← Back to context

Comment by maxloh

4 days ago

The "Obscura and Mullvad" argument actually makes sense. Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.

Another question: How does the Obscura client get the Mullvad exit server’s public key? Are they hardcoded at compile time, fetched from Mullvad's server, or fetched from Obscura's server?

The latter seems to be dangerous if there isn't some kind of signature verification done on the client side before using the key.

Good question! It's the latter right now (which is not ideal), but I think Mullvad is going to sign their server pubkeys pretty soon and we'll switch to that.

We do currently show it in the app and there's an easily clickable link so you can verify against Mullvad's website for the pubkey

> Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.

Its just very, very, very unfortunate that they chose the US for Obscura.

Of all the jurisdictions in the world you chose the one that has become exponentially untrustworthy in the eyes of non-US users ....