‹ BackHN Continuity

Thread

Obscura: VPN that can't log your activity

233 points · 140 comments · Flimm

  1. maxloh · · focus · HN ↗
    I don't understand the point of this.

    Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.

    Why should I choose this over Mullvad?

    1. maxloh · · focus · HN ↗
      Mullvad is a Swedish company, which has stricter privacy protection laws in place.

      According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.

      The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?

      [0]: &quot;(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016...&quot; <a href="https:&#x2F;&#x2F;obscura.com&#x2F;legal&#x2F;" rel="nofollow">https:&#x2F;&#x2F;obscura.com&#x2F;legal&#x2F;

      1. dongcarl · · focus · HN ↗
        (Carl from Obscura here)

        I love folks who are also reasoning through security models! A few things to note here:

        - We believe that all software running on a user&#x27;s computer should be open source, so you can audit and build your own client: <a href="https:&#x2F;&#x2F;github.com&#x2F;Sovereign-Engineering&#x2F;obscuravpn-client" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Sovereign-Engineering&#x2F;obscuravpn-client

        - With traditional Single-Party VPNs, even if you trust them fully and they&#x27;re honest, they can still be compromised or hacked. With Obscura, even if we&#x27;re hacked there&#x27;s nothing to leak (other than WireGuard packets fully encrypted to Mullvad&#x27;s servers).

        - The change in trust is that instead of trusting a single company (Mullvad), you&#x27;re trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.

        1. maxloh · · focus · HN ↗
          The &quot;Obscura and Mullvad&quot; argument actually makes sense. Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.

          Another question: How does the Obscura client get the Mullvad exit server’s public key? Are they hardcoded at compile time, fetched from Mullvad&#x27;s server, or fetched from Obscura&#x27;s server?

          The latter seems to be dangerous if there isn&#x27;t some kind of signature verification done on the client side before using the key.

          1. dongcarl · · focus · HN ↗
            Good question! It&#x27;s the latter right now (which is not ideal), but I think Mullvad is going to sign their server pubkeys pretty soon and we&#x27;ll switch to that.

            We do currently show it in the app and there&#x27;s an easily clickable link so you can verify against Mullvad&#x27;s website for the pubkey

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.