Comment by mulmen

4 days ago

But if both services keep logs de-anonymization is a join.

(Carl from Obscura here)

Very true, but if even 1 of (Obscura, Mullvad) is honest, there's no de-anonymization.

For traditional Single-Party VPNs, you just need to compromise 1 party, with Two-Party Relays, you need to compromise both.

  • > Very true, but if even 1 of (Obscura, Mullvad) is honest

    Just Obscura's compromise is enough, as pointed out previously: https://news.ycombinator.com/item?id=43016574

    Unless something has changed in Obscura's architecture, the interface with Mullvad is under Obscura's control, and thus it can compromise client's credentials. This is unlike iCloud Private Relay where the guarantees are cryptographic in nature and not merely based on promises.

They don't even need to. If you observe enough of them you can correlate traffic patterns between them and find out which one is used by which endpoint