Obscura: The first VPN that can't log your activity

(obscura.com)

46 points | by Flimm 1 hour ago

17 comments

  • maxloh 1 hour ago
    I don't understand the point of this.

    Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.

    Why should I choose this over Mullvad?

  • john_strinlai 1 hour ago
    i am very skeptical of most vpn companies, and while i haven't looked too hard at obscura, it is worth noting the official partnership with mullvad (https://mullvad.net/en/blog/mullvad-partnered-with-obscura-v...) which is certainly a positive signal

    side note: i really wish more companies did the no email + randomized account number flow. there is a certain popular "pro-privacy" product beloved by many here that requires an email address and refuses to offer a similar account number method, which has turned me off the product.

    • dongcarl 18 minutes ago
      (Carl from Obscura here)

      Yeah we thought the randomized account number flow was an ingenious idea, so we did that and made the last digit a Verhoeff checksum to check for mistypes!

      Though sometimes people forget to write the number down and... There's not much we can do.

    • mulmen 57 minutes ago
      > there is a certain popular "pro-privacy" product beloved by many here

      Please don’t speak in riddles. Just say what you mean.

      • john_strinlai 45 minutes ago
        for what purpose? there is nothing to be gained from pointing fingers, and takes the discussion in an even more unrelated direction.

        although i guess people's curiosity is also dragging my comment in an unrelated direction anyways. lose-lose situation.

        my main point is that the account number method is really nice, and a great selling point for such privacy-conscious products. not offering it in a privacy-conscious product is enough signal that it has made me choose not to purchase the product. that's the important bit, and where i was hoping to drive the conversation.

        • bityard 28 minutes ago
          There is even less to be gained by issuing vague unactionable warnings and/or accusations...
          • john_strinlai 26 minutes ago
            it's not a warning or accusation...

            this isn't some hidden feature you get caught with your pants down over. if you try to sign up to something and it doesn't offer an account number, you know that it doesn't offer an account number instantly.

            no time wasted for you. it's not some nefarious plot by the company.

            it's just a business decision. i was hoping to talk about the business decision of that particular sign up flow.

        • PunchyHamster 37 minutes ago
          Incorrect. Pointing out bad products is a warning to other people to not waste time on it. We should be doing it more, not less.

          I also have no idea what company/service you're talking about

        • mulmen 40 minutes ago
          Because it creates confusion as proven by the responses mistakenly assuming that you were referring to proton.
          • john_strinlai 29 minutes ago
            and if i mention the company, the responses are all about the company instead of the feature.

            next time i will just keep my thoughts to myself and we'll all be happy.

      • t-writescode 30 minutes ago
        They’re almost certainly referencing Signal.
    • baal80spam 51 minutes ago
      privacy <> anonymity

      Proton VPN ensures privacy.

      • water-drummer 47 minutes ago
        Privacy without anonymity is just privacy with a backdoor waiting to be unlocked.
      • john_strinlai 49 minutes ago
        i am not talking about proton.
    • ignoramous 56 minutes ago
      > ... a certain popular "pro-privacy" product beloved by many here ...

      If you're talking about Proton VPN, they do support "credential-less accounts" through their official apps, I believe? At least, on Android since 2024: https://www.androidpolice.com/proton-vpn-works-without-accou...

      • john_strinlai 49 minutes ago
        i am hesitant to really narrow it down, but it is not proton (i am a very early proton customer)
        • mulmen 48 minutes ago
          Then why comment at all? This is the danger of speaking in riddles.
  • barathr 46 minutes ago
    As others have pointed out, this is like Apple iCloud Private Relay, and other multi-hop privacy systems that have been built on and off over the last several decades (Tor included).

    We wrote a research paper on the general principle a few years ago: https://conferences.sigcomm.org/hotnets/2022/papers/hotnets2...

    • dongcarl 39 minutes ago
      Good to see you here Barath :-)

      I didn't realize Chris Wood was also an author!

  • skaul 1 hour ago
    So two hops, basically. First hop sees your IP address but not the website you're going to, second hop sees website but not IP address. Similar to Private Relay: https://support.apple.com/en-us/102602.
    • dongcarl 41 minutes ago
      (Carl from Obscura here)

      Yup, exactly!

    • mulmen 52 minutes ago
      But if both services keep logs de-anonymization is a join.
      • PunchyHamster 35 minutes ago
        They don't even need to. If you observe enough of them you can correlate traffic patterns between them and find out which one is used by which endpoint
  • wahern 33 minutes ago
    > the first VPN that can’t log your activity and outsmarts internet censorship.

    I guess they never heard of Zero Knowledge Systems: https://en.wikipedia.org/wiki/Zero_Knowledge_Systems

  • dongcarl 21 minutes ago
    Carl from Obscura here

    Happy to answer any questions y’all might have!

    Also, the technical folks may be more interested in our original post: https://obscura.com/blog/bootstrapping-trust/

    • walrus01 12 minutes ago
      Hi Carl, thanks for being here to answer questions. Two questions: Do you have any active testers in Iran right now, and secondly, how is this architected to deal with advanced DPI boxes in ISP networks that detect flows of encrypted traffic and drop it? The methods I'm seeing people use with success from within Iran right now are very different than something like a commercial mullvad or competitor VPN.

      Some of them rely on people having a helpful third party in ("free") country to set up a private relay in something like Azure IP space that isn't used by any other VPN users, so it doesn't attract a level of attention (or attention by multiples of different peoples' encrypted flows) that publicly published commercial VPN services do. It's a hard problem to solve on a scale of more than a couple of people.

      The multi party relay concept is great, my concerns are more with traffic detection/DPI in between the end user and the first hop in the relay.

  • hp197 25 minutes ago
    https://news.ycombinator.com/item?id=48696800

    This is where part of your money flows to (I have opinions about this).

    Not sure if you are also aware of it.

  • hehdtyjjoj 1 hour ago
    How does this prove Obscura and Mullvad can't just both gather tracking data and then just combine it on demand?
    • dongcarl 4 minutes ago
      (Carl from Obscura here)

      This doesn't prove it. However, Obscura makes it so that there's no *single party* that if hacked or otherwise compromised would hurt your internet privacy.

    • woah 1 hour ago
      and how is it better than just connecting to mullvad over nordvpn or something?
      • dongcarl 2 minutes ago
        (Carl from Obscura here)

        Other than the obvious hassle? XP

        If you connect to Mullvad over NordVPN:

        - You're giving both Mullvad and Nord some payment information (with Obscura you only give that to us, Mullvad has no idea)

        - You don't get our QUIC-based obfuscation (see more here: https://obscura.com/blog/bootstrapping-trust/)

      • iAMkenough 49 minutes ago
        If you're already a Tailscale user, seems like this solution is nearly identical to using Mullvad as an exit node.

        You would go with this solution if you don't trust Tailscale or NordVPN, I guess.

        • dongcarl 1 minute ago
          (Carl from Obscura here)

          I could be wrong but in Tailscale if you use Mullvad as an exit node, the traffic flows directly from your device to Mullvad's servers.

          Whereas with Obscura, your traffic flows to the Obscura relay, then the Mullvad exit.

  • osnxkwmxkwnd 1 hour ago
    This sounds pretty neat, and I do dig the website, though I can’t help but think it’s an odd combination to have bitmap/pixelated fonts and graphics inside perfect squircles.

    Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled with care. Right now it feels like the designer had a bunch of ideas and didn’t know how to bring them together in a cohesive identity.

    Bonus point for the TRON reference at the end! “I fight for the users!”

    • dongcarl 12 minutes ago
      (Carl from Obscura here)

      I'm a sucker for retro 8-bit graphics and fun mascots, so we went with that, but when we experimented with 8-bit for actual UI and long text we immediately found it to be super unusable and unreadable :-(

      > Bonus point for the TRON reference at the end! “I fight for the users!”

      Ah ofc the HN poster knows the reference :-) I've had it as my email signature since high school I think.

  • ChocolateGod 1 hour ago
    Your traffic is still unencrypted by the VPN provider at the other end of the Wireguard connection, I am not sure how this changes that?
  • ramblurr 1 hour ago
    So like OHTTP but for UDP traffic? I suppose they are using MASQUE CONNECT-UDP?

    They are careful to not exactly claim the same anonymity properties of Tor, though I think a lay reader will read that differently (ie, that they do have the same anonymity property as Tor).

    That said being able to verify the inner wireguard conn to mullvad is nice. Of course you have to trust them that they aren't colluding with mullvad to share your identity/ip. But same goes for OHTTP.

  • dorongrinstein 1 hour ago
    I love the website, messaging and idea. Well done. if you guys need a place to host, please consider controlplane.com
  • iAMkenough 1 hour ago
    Basically a middle-man for a Mullvad VPN, where if Mullvad decides to pull out of their agreement with this company, you lose your connection and are hopefully refunded.

    The single point of failure for this product is Mullvad and its leadership's changing opinions.

    • dgellow 1 hour ago
      Obscura itself is also a point of failure
  • nalekberov 1 hour ago
    I don't like 'us vs others' kinda comparisons, it's just marketing trick, which means they care more about sales than your privacy.

    Secondly, Mullvad did what Obscura does now years ago.

    Furthermore who needs a gamified VPN tool?

  • chews 35 minutes ago
    a vpn company is a paid for MITM attack surface.
  • mkrdnk 1 hour ago
    > first

    Really? XD

  • boguscoder 30 minutes ago
    It’s often ‘impossible’ and until it happens /s