Obscura: VPN that can't log your activity

obscura.com

132 points by Flimm 13 hours ago


barathr - 12 hours ago

As others have pointed out, this is like Apple iCloud Private Relay, and other multi-hop privacy systems that have been built on and off over the last several decades (Tor included).

We wrote a research paper on the general principle a few years ago: https://conferences.sigcomm.org/hotnets/2022/papers/hotnets2...

maxloh - 13 hours ago

I don't understand the point of this.

Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.

Why should I choose this over Mullvad?

skaul - 13 hours ago

So two hops, basically. First hop sees your IP address but not the website you're going to, second hop sees website but not IP address. Similar to Private Relay: https://support.apple.com/en-us/102602.

john_strinlai - 13 hours ago

i am very skeptical of most vpn companies, and while i haven't looked too hard at obscura, it is worth noting the official partnership with mullvad (https://mullvad.net/en/blog/mullvad-partnered-with-obscura-v...) which is certainly a positive signal

side note: i really wish more companies did the no email + randomized account number flow. there is a certain popular "pro-privacy" product beloved by many here that requires an email address and refuses to offer a similar account number method, which has turned me off the product.

RandomGerm4n - 2 hours ago

It would be cool if there were a way to use it the other way around. A Mullvad server as the entry point and an Obscura server as the exit point. My main problem with Mullvad right now is that its servers are blocked almost everywhere or generate an excessive number of Captchas. With other VPNs, that’s been much less of an issue so far. Alternatively, a residential proxy might be a good option as an optional exit point. One way to achieve this, for example, would be through a partnership with a regular ISP from which you could then borrow IP addresses.

- an hour ago
[deleted]
tbtech_vn - an hour ago

That's really cool, but perhaps a bit overkill for the typical no-log quick access variant, so shameless plug here even if it primarily is for autonomous agents.

https://x402socks.com

wahern - 12 hours ago

> the first VPN that can’t log your activity and outsmarts internet censorship.

I guess they never heard of Zero Knowledge Systems: https://en.wikipedia.org/wiki/Zero_Knowledge_Systems

osnxkwmxkwnd - 13 hours ago

This sounds pretty neat, and I do dig the website, though I can’t help but think it’s an odd combination to have bitmap/pixelated fonts and graphics inside perfect squircles.

Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled with care. Right now it feels like the designer had a bunch of ideas and didn’t know how to bring them together in a cohesive identity.

Bonus point for the TRON reference at the end! “I fight for the users!”

est - 7 hours ago

I hope MPTCP would be more popular

Many src-dst connections but as a single logical connection. There's no way any middlebox could easy capture full data even metadata.

http2/QUIC can do something similar with frames (and hopefully multipath)

Don't place your whole stream inside a single src-dst IP connection. Demux them into many paths over the Internet. We need more variety of "traffic shapes" to combat Internet surveillance.

I'd argue it's even more effective than encryption. Split your activity and mix them, monitor traffic over a single transport is useless.

hehdtyjjoj - 13 hours ago

How does this prove Obscura and Mullvad can't just both gather tracking data and then just combine it on demand?

dongcarl - 12 hours ago

Carl from Obscura here

Happy to answer any questions y’all might have!

Also, the technical folks may be more interested in our original post: https://obscura.com/blog/bootstrapping-trust/

fh67 - 11 hours ago

https://obscura.com/check/ does this page know the difference between a direct mullvad user and an obscura user, if so, how?

Packet padding but no docs about this?

Wowfunhappy - 6 hours ago

> Exit servers (run by Mullvad) connect you to the internet but never see your personal info. Obscura masks your real IP address when relaying to the exit server.

How is this possible? If the exit server doesn't know your IP, how does it know where to send the traffic?

hp197 - 12 hours ago

https://news.ycombinator.com/item?id=48696800

This is where part of your money flows to (I have opinions about this).

Not sure if you are also aware of it.

ramblurr - 13 hours ago

So like OHTTP but for UDP traffic? I suppose they are using MASQUE CONNECT-UDP?

They are careful to not exactly claim the same anonymity properties of Tor, though I think a lay reader will read that differently (ie, that they do have the same anonymity property as Tor).

That said being able to verify the inner wireguard conn to mullvad is nice. Of course you have to trust them that they aren't colluding with mullvad to share your identity/ip. But same goes for OHTTP.

skyzoidbroczky - 6 hours ago

Any vpn company who market itself as aiming for the anonymity of its user is essentially selling snake oil to its customers. The fact that this company pretends to be more respective of the privacy of its user because it is in America is a vast joke, companies in America are expect to collaborate with the security services, even monopolies don't escape from it.

ChocolateGod - 13 hours ago

Your traffic is still unencrypted by the VPN provider at the other end of the Wireguard connection, I am not sure how this changes that?

saligne - 5 hours ago

i'd like to see some more info about the quic as obfuscation claim. imo this isn't really useful for people living in countries with restrictive firewalls. quic is blocked or throttled quite easily.

MassPikeMike - 5 hours ago

I hate to be the one to throw stones at an outfit that is trying to do something good, protecting people's privacy.

But the claim in Obscura's FAQ that paying with Bitcoin or Monero offers more privacy than paying with a credit card is sadly misguided. No-KYC cryptocurrency is largely a thing of the past, and outfits like Chainanalysis can associate a Lightning or Monero address to a human with near-perfect accuracy. The fact that Obscura's FAQ doesn't acknowledge this makes me feel like its author was either pretending this is not the case, or is unaware of it. Either of those is pretty bad.

Mullvad lets customers sign up for an account and pay in cash, which is a good, privacy-preserving choice. In the US, payment by postal money order or by gift card, either of which can be purchased with cash, would also be good choices. Users, and Obscura, should not be fooled by some vague association of cryptocurrency and privacy. In the age of ubiquitous KYC that ship has sailed with the possible exception of ZCash. And I wouldn't bet my life on ZCash, either.

floro - 11 hours ago

Vp.net did it first: https://vp.net/l/en-US/technical#cryptography

abbracadabbra - 10 hours ago

Great signup flow, except there’s an error when it comes to installing the app at the end. Worked around by installing manually via app store

dorongrinstein - 13 hours ago

I love the website, messaging and idea. Well done. if you guys need a place to host, please consider controlplane.com

VCFundedGenYer - 11 hours ago

Many VPNs don't log activity. Headline is objectively false.

iAMkenough - 13 hours ago

Basically a middle-man for a Mullvad VPN, where if Mullvad decides to pull out of their agreement with this company, you lose your connection and are hopefully refunded.

The single point of failure for this product is Mullvad and its leadership's changing opinions.

- 6 hours ago
[deleted]
nalekberov - 13 hours ago

I don't like 'us vs others' kinda comparisons, it's just marketing trick, which means they care more about sales than your privacy.

Secondly, Mullvad did what Obscura does now years ago.

Furthermore who needs a gamified VPN tool?

chews - 12 hours ago

a vpn company is a paid for MITM attack surface.

mkrdnk - 13 hours ago

> first

Really? XD

Transformanshen - 8 hours ago

[dead]

EtienneDeLyon - 8 hours ago

[dead]

boguscoder - 12 hours ago

It’s often ‘impossible’ and until it happens /s