Obscura VPN – Privacy that's more than a promise
obscura.net
obscura.net
And with the recent Debacle of Snooper's Law apple e2ee backdoor.
Let me tell you something. A company is asked for a backdoor and they are forced to not tell anybody about it.
The only reason why it was leaked was because of whistleblower. And so , who knows if they have already signed such thing with the NSA or UK already but for their mac's and other devices
I do not believe there is such thing as privacy from such organizations. If they want you bad enough, they will get you. Don't have a reason? They'll make one.
Do you remember the "Heartbleed" exploit in SSL many years ago? There were allegations that the NSA knew about and used that exploit for many years before the public ever knew about. However, that is not exactly an easy statement to confirm nor deny.
Edit: I also wanted to add something I remember from a talk I saw with a person who once worked for the NSA. He was intentionally only talking about surface-level concepts, but he did mention that the one thing the NSA has, that most do not, is unlimited time and patience.
He said something along the lines of how they can just sit and watch a server, for example. Say that the server is on version 1.0.0 of whatever. Well, the NSA can find an exploit in version 1.1.0 and keep it under wraps. All they have to do is just wait. The second the server is upgraded to 1.1.0, then boom, they're in.
He also used the example of BYOD ("bring your own device") in workplace settings. Say they cannot can entry into somewhere. Well, if they can compromise someone's personal device, then they can just wait. The second the personal device connects to the network they want/is in close enough proximity to the network they want, then boom, they're in.
Be it one second, one hour, ... 10 years, etc.. They can wait. All it takes is one brief instance of a hole in the defense.
Truly some boogeyman level stuff, but I just hope they use their powers for good when possible. Though, I imagine plenty of other countries also have similar "arms race" abilities, which does complicate matters.
Some days, I just want to get a cabin in the woods, and get away from all this dystopian technology.
While I was writing this message , I was roaming out side in the street , my street isn't developed, so there is a lot of empty space 2 sides of my house.
I saw a peacock flying & sitting in front of my house. It was so majestic. It's wings when they fly , the sound they produce is such majestic that it touches your mind.
The solution isn't a cabin in the woods , the solution is living in such remote area like I live , seriously I am not that far away from the main town , but still this place is so nice I just realized but development would come , and houses would get built. Then there would be no more peacocks flying in.
I really get what you are feeling. But I believe that getting away from dystopian technology is far more easier by degoogling with grapheneos or getting a dumb phone like me & linux with sandboxing each applications ,I do think that we can get far away , like they would need to find a bug in such things like qemu , pledge , flatpak etc. though I think they might already have found a bug in some version and like you said, are waiting.
The only solution I can find is to read the source code of these sandboxing applications on linux and to never update it / it should be such that doesn't require updates , a completely minimal sandboxing solution.
How can we imagine they use their powers for good , when the president has handed things over to oligarchy who want maximum profits. What benefit do they get from using their power for good ? None. I am sure that they are using the power of both good and evil.
and carrying CSAM is a serious offense and you will get into jail for it. and the jail prisoners aren't kind to CSAM convicted prisoners and they would bully them immensely , maybe even cause them to suicide or just make their life hell.
I have friend/old-coworker that left my current employer for our state's version of the FBI. While no worker in his agency handled CSAM cases full-time, they all have to do rotations.
There is a lot he could not tell me about the work he did, and how they managed the detain suspects. But I do remember him telling me that he witnessed things that he thought were not even possible. Considering we were both developers, I take his word for it.
Anyway, I once asked him, "What is stopping you all from beaming CSAM on a person's computer, and then targeting that individual?" He paused for a second and said, "Well, we would never do that..." I asked again, "Sure, but what is stopping you all from doing that?" He said, "Well, nothing... but we wouldn't do that..."
Right then, my heart had this sinking feeling. While he is probably right, it did instill a sense of "Well, you never know..." in me. Do I believe most people convicted of CSAM are guilty? Absolutely. Everyone? Perhaps not. Still, good luck convincing a tech illiterate jury of your peers that "the government did it to me!" As far as I am concerned, once charged with such crimes, one is guilty until proven innocent.
I have always believed that if 'they' want you bad enough, then they will get you. By 'they', I mean any of the powers that be -- government, organized criminals, etc..
Goosebumps on my f'ing face.
And I was thinking this on 5 eyes level but you are saying a single country can do that?
When I had discovered that conspiracy theory which I now believe is true to some degree.
I then used to think, what if they want you to believe that you hold a chance. They don't want you to know they can get you as you are saying it. They want to give you the illusion of freedom. They will target their opposition , journalists with this if all goes south. There are also secret courts.
May I ask , if they can always get you why don't they use this in making their opposition go poof. If I am being extra conspiracist now , is it that they want you to give the freedom b/w 2 systems both of which don't change things really that much. Both political parties are kind of the same thing
but dude what the actual fuck.
They can use csam to break general encryption by saying it's bad for children etc, they can use csam to punish those they want.
I am now seriously wondering if I even have real tangible choice in the government.
I am now wondering if I am literally living in 1984. What if these wars and shit are just a distraction , yes they happen but...
Dude I have come to a realisation, I am seriously living in 1984. Reward is given to those who comply , those who aren't skeptics , skeptics are brushed off as conspiracist.
But yes the use case for a VPN is pretty narrow. E.g. not wanting your ISP to mess with your traffic and decreasing chances of detection of torrenting
Totally! Mullvad is _the_ pioneer in this space, and we look up to them. This is why they were our top pick for being an exit hop provider!
What would you like them to do? Considering that AIUI they outright don't log or monitor users at all, I can't think of anything they could do with your reports.
The issue is that VPN providers have zero motivation to do this, because a non-zero percentage of their user base is literally paying them BECAUSE they can use the service to attack other servers with a level of anonymity. If the VPN providers were to combat this issue it would negatively impact their revenue.
In other words, to break the fundamental premise of their product and identify traffic to a user.
> I think there would be a better way using AI to analyze abuse patterns, and automatically flag bad users which match these patterns.
Not without, again, creating an entire system which exists only to record traffic and tie it back to users.
Basically, both of your suggestions amount to "stop providing the product that is their entire business model", because the whole point is that they go out of their way to avoid having the information that you want them to use.
they can't have AI detection or any other thing to help you. Simply put they can't help you. If they have to , then they aren't that private.
And they are in the business of privacy.
I wonder why threat actors are abusing your website ? I think you have also used cloudflare anti DDOS ? so the problem isn't DDOS , then what exactly is the problem ? are they signing up and abusing your free service or something like that ?
One comment/question about the exit nodes. Can someone correct or validate my thoughts:
It’s a WireGuard tunnel from the user to Mullvad, so while Obscura can’t see the user traffic, couldn’t the Mullvad exit node see the traffic, and using knowledge of the users WireGuard public key, associate all that users traffic with that key? So even if they can’t associate it with an IP, they could still potentially identify and track you.
This assumes they use a customised version of WireGuard to somehow log & associate each decrypted IP packet against the users public key.
Even if Mullvad doesn't do it, someone else might. Mullvad is, I expect, now a valuable target because it is the VPN service of choice for so many people concerned with security. Does Mullvad have the budget and expertise to protect itself against determined, highly-resourced attackers?
Finally, is it possible for a third party, intercepting traffic between Obscura and Mullvad, to identify the public key used to encrypt it? I don't think so - the only way to validate a signature is with both keys; that's kind of the point. But maybe there is an attack I'm unaware of?
What is "zero trust deployments"?
Depends on the payment method. Accounting is mandatory in Sweden.
As a customer of [payment] services, these entities would allow us to request this information if we chose to do so. In short, your payment actions with these two methods are not anonymous and the GDPR and other relevant data protection regulations may apply if you are making a payment by credit card, PayPal, Swish or by bank wire.
The data must be kept for the statutory retention period described in applicable local laws such as the Swedish Accounting Act (some information must be stored for seven years from the end of the fiscal year).
That "some information" according to Swedish Accounting Act (bokföringslagen): "Every transaction, including customer payments, must be supported by proper documentation such as invoices, receipts, and payment confirmations."https://mullvad.net/en/help/no-logging-data-policy / https://archive.vn/qkvD3
What you're now telling me is only if I, as a user, don't give Mullvad my info, they wouldn't have to store that. I mean, that's one way or one way of looking at it, alright.
my conspiracy spidey sense is sensing something fishy...
Maybe timing attack is not part of .onion addresses ?
The downside is that it gets much slower, and feels 'bad' as an end user. Each packet takes longer.
> Does Mullvad have the budget and expertise to protect itself against determined, highly-resourced attackers?
I think Mullvad is actively working on [System Transparency](https://www.system-transparency.org/), which will help a lot.
> Finally, is it possible for a third party, intercepting traffic between Obscura and Mullvad, to identify the public key used to encrypt it? I don't think so - the only way to validate a signature is with both keys; that's kind of the point. But maybe there is an attack I'm unaware of?
I had asked this question a long time ago on either a noiseprotocol or wireguard IRC channel, and the answer is no, a third party intercepting traffic between Obscura and Mullvad, WON'T be able to identify the public key used to encrypt it.
Trust, 2-Party Relays, and QUIC - https://news.ycombinator.com/item?id=43016574 - Feb 2025 (33 comments)
I hate modern web development.
I also think people skipping over learning some basic CSS fundamentals also end up skipping over basic UI/UX needed for accessible websites, something every web developer should have some awareness about.
Complete reliance on CSS frameworks does not magically make the websites accessible,it gets you 90% there.
Also /blog leads of 403!? Wildcard redirects are not that difficult to setup either.
I have my blog hosted at omg.lol and while I had to support mobile by myself, it was really really simple.
Here is my blog: https://xd1.dev
Here is the code for the blog's responsive layout: https://github.com/gchamon/xd1.dev/blob/main/css/responsive-...
No injection, no build, just plain inline linking https://github.com/gchamon/xd1.dev/blob/10b98ddb37a9786ca8fe...
You’re absolutely right, we fixed it and forgot to push to prod XP
Mullvad only needs to associate each decrypted IP packet against an assertion that the packet was paid for. I assume each Obscura node would have a public key, but not associated with a user.
They notably offer this service for Tailscale (as an add-on) and I imagine that it works similarly (on the backend)
Eg based on the specific sites visited, payload sizes potentially, domains looked up, etc you’d be able to characterise the person. Especially so if anything they did was not encrypted, or they have their own vanity domain (for emails or anything else).
> Mullvad only needs to associate each decrypted IP packet against an assertion that the packet was paid for.
The idea of Obscura is by using two middlemen (them + Mullvad) that neither party can figure out who the end user is. So I’m looking at Mullvad from the perspective of: if they were evil, what about this solution are safeguard protecting the end users privacy. And my conclusion is they’d still be able to break the users privacy in the same way as knowing the users IP, just without the IP.
This is actually quite an interesting point that we’ve been discussing internally.
Right now Obscura rotates your WireGuard key on every “Connect”, but in a future release we will start caching (persist) your WireGuard keys on your client. When we flip that switch, we will also enable recurring key rotation and add a button in the UI for manual key rotation. This rotation would make it harder for Mullvad to track a user across the same key. (Not that they would anyway)
All of this is available for folks to verify at on our GitHub repository: https://github.com/Sovereign-Engineering/obscuravpn-client
* State actor determines that an IP belonging to a VPN company had a session on example.com around t1-t2
* You -> VPN server at t1
* VPN server -> example.com at t1+latency
* More traces from both sides until around t2 as you browse the site
By correlating multiple samples, and accounting for latency between you and the VPN server and delay introduced by the VPN itself, they would be able to get decent confidence that it was you.
I feel sad that we have given governments such major accesses in the name of unification.
We need more decentralization at the political level & economical level as well (like most money goes to your city , then state , then at the country , very nominal amount)
Let city decide what it wants with major town hall discussions.
https://www.ivpn.net/privacy-guides/isp-netflow-surveillance...
This adversary would have the ability to ingest massive amounts of data and metadata[0] it acquires from tier 1 ISPs all over the country[1] and the world[2]. They'll not see raw HTTP traffic because most everything of interest is encrypted, but can store and capture (time, srcip, srcport, dstip, dstport, bytes).
From there, it's a statistical attack: user A sent 700 kilobytes to a VPN service at time t; at t+epsilon the VPN connected to bad site B and sent 700 kilobytes+epsilon packets. Capture enough packet flows that span the user, the VPN, and the bad site and you can build statistical confidence that user A is interacting with bad site B, even with the presence of a VPN.
This could go other directions too. If bad site B is a Tor hidden site whose admin gets captured by the FBI and turns over access, they'll be unmasking in reverse – I got packets from Tor relay A, which relay sent packets at time-epsilon to it, (...), to the source.
There's very little you can do to fight this kind of adversary. Adding hops and layers (VPN + VPN, Tor, Tor + VPN, etc.) can only make it harder. It's certainly an expensive attack both in terms of time consumption, storage, and it requires massive amounts of data, but if your threat model includes a global passive adversary, game over.
[0] https://en.wikipedia.org/wiki/XKeyscore
- users only ever talk to nodes in 8kb chunks, and they TX/RX 12 packets per second.
- nodes only talk to each other in 128kb chunks. Up to 8x / second, no lower than 1x/second
Truly constant rate anonymity networks dramatically add resistance to passive traffic analysis, but they move users from a low-latency/high-throughput network to 56k dialup speeds :) Not only does this suck so most people won't use it, but the people who do chose to use it will glow neon bright to adversaries. The use of the system will be a strong indicator that, even if you don't know what the user is doing, the user is doing _something_ interesting.
And even if there was desire, these networks are intrinsically limited in size and scale if they want to maintain constant rate. Herbivore[0] is an interesting proposal in this space - use a DC-net partitioned into smaller cliques to give in-group anonymity but mass participation. And most use chaff packets – A has nothing to send so sends encrypted random data to maintain the constant rate guarantee... I'm trying to find the paper I read that suggests a global passive adversary who goes "hands on" in the network could use a combination of watermarks generated through packet dropping/artificial queues + knowledge of which packets are chaff to build a trace, but I'm struggling. If I do I'll drop it here.
For fun, go check out https://groups.google.com/g/alt.anonymous.messages – this is probably the classic example of a (very) high-latency but very strong anonymizing mix network.
[0] https://www.cs.cornell.edu/people/egs/papers/herbivore-tr.pd...
But every layer helps; I'd feel more than happy torrenting over Mullvad alone, and I'd definitely use it as an additional layer of defense with other tools to keep me private if my threat model needed to consider stronger risks.
https://www.youtube.com/watch?v=9_b8Z2kAFyY
Just use Tor.
This might or might not extend to VPN nodes depending on your threat model - I'd personally assume every single node offered to me by a company in exchange for money is malicious if I was concerned about privacy.
Mullvad with cash seems like a super ideal way to go. Why can't I just mail you $20 and call it a day?
Also, let's not forget Monero. Even if you buy Monero in a KYC exchange, the letterbois can only track if you've bought, but can't track where you send it to next. You could then exchange it for bitcoin with someone or using a non-KYC service, and there you have it, an anonymous BTC reserve. Or you could just bypass BTC altogether and use the much superior Monero to buy whatever you want.
I understand that it's possible to get crypto through obscure methods. However if you're selling a privacy focused solution, ideally you shouldn't have to spend 3-4 weeks to acquire the funds to purchase it.
I make no claims that commercial VPNs are more secure, but at least they have some level of interest in keeping their promises if people are paying them, whereas a free service does not carry the same incentive.
Pick your poison, I guess.
They also haven't had any influence or control in the development of todays tor project that has existed for over 20 years and despite a massive amount of attacks and research there has never been found anything.
That does not mean there aren't serious drawbacks that are more worth pointing out such as why bother with a very complex and noisy backdoor when you can just covertly create enough nodes to do traffic correlation.
Winner winner chicken dinner.
FVEY's annual budget is $1.7bn + $1bn + $122mm (NZ :3) + $4.6bn + $classified billion.
You think those guys can't mount a Sybil attack against https://metrics.torproject.org/ ?!
Cool, sounds like an organization that is heavily incentivized to make their communication hard to intercept and eavesdrop on.
And 50% of the time it works every time...
A lot of things simply don't work if you're using tor. You get blocked, you get blacklisted, accounts get terminated, and so on.
Google Search comes to mind as the most Tor-hostile website though, and that allows Mullvad just fine.
but if a website is working on mullvad and not on tor and you are forced to use that website , then yes compromise your opsec a little bit I suppose
so I would argue that tor + mullvad is still a worse opsec than tor and it still has roughly the same / slightly worse speed with tor.
but I would also argue that tor + mullvad is a better model than obscura + mullvad for opsec but not for speed.
TLDR: Don't use tor with vpn's unless you are forced to (like website block , because then you are kind of forced to reduce your opsec a little bit)
The answer is yes - this is the same concept as Apple's Private Relay.
I think you have misread things. They aren't comparing private relay with tor but rather with obscura for which the answer is a yes
For authentication? Yes.
Private Relay has Tor-like guarantees (with 2 hops) baked into the protocol, as it uses anonymous authorization tokens (which can't be tied to Apple IDs they represent) at exit node.
https://www.apple.com/privacy/docs/iCloud_Private_Relay_Over...
That's IMVHO the substance, not counting the fact that even a secure channel is meaningless if you run proprietary crapware at their end.
Police can ask the service provider to assign you to a specific exit node.
Once you are on that specific exit node it's over.
It's easy for the police to convince you, the CEO of Obscura wouldn't want to be charged as an aid in a crime.
MacOS is becoming the default platform for development now? This in and of itself, is a threat.
If I get any kind of a VPN system, I would want it to cover the entire network with just a single installation. Targeting routers running open-source firmware would be a great next step after the three main desktop platforms.
Plus, this then allows Obscura to protect any manner of net-enabled device, regardless of installed OS. Even my HaikuOS systems would be protected that way.
My second question involves roaming devices, such as phones -- will there be a mechanism in play that would allow a phone to recognize a “friendly” or “home” network, and disable its own Obscura install in favour of force-redirecting all network communication through the home Obscura? Or would it simply default to running Obscura-within-Obscura?
My last question involves multiple households: is there any plan to provide a bridging solution between multiple households, so they effectively appear like one giant network with a shared Obscura bridge to the Internet? The point being, I have services on my own home network that I would like to share out to my parents and my brother, which is very doable with a home-built VPN, but I also want a VPN that is a lot like Obscura to protect everyone with regards to direct Internet communication.
Are you planning no-ads campaigns (similar to what simpleanalytics.com does)?
I'm on a privacy-first project and such info would help.
The security on the whole thing still relies on the idea that those two providers, who are partnering to offer this service and sharing the cost, would only try to attack you separately and not together. I don't buy it.
Ah we added payment and pricing to our navbar in staging but forgot to push to prod. Doing so now!
What happened to the tickets being tracked in the Epic that signified this launch? The entire Epic should have been flagged as resolved/completed before a launch like this should have been triggered. As in, the ticket for the launch should have been dependent on the Epic itself being completed.
That’s how you dot your i’s and cross your t’s to prevent very important things from falling through the cracks.
How does Obscura compare to Tor?
We have immense respect for the Tor project (and encourage you to support it), but its volunteer-run network can be slow and susceptible to DDoS issues, making it infeasible for everyday use.
Obscura uses two dedicated, high-performance hops for maximum speed and reliability – meaning you get many of Tor’s privacy benefits without sacrificing everyday usability.
> Obscura’s servers relay your connection to exit servers but can never decrypt your traffic.
Doesn't that rely on us trusting that the server runs the code they claim it does? Or is there a way to prove that their server can't get the decryption key (i.e. by proving that it's not possible for them to switch the final hop, or add undisclosed hops in between)?
[0] https://github.com/Sovereign-Engineering/obscuravpn-client/b...
Here's what [one of our FAQ entries](https://obscura.net/#faq-trust) say:
> Additionally, our app displays your current exit hop’s WireGuard public key on its “Location” page. You can check this key against what Mullvad publishes [here](https://mullvad.net/servers) to ensure that you’re connected via a genuine Mullvad exit hop!
Let me know if that's unclear!
Woah I didn’t know about the specific term “VPN cascading”… And it seems like my GLiNet travel router can do it too?
Well in any case, it seems like with cascading you’d have to register with 2 different providers, offering your personal info (if necessary) to both.
Happy to answer any questions y’all might have!
1)How can I trust that you are sending the data to mullvad only , is there some way of proving this instead of trusting you ?
2) What if all the VPN companies merge together to create such network with 2-3 hops yet still having maximum privacy.
3)Off-topic? But couldn't this theoretically be done if lets say the mullvad vpn connects via https to something like piping server but instead of a single write -> multiple reciever , we fork it a little bit for multiple write -> single receiver & this can work itself on curl and its encrypted. I can in my rough mind draw exactly what obscura is trying to do but with piping server which is so much easier to self host & even host it on multiple cloud providers. Though a big thing is that the nodes would have to be a little configured for this specific purpose (maybe this is where obscura can come in?)
Supposing that this can be done , then what threat model difference would have it as compared to current obscura. https://github.com/nwtgck/piping-server
1) Here's what [one of our FAQ entries](https://obscura.net/#faq-trust) say:
> Additionally, our app displays your current exit hop’s WireGuard public key on its “Location” page. You can check this key against what Mullvad publishes [here](https://mullvad.net/servers) to ensure that you’re connected via a genuine Mullvad exit hop!
2) I really hope that the VPN industry comes together and become each others' 1st/exit hops!
3) Not totally sure what you mean, but we [use WireGuard-over-QUIC](https://obscura.net/blog/bootstrapping-trust/).
Mac apps by default ping the apple servers before they can connect to wireguard over quic and what not.
So its definitely not as secure as using linux or bsd.
Please I want to understand what makes linux / cross platform development harder.
It was for zeditor , arc browser and what not. Things make me treat as third class citizen and mac users as first kind of feels a little .. weird.
Tor still offers more privacy benefits than Obscura for sure, but you want a shorthand, “Tor with 2 hops” works :-)
https://tor.stackexchange.com/questions/491/why-does-tor-use...
Your trust is that Obscura and Mullvad will not collude.
EDIT: Ah, they use Mullvad for exit hops. Sweet.