‹ BackHN Continuity

Thread

Obscura: VPN that can't log your activity

233 points · 140 comments · Flimm

  1. skaul · · focus · HN ↗
    So two hops, basically. First hop sees your IP address but not the website you&#x27;re going to, second hop sees website but not IP address. Similar to Private Relay: <a href="https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;102602" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;102602.
    1. mulmen · · focus · HN ↗
      But if both services keep logs de-anonymization is a join.
      1. PunchyHamster · · focus · HN ↗
        They don&#x27;t even need to. If you observe enough of them you can correlate traffic patterns between them and find out which one is used by which endpoint
      2. dongcarl · · focus · HN ↗
        (Carl from Obscura here)

        Very true, but if even 1 of (Obscura, Mullvad) is honest, there&#x27;s no de-anonymization.

        For traditional Single-Party VPNs, you just need to compromise 1 party, with Two-Party Relays, you need to compromise both.

        1. [deleted] · · focus · HN ↗

          [deleted]

        2. ignoramous · · focus · HN ↗
          &gt; Very true, but if even 1 of (Obscura, Mullvad) is honest

          Just Obscura&#x27;s compromise is enough, as pointed out previously: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=43016574">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=43016574

          Unless something has changed in Obscura&#x27;s architecture, the interface with Mullvad is under Obscura&#x27;s control, and thus it can compromise client&#x27;s credentials. This is unlike iCloud Private Relay where the guarantees are cryptographic in nature and not merely based on promises.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.