← Back to context

Comment by maxloh

5 days ago

Mullvad is a Swedish company, which has stricter privacy protection laws in place.

According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.

The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?

[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/

(Carl from Obscura here)

I love folks who are also reasoning through security models! A few things to note here:

- We believe that all software running on a user's computer should be open source, so you can audit and build your own client: https://github.com/Sovereign-Engineering/obscuravpn-client

- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).

- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.

  • The "Obscura and Mullvad" argument actually makes sense. Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.

    Another question: How does the Obscura client get the Mullvad exit server’s public key? Are they hardcoded at compile time, fetched from Mullvad's server, or fetched from Obscura's server?

    The latter seems to be dangerous if there isn't some kind of signature verification done on the client side before using the key.

    • Good question! It's the latter right now (which is not ideal), but I think Mullvad is going to sign their server pubkeys pretty soon and we'll switch to that.

      We do currently show it in the app and there's an easily clickable link so you can verify against Mullvad's website for the pubkey

    • > Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.

      Its just very, very, very unfortunate that they chose the US for Obscura.

      Of all the jurisdictions in the world you chose the one that has become exponentially untrustworthy in the eyes of non-US users ....

      1 reply →

The EU is working to make what Mullvad is doing illegal.

https://codamail.com/articles/privacy-law-directory/internat...

"EU surveillance co-operation"

  • > The EU is working to make what Mullvad is doing illegal.

    In other news, it has been demonstrated in a court of law that Mullvad "no logs" means no logs.

    TL;DR: Six police officers turned up at Mullvad offices with a search warrant for logs and data. Mullvad said "take a look for yourself". They went home with nothing.

    Lots of people on HN and elsewhere are spreading a lot of FUD about the EU and what the EU MIGHT do – remember MIGHT .... politicians discuss a lot of stuff, and a lot of it never gets implemented.

    It is the job of politicians to discuss issues of the day and potential ways to deal with them.

    One thing that is clear. The EU is not a dicatorship. They have a long history of listening and acting on what industry experts tell them. Even if it means "watering down" ideas being discussed by the politicians.

    I have a lot of faith that Mullvad (and, frankly, all the other VPN providers) would make a lot of noise if any of this EU FUD people are spreading actually ever became reality.

    Until then, I suggest people put the EU FUD tin-foil hat to one side.

    [1] https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec... [2] https://mullvad.net/en/blog/update-the-swedish-authorities-a...

    • I have always wondered, what will companies do, if the law changes. Will they still "care" for the consumer, or just "comply" with the law.

      [1] - lobbying by leather industry to exempt them from EU Deforestation Regulation - https://news.mongabay.com/2026/09/now-exempt-from-eu-defores...

      [2] - lobbying to remove due diligence on human rights violation in supply chain in certain industry sectors - https://www.business-humanrights.org/en/latest-news/eu-csddd...

      > They have a long history of listening and acting on what industry experts tell them

      Yes, most famously the diesel gate, european automakers cheating emission tests, [3] because EU invited companies to self regulate their lab tests.

      [3] - https://corporateeurope.org/sites/default/files/driving_into...

      World used to believe companies used to care for them, before snowden showed up. Even now people are still surprised, when companies like LG get caught doing illegal stuff. How long before there is a scandal in EU? Fool me once...

      As much as i like to believe EU "cares" about the consumer, its really stupid for someone to blindly put their faith in Mullvad. Zero trust. When you are online, you are on your own.

Yeah, it's basically not possible to offer an actually secure and private service in the US. If men with guns and gag orders haven't shown up at their new york office yet, they will as soon as this VPN gets popular enough to show up on their radar. At that point if they have any integrity they'll shut their service down like Lababit did rather than allow it to be compromised by the state.