acting on what industry experts tell them. Even if it means "watering down" ideas being discussed by the politicians.
I have a lot of faith that Mullvad (and, frankly, all the other VPN providers) would make a lot of noise if any of this EU FUD people are spreading actually ever became reality.
Until then, I suggest people put the EU FUD tin-foil hat to one side.
[1] https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec... [2] https://mullvad.net/en/blog/update-the-swedish-authorities-a...
1 reply →
I wouldn't be so sure; Ex A: The terrifying expansion of Sweden’s state surveillance, https://edri.org/our-work/the-terrifying-expansion-of-sweden...
Yeah, it's basically not possible to offer an actually secure and private service in the US. If men with guns and gag orders haven't shown up at their new york office yet, they will as soon as this VPN gets popular enough to show up on their radar. At that point if they have any integrity they'll shut their service down like Lababit did rather than allow it to be compromised by the state.
Sweden was compromised years ago, Assange's case is proof.
Individuals in Sweden certainly were.
We think Mullvad is a great privacy tool, which is why we partnered with them!
As for what's different: We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays): https://www.privacyguides.org/articles/2024/11/17/where-are-...
With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised. More on this here: https://obscura.com/#how
Also, all our apps are open-source as well: https://github.com/Sovereign-Engineering/obscuravpn-client
Disclaimer: I'm the creator of Obscura.
How do you compare with iCloud Private Relay (with the obvious exception that private relay only works on macOS, and in specific apps only)?
We're heavily inspired by them (see our original blog post which is a bit more technical here: https://obscura.com/blog/bootstrapping-trust/)
The differences are:
- We allow you to choose an exit location (I believe iCloud Private Relay restricts you to the same location)
- Our exit hop is Mullvad instead of Cloudflare+Fastly+Akamai
- We use QUIC for transport instead of HTTP/3 (which is built on QUIC and has a bit more overhead)
1 reply →
A lot of people are abandoning Mullvad because their CEO is directly funding a far-right political party.
As they should, IMHO.
Purity politics, doesn't work sorry, just highlights hypocrisy.
I can't see how this has any bearing on the functioning of Mullvad, if they were campaigning on circumventing privacy rights it'd be a different story.
Sometimes people don't want to financially support people or companies that engage in certain behaviors they consider unethical. Whether or not the product functions is irrelevant in such a situation.
1 reply →
People not wanting to give money to someone they don't like is now purity politics and hypocrisy?
That actually signals that the CEO has a legit reason for Mullvad to work really well.
Sure. But the political party in question has an explicit goal of rounding up and "deporting" all immigrants and all the children of immigrants (including those who grew up in Sweden and are citizens).
Besides being reprehensible, that kind of mass trafficking requires mass surveillance. It simply can't be done without it.
This kind of surveillance is antithetical to what Mullvad promises.
There of course could be a "privacy for me and my customers, but not for thee" thing in their minds.
But I don't trust that CEO whatsoever, and I don't trust the rest of Mullvad's leadership either because their response to the backlash was mealy mouthed "everyone is entitled to their opinion, let's all be civil" minimization schlock. They didn't give a fuck; they just wanted the PR problem to go away.
Mullvad's VPN service might continue to be trustworthy, but... I have other options. And it could be enshittified over time, just like so many other things. At least one CEO has a motivation to enable mass surveillance.
I'm also just not going to knowingly put money into the hands of someone I know will use it for evil, if and when I have a choice, which in this case I do.
Do you know if there are other/general replacements for their browser extension that allows choosing a server/location per domain?
Because its CEO is known as the sponsor of the Orebro party?
1.5k comments discussion for context: https://news.ycombinator.com/item?id=48717469
I still don't see the relevance. Modern purity politics is silly. Is there a conflict of interest for Mullvad? If not, I don't see the issue.
Many people also don't see the relevance of reducing reliance in services from Russian companies or using Chinese software for critical matters either. Newsflash, not everyone has the same opinion.
1 reply →
That indeed can be a problem for many.
Calls for ethical purity are usually very selective, serving to protect incumbents.
For example, every big tech company supports the current US administration in some capacity, either with funds, their surveillance stack or both.
Almost noone has stopped using big tech products and services because of that. (Unfortunately!)
But beware! There is someone in one tiny, privacy-preserving company who is doing something that not everyone agrees with!
That is a big problem, right? I think this is a big problem, everyone!
You see those comments in every Mullvad thread, but not necessarily in every thread about big tech products or services.
5 replies →