Obscura: A VPN that can't track your activity
obscuravpn.io
obscuravpn.io
They may not be able to track your stuff as it is today, but one single FISA order demanding they push a update out to just to a few specific IP addresses and it will be all the same.
All things you download and install to your device can screw you if they have any functional way to update or have any serverside includes. (like a analytics JS tracker that can be changed to a JS logger)
We run into this a bit with https://redact.dev , but for people who want to be sure the login information they provide is safe. At the end of the day, you are always at the mercy of the courts AND the founders not doing evil things.
Heres a quick meme to better explain: https://i.imgur.com/Vnerxcb.png
True. This is why all client side source code will be released and reproducible builds offered on platforms that support it.
If you don't know what code you're running, yeah you're screwed either way.
Look- the point is, you will go down a endless rabbithole of trying to appease everyone with "bulletproof" security. And the more you go, the more functionality and usefulness you will give up.
The best solution is to be realistic and not make defacto claims. Even things like TOR, which have been open source and audited from day one have had serious issues, and I am sure many TOR developers parroted the "you cant be tracked using us" only to have exploits and code issues pop up multiple times.
Nixpkgs please! It's the most successful reproducibility experiment I know of.
Fun fact: all of the current website's infra is NixOS-based
Fun fact #2: I overhauled Bitcoin Core's reproducible build system to use Guix (a Nix-inspired functional package manager)
All the nix deployment tools had too much magic and broke, but nixos-rebuild always works and it's part of Nix!
Disko was great for bootstrapping servers: https://github.com/nix-community/disko
[0]https://transparencyreport.google.com/user-data/us-national-...
The only claim they made is about the vpn service itself. If FISA orders it, the NSA will break into your house and plant cameras to watch your monitor lol. That's a strawman argument. You shouldn't argue against an claim they didn't make about update security, but even then can't you just use your own wireguard client? You don't have to use theirs right?
There's Google One VPN (which uses blind signatures for access tokens) as well as iCloud Private Relay (which leverages nested encrypted channels terminated by a different entity than the one that receives user-side traffic, as well as blind signatures for authentication if I remember correctly).
That said, it's definitely nice to have alternatives, but as with all VPN services, I'd be cautious – the proposition of "perfectly anonymous network access" attracts a lot of attention, not all of it beneficial to the product/project.
That's an understatement. The earliest example that comes to mind is from over a quarter of a century ago: https://en.wikipedia.org/wiki/Zero_Knowledge_Systems ZKS even predated Tor as one of the (if not the) first Onion Routing/Pipenet implementations outside the Navy's program. At the time, ZKS earned a lot of mindshare in the tech industry, but unfortunately they were a tad early to the commercial VPN party.
There's also another company/product that has Port in the name I think, PortMonitor or... it's on the tip of my tongue. Anyway they have a paid version of the product that is essentially a series of servers (their own and user-donated servers) that tries to re-create the onion routing protocol, but with VPNs and blind tokens.
Edit: Postmaster with the Safing Privacy Network (SPN) https://safing.io/spn/
It's sad. I really wish they'd improve speed, latency, and packet loss. If they did then I would go back in a heartbeat.
Yeah: https://datatracker.ietf.org/doc/draft-ietf-privacypass-rate...
> My understanding is it's CONNECT-IP / MASQUE where the encrypted & HTTP encapsulated IP request is sent to Obscura and the details of the request are forwarded to what they're calling a "Blind Relay" which only knows Obsucra's IP. 2-hop onion routing with pre-defined routes. No Tor consensus. Very simple. https://datatracker.ietf.org/doc/draft-ietf-masque-connect-i...
- bitgould from https://stacker.news/items/268728/r/031ef7d322
Impossible to say without seeing the source code though.
I like that they plan to open source the client and do not mention any plans to open source their server software. Being able to audit more of their claims runs the risk of spoiling the mystique — you can’t run a VPN without a little bit of a sexy pinky promise.
I'm the maker of Obscura.
Happy to answer questions folks have. Also, what thinkmassive dug up is accurate: https://news.ycombinator.com/item?id=37711006
Update: Just fixed the Matrix->Discord bridge, apologies if it didn't work for you before.
>We have immense respect for the Tor project (please donate to the foundation if you can), but its slow speed and frequent network-wide DDoS attacks make it infeasible for everyday use.
>Obscura has most of the benefits of connecting via Tor but is optimized for everyday use by being much faster and more reliable.
Curious about the details on this.
Whilst the DDoS was ongoing, Tor was quite slow.
The infosec hobbyist in me believes the many-months-long massive DDoS attack against tor infrastructure was exploiting a vulnerability in tor to perform (timing attacks, or related traffic correlation attacks) against and unmask hidden services or hidden service users, or maybe even exit node users. How realistic is this to someone that understands the tor network more in-depth than I do?
Because it's so noisy and expensive, I can't believe they'd keep it up this long if it wasn't extremely effective, whatever the purpose and actor.
I'm not sure we would know about the Carnegie Melon research if it weren't for the researchers trying to give a talk about at Black Hat 2014. https://threatpost.com/tor-sniffs-out-attacks-trying-to-dean...
Or 2015 at MIT - https://www.bitdefender.com/blog/hotforsecurity/de-anonymiza...
Or 2019-2021+ - https://nusenu.medium.com/is-kax17-performing-de-anonymizati...
Or 2022 - https://infocondb.org/con/def-con/def-con-30/deanonymization...
Bitcoin is not anonymous. This makes me doubt of all their privacy claims
they’ve been slowing progress down for 10 years straight now
but don’t worry you’ve been able to pay bitcoin invoices with monero and everything else for nearly as long too, just use a mixer and set the destination asset and address to the one on the invoice
Monero’s cross contribution has been good, wasnt talking about them. Not sure off the top of my head anymore.
I was curious why XMR isn't available.
They also ban most sat phones by the way.
Owning cryptocurrency is not illegal in India. There is no ban on any cryptocurrencies in India. There is a hefty tax deduction at source on any transactions. Cryptocurrencies are not recognized as legal tender in India, which is the case in many other countries.
If not, what's your point?
As others have mentioned, swapping between chains is also an option.
I couldn't find any info on the page about who provides the relays, but that seems like the hardest problem to solve. The relays are taking on all the risk, after all - if someone does something illegal the exit relay will be where the authorities go first.
Of course, with my way and Obscura, you should use a leak-proof setup that doesn't rely on you OS/device being nice (looking at MS and Apple there).
Good thing about that too is it avoids leaks, as long as you set your adapters right.
If implemented correctly (and that's a big if!), a nested tunnel approach can make that much harder and require global passive or active traffic observation capabilities (for timing observation, possibly with active timing modifications, of specific flows), or collusion of at least two different entities.
It's probably worth mentioning that such a setup does not provide you with the same level of privacy as Tor, especially if all hops are within Five Eyes countries.
Bitcoin can also be anonymized via coinjoin like samurai or Wasabi, although Wasabi is not recommended: https://medium.com/oxt-research/a-statement-on-two-discovere...
In fact, if you're truly trying to be as as anonymous as possible with privacy redundancy, coinjoining before converting to XMR is your best course of action.