‹ BackHN Continuity

Thread

Obscura: VPN that can't log your activity

233 points · 140 comments · Flimm

  1. maxloh · · focus · HN ↗
    I don't understand the point of this.

    Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.

    Why should I choose this over Mullvad?

    1. maxloh · · focus · HN ↗
      Mullvad is a Swedish company, which has stricter privacy protection laws in place.

      According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.

      The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?

      [0]: &quot;(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016...&quot; <a href="https:&#x2F;&#x2F;obscura.com&#x2F;legal&#x2F;" rel="nofollow">https:&#x2F;&#x2F;obscura.com&#x2F;legal&#x2F;

      1. dongcarl · · focus · HN ↗
        (Carl from Obscura here)

        I love folks who are also reasoning through security models! A few things to note here:

        - We believe that all software running on a user&#x27;s computer should be open source, so you can audit and build your own client: <a href="https:&#x2F;&#x2F;github.com&#x2F;Sovereign-Engineering&#x2F;obscuravpn-client" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Sovereign-Engineering&#x2F;obscuravpn-client

        - With traditional Single-Party VPNs, even if you trust them fully and they&#x27;re honest, they can still be compromised or hacked. With Obscura, even if we&#x27;re hacked there&#x27;s nothing to leak (other than WireGuard packets fully encrypted to Mullvad&#x27;s servers).

        - The change in trust is that instead of trusting a single company (Mullvad), you&#x27;re trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.

        1. maxloh · · focus · HN ↗
          The &quot;Obscura and Mullvad&quot; argument actually makes sense. Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.

          Another question: How does the Obscura client get the Mullvad exit server’s public key? Are they hardcoded at compile time, fetched from Mullvad&#x27;s server, or fetched from Obscura&#x27;s server?

          The latter seems to be dangerous if there isn&#x27;t some kind of signature verification done on the client side before using the key.

          1. traceroute66 · · focus · HN ↗
            &gt; Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.

            Its just very, very, very unfortunate that they chose the US for Obscura.

            Of all the jurisdictions in the world you chose the one that has become exponentially untrustworthy in the eyes of non-US users ....

            1. voakbasda · · focus · HN ↗
              … as well as in the eyes of many of its own citizens.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.