This sounds pretty neat, and I do dig the website, though I can’t help but think it’s an odd combination to have bitmap/pixelated fonts and graphics inside perfect squircles.
Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled with care. Right now it feels like the designer had a bunch of ideas and didn’t know how to bring them together in a cohesive identity.
Bonus point for the TRON reference at the end! “I fight for the users!”
I'm a sucker for retro 8-bit graphics and fun mascots, so we went with that, but when we experimented with 8-bit for actual UI and long text we immediately found it to be super unusable and unreadable :-(
> Bonus point for the TRON reference at the end! “I fight for the users!”
Ah ofc the HN poster knows the reference :-) I've had it as my email signature since high school I think.
side note: i really wish more companies did the no email + randomized account number flow. there is a certain popular "pro-privacy" product beloved by many here that requires an email address and refuses to offer a similar account number method, which has turned me off the product.
for what purpose? there is nothing to be gained from pointing fingers, and takes the discussion in an even more unrelated direction.
although i guess people's curiosity is also dragging my comment in an unrelated direction anyways. lose-lose situation.
my main point is that the account number method is really nice, and a great selling point for such privacy-conscious products. not offering it in a privacy-conscious product is enough signal that it has made me choose not to purchase the product. that's the important bit, and where i was hoping to drive the conversation.
this isn't some hidden feature you get caught with your pants down over. if you try to sign up to something and it doesn't offer an account number, you know that it doesn't offer an account number instantly.
no time wasted for you. it's not some nefarious plot by the company.
it's just a business decision. i was hoping to talk about the business decision of that particular sign up flow.
Yeah we thought the randomized account number flow was an ingenious idea, so we did that and made the last digit a Verhoeff checksum to check for mistypes!
Though sometimes people forget to write the number down and... There's not much we can do.
Basically a middle-man for a Mullvad VPN, where if Mullvad decides to pull out of their agreement with this company, you lose your connection and are hopefully refunded.
The single point of failure for this product is Mullvad and its leadership's changing opinions.
Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.
Mullvad is a Swedish company, which has stricter privacy protection laws in place.
According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.
The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?
[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/
- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).
- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.
Yeah, it's basically not possible to offer an actually secure and private service in the US. If men with guns and gag orders haven't shown up at their new york office yet, they will as soon as this VPN gets popular enough to show up on their radar. At that point if they have any integrity they'll shut their service down like Lababit did rather than allow it to be compromised by the state.
Same country at least - the iCloud Private Relay options, iOS:
“1: Maintain general location
2: Use country and time zone
Maintain your general location to receive localized content, or enhance your privacy by using a broader IP address based on your country and time zone.
Safari Private Browsing always uses an IP location from your country and time zone.”
This doesn't prove it. However, Obscura makes it so that there's no *single party* that if hacked or otherwise compromised would hurt your internet privacy.
So like OHTTP but for UDP traffic? I suppose they are using MASQUE CONNECT-UDP?
They are careful to not exactly claim the same anonymity properties of Tor, though I think a lay reader will read that differently (ie, that they do have the same anonymity property as Tor).
That said being able to verify the inner wireguard conn to mullvad is nice. Of course you have to trust them that they aren't colluding with mullvad to share your identity/ip. But same goes for OHTTP.
So two hops, basically. First hop sees your IP address but not the website you're going to, second hop sees website but not IP address. Similar to Private Relay: https://support.apple.com/en-us/102602.
They don't even need to. If you observe enough of them you can correlate traffic patterns between them and find out which one is used by which endpoint
As others have pointed out, this is like Apple iCloud Private Relay, and other multi-hop privacy systems that have been built on and off over the last several decades (Tor included).
Hi Carl, thanks for being here to answer questions. Two questions: Do you have any active testers in Iran right now, and secondly, how is this architected to deal with advanced DPI boxes in ISP networks that detect flows of encrypted traffic and drop it? The methods I'm seeing people use with success from within Iran right now are very different than something like a commercial mullvad or competitor VPN.
Some of them rely on people having a helpful third party in ("free") country to set up a private relay in something like Azure IP space that isn't used by any other VPN users, so it doesn't attract a level of attention (or attention by multiples of different peoples' encrypted flows) that publicly published commercial VPN services do. It's a hard problem to solve on a scale of more than a couple of people.
The multi party relay concept is great, my concerns are more with traffic detection/DPI in between the end user and the first hop in the relay.
osnxkwmxkwnd | 2 hours ago
Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled with care. Right now it feels like the designer had a bunch of ideas and didn’t know how to bring them together in a cohesive identity.
Bonus point for the TRON reference at the end! “I fight for the users!”
dongcarl | 54 minutes ago
I'm a sucker for retro 8-bit graphics and fun mascots, so we went with that, but when we experimented with 8-bit for actual UI and long text we immediately found it to be super unusable and unreadable :-(
> Bonus point for the TRON reference at the end! “I fight for the users!”
Ah ofc the HN poster knows the reference :-) I've had it as my email signature since high school I think.
john_strinlai | 2 hours ago
side note: i really wish more companies did the no email + randomized account number flow. there is a certain popular "pro-privacy" product beloved by many here that requires an email address and refuses to offer a similar account number method, which has turned me off the product.
mulmen | an hour ago
Please don’t speak in riddles. Just say what you mean.
john_strinlai | an hour ago
although i guess people's curiosity is also dragging my comment in an unrelated direction anyways. lose-lose situation.
my main point is that the account number method is really nice, and a great selling point for such privacy-conscious products. not offering it in a privacy-conscious product is enough signal that it has made me choose not to purchase the product. that's the important bit, and where i was hoping to drive the conversation.
mulmen | an hour ago
john_strinlai | an hour ago
next time i will just keep my thoughts to myself and we'll all be happy.
PunchyHamster | an hour ago
I also have no idea what company/service you're talking about
bityard | an hour ago
john_strinlai | an hour ago
this isn't some hidden feature you get caught with your pants down over. if you try to sign up to something and it doesn't offer an account number, you know that it doesn't offer an account number instantly.
no time wasted for you. it's not some nefarious plot by the company.
it's just a business decision. i was hoping to talk about the business decision of that particular sign up flow.
t-writescode | an hour ago
ignoramous | an hour ago
If you're talking about Proton VPN, they do support "credential-less accounts" through their official apps, I believe? At least, on Android since 2024: https://www.androidpolice.com/proton-vpn-works-without-accou...
john_strinlai | an hour ago
mulmen | an hour ago
baal80spam | an hour ago
Proton VPN ensures privacy.
john_strinlai | an hour ago
water-drummer | an hour ago
dongcarl | 59 minutes ago
Yeah we thought the randomized account number flow was an ingenious idea, so we did that and made the last digit a Verhoeff checksum to check for mistypes!
Though sometimes people forget to write the number down and... There's not much we can do.
iAMkenough | an hour ago
The single point of failure for this product is Mullvad and its leadership's changing opinions.
dgellow | an hour ago
maxloh | an hour ago
Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.
Why should I choose this over Mullvad?
maxloh | an hour ago
According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.
The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?
[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/
ignoramous | an hour ago
miohtama | an hour ago
https://codamail.com/articles/privacy-law-directory/internat...
"EU surveillance co-operation"
dongcarl | 27 minutes ago
I love folks who are also reasoning through security models! A few things to note here:
- We believe that all software running on a user's computer should be open source, so you can audit and build your own client: https://github.com/Sovereign-Engineering/obscuravpn-client
- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).
- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.
autoexec | 25 minutes ago
bossyTeacher | an hour ago
1.5k comments discussion for context: https://news.ycombinator.com/item?id=48717469
dongcarl | an hour ago
As for what's different: We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays): https://www.privacyguides.org/articles/2024/11/17/where-are-...
With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised. More on this here: https://obscura.com/#how
Also, all our apps are open-source as well: https://github.com/Sovereign-Engineering/obscuravpn-client
Disclaimer: I'm the creator of Obscura.
frizlab | 50 minutes ago
dongcarl | 39 minutes ago
The differences are:
- We allow you to choose an exit location (I believe iCloud Private Relay restricts you to the same location)
- Our exit hop is Mullvad instead of Cloudflare+Fastly+Akamai
- We use QUIC for transport instead of HTTP/3 (which is built on QUIC and has a bit more overhead)
Barbing | 29 minutes ago
“1: Maintain general location
2: Use country and time zone
Maintain your general location to receive localized content, or enhance your privacy by using a broader IP address based on your country and time zone.
Safari Private Browsing always uses an IP location from your country and time zone.”
dorongrinstein | an hour ago
mkrdnk | an hour ago
Really? XD
hehdtyjjoj | an hour ago
woah | an hour ago
iAMkenough | an hour ago
You would go with this solution if you don't trust Tailscale or NordVPN, I guess.
dongcarl | 42 minutes ago
I could be wrong but in Tailscale if you use Mullvad as an exit node, the traffic flows directly from your device to Mullvad's servers.
Whereas with Obscura, your traffic flows to the Obscura relay, then the Mullvad exit.
iAMkenough | 33 minutes ago
I'm under the impression that my personal device isn't the WireGuard endpoint for the Mullvad connection, Tailscale is.
dongcarl | 19 minutes ago
dongcarl | 44 minutes ago
Other than the obvious hassle? XP
If you connect to Mullvad over NordVPN:
- You're giving both Mullvad and Nord some payment information (with Obscura you only give that to us, Mullvad has no idea)
- You don't get our QUIC-based obfuscation (see more here: https://obscura.com/blog/bootstrapping-trust/)
dongcarl | 46 minutes ago
This doesn't prove it. However, Obscura makes it so that there's no *single party* that if hacked or otherwise compromised would hurt your internet privacy.
nalekberov | an hour ago
Secondly, Mullvad did what Obscura does now years ago.
Furthermore who needs a gamified VPN tool?
ramblurr | an hour ago
They are careful to not exactly claim the same anonymity properties of Tor, though I think a lay reader will read that differently (ie, that they do have the same anonymity property as Tor).
That said being able to verify the inner wireguard conn to mullvad is nice. Of course you have to trust them that they aren't colluding with mullvad to share your identity/ip. But same goes for OHTTP.
dongcarl | 53 minutes ago
Actually it's WireGuard over QUIC Unreliable Datagrams!
See: https://obscura.com/blog/bootstrapping-trust/
ChocolateGod | an hour ago
skaul | an hour ago
mulmen | an hour ago
PunchyHamster | an hour ago
dongcarl | 36 minutes ago
Very true, but if even 1 of (Obscura, Mullvad) is honest, there's no de-anonymization.
For traditional Single-Party VPNs, you just need to compromise 1 party, with Two-Party Relays, you need to compromise both.
dongcarl | an hour ago
Yup, exactly!
barathr | an hour ago
We wrote a research paper on the general principle a few years ago: https://conferences.sigcomm.org/hotnets/2022/papers/hotnets2...
dongcarl | an hour ago
I didn't realize Chris Wood was also an author!
chews | an hour ago
dongcarl | 34 minutes ago
I totally agree for traditional Single-Party VPNs, which is why we are a Two-Party Relay. More here: https://obscura.com/blog/bootstrapping-trust/
wahern | an hour ago
I guess they never heard of Zero Knowledge Systems: https://en.wikipedia.org/wiki/Zero_Knowledge_Systems
boguscoder | an hour ago
hp197 | an hour ago
This is where part of your money flows to (I have opinions about this).
Not sure if you are also aware of it.
dongcarl | an hour ago
Happy to answer any questions y’all might have!
Also, the technical folks may be more interested in our original post: https://obscura.com/blog/bootstrapping-trust/
walrus01 | 53 minutes ago
Some of them rely on people having a helpful third party in ("free") country to set up a private relay in something like Azure IP space that isn't used by any other VPN users, so it doesn't attract a level of attention (or attention by multiples of different peoples' encrypted flows) that publicly published commercial VPN services do. It's a hard problem to solve on a scale of more than a couple of people.
The multi party relay concept is great, my concerns are more with traffic detection/DPI in between the end user and the first hop in the relay.
dongcarl | 49 minutes ago
I believe QUIC has been harder to block for censors, esp with Chaos Protection on by default in Chrome. See: https://gfw.report/publications/usenixsecurity25/en/
floro | 15 minutes ago
mzajc | 11 minutes ago
fh67 | 12 minutes ago
Packet padding but no docs about this?