Live data from Hacker News

Obscura VPN – Privacy that's more than a promise

obscura.net

111–120 of 170 posts

Re: Obscura VPN – Privacy that's more than a promise

#111

Earlier quoted context omitted.

Hey Carl, sorry to hijack the thread but I have a question for you. Being the operator a small website (5M views/month, 200k users), I am often plagued by targeted cyber attacks. Over the years many of these come from privacy enhanced networks (eg Tor, Mullvad, etc). I have approached Mullvad many times with abusive user reports which they seem to simply ignore. How do you plan to address this in your product? Will y…

> I have approached Mullvad many times with abusive user reports which they seem to simply ignore. What would you like them to do? Considering that AIUI they outright don't log or monitor users at all, I can't think of anything they could do with your reports.

Yes that is the crux of the issue. However many times when I reported bad actors to Mullvad the attacks were multi day attacks that were ongoing. It would have been trivial for Mullvad to add a filter to check for future packets from that VPN ip to my server IP and flag the associated account. However I believe even this approach is far to manual and invasive. I think there would be a better way using AI to analyze abuse patterns, and automatically flag bad users which match these patterns.

The issue is that VPN providers have zero motivation to do this, because a non-zero percentage of their user base is literally paying them BECAUSE they can use the service to attack other servers with a level of anonymity. If the VPN providers were to combat this issue it would negatively impact their revenue.

Re: Obscura VPN – Privacy that's more than a promise

#112
post #89

Earlier quoted context omitted.

If the abuse is serious enough, pursue legal avenues. Otherwise, these types of companies shouldn't be unmasking users based on a random persons assertion that someone is bad. That would be an abuse vector itself.

I am not asking them to. I am asking them to do a better job of bad actor detection and banning. Their current stance seems to be “ignore all packets, log nothing”. In my opinion they should be doing some amount of AI based abuse detection. This should be possible without violating user privacy.

How would you get training data for the AI without logging packets?

Re: Obscura VPN – Privacy that's more than a promise

#113
post #43

Earlier quoted context omitted.

Governments do not even need any of the providers to comply, they can access global NetFlow data. This is conveniently not discussed by any commercial VPN provider.

Honestly, paying for a VPN is just purchasing slow internet speeds at a premium. https://www.youtube.com/watch?v=9_b8Z2kAFyY Just use Tor.

So the idea is to torrent stuff at maybe 1 mb/s over Tor? I think I'll stick to VPNs

Re: Obscura VPN – Privacy that's more than a promise

#114

Earlier quoted context omitted.

Hey Carl, sorry to hijack the thread but I have a question for you. Being the operator a small website (5M views/month, 200k users), I am often plagued by targeted cyber attacks. Over the years many of these come from privacy enhanced networks (eg Tor, Mullvad, etc). I have approached Mullvad many times with abusive user reports which they seem to simply ignore. How do you plan to address this in your product? Will y…

I can understand that concern, and I think in the future some version of [Privacy Pass]( https://privacypass.github.io/ ) will allow for site operators to differentiate between normal vs. abusive users without relying on IP reputation (which is more unreliable anyway since CGNAT is a thing).

We typically don't ban IPs for the very reason mentioned here (CGNAT is a very real thing and we have many users who share IPs). However we do ban IP ranges associated with VPNs that we see an excessive amount of abuse from. I might be an outlier on the internet, but if you take the stance you have outlined above, that you will effectively do nothing to combat the level of abuse from your network, you inevitably hurt your honest users because some web services will be unavailable to them via your VPN.

Re: Obscura VPN – Privacy that's more than a promise

#116

Two-server approach sounds similar to ProtonVPN "secure core" feature: https://protonvpn.com/features/secure-core

These occur within two protonvpn servers themselves whereas obscura work b/w two different servers owned by two different entities (one obscura and other exit node of mullvad)

Re: Obscura VPN – Privacy that's more than a promise

#117

Earlier quoted context omitted.

Doesn't matter if you use Windows / Mac because it will ping their services before you jump on the VPN and it will know the before IP and the IP after. :)

My boy, Tim Cook, ain't a snitch though. (At least, I hope not).

You can't prove it. Apple isn't open source.

And with the recent Debacle of Snooper's Law apple e2ee backdoor.

Let me tell you something. A company is asked for a backdoor and they are forced to not tell anybody about it.

The only reason why it was leaked was because of whistleblower. And so , who knows if they have already signed such thing with the NSA or UK already but for their mac's and other devices

Re: Obscura VPN – Privacy that's more than a promise

#118

Earlier quoted context omitted.

> I have approached Mullvad many times with abusive user reports which they seem to simply ignore. What would you like them to do? Considering that AIUI they outright don't log or monitor users at all, I can't think of anything they could do with your reports.

Yes that is the crux of the issue. However many times when I reported bad actors to Mullvad the attacks were multi day attacks that were ongoing. It would have been trivial for Mullvad to add a filter to check for future packets from that VPN ip to my server IP and flag the associated account. However I believe even this approach is far to manual and invasive. I think there would be a better way using AI to analyze a…

> It would have been trivial for Mullvad to add a filter to check for future packets from that VPN ip to my server IP and flag the associated account.

In other words, to break the fundamental premise of their product and identify traffic to a user.

> I think there would be a better way using AI to analyze abuse patterns, and automatically flag bad users which match these patterns.

Not without, again, creating an entire system which exists only to record traffic and tie it back to users.

Basically, both of your suggestions amount to "stop providing the product that is their entire business model", because the whole point is that they go out of their way to avoid having the information that you want them to use.

Re: Obscura VPN – Privacy that's more than a promise

#119

Earlier quoted context omitted.

Doesn't matter if you use Windows / Mac because it will ping their services before you jump on the VPN and it will know the before IP and the IP after. :)

My boy, Tim Cook, ain't a snitch though. (At least, I hope not).

Also I had read somewhere about a really strange conspiracy theory which really made me question if we can really be against government and big tech (since "lobbying" is made official) but if 5 eyes (the billionaires?) really wanted (heck only if UK + australia wanted , australia police is given the ability to remotely plant data in nation's interest and uk also is getting apple to force data to be leaked in the apple ecosystem and who knows what else. Its only a matter of time that they put 2+2 together (or they have?) and use it to plant CSAM (yes NSA has distributed CSAM for the purposes of catching people , so I wonder if such 5 eyes also have these , please hackernews moderators just because I have mentioned CSAM , don't remove this comment I suppose)

and carrying CSAM is a serious offense and you will get into jail for it. and the jail prisoners aren't kind to CSAM convicted prisoners and they would bully them immensely , maybe even cause them to suicide or just make their life hell.

Re: Obscura VPN – Privacy that's more than a promise

#120
post #70

I'm not clear on the technical details here. > Obscura’s servers relay your connection to exit servers but can never decrypt your traffic. Doesn't that rely on us trusting that the server runs the code they claim it does? Or is there a way to prove that their server can't get the decryption key (i.e. by proving that it's not possible for them to switch the final hop, or add undisclosed hops in between)?

(Carl from Obscura here) Here's what [one of our FAQ entries]( https://obscura.net/#faq-trust ) say: > Additionally, our app displays your current exit hop’s WireGuard public key on its “Location” page. You can check this key against what Mullvad publishes [here]( https://mullvad.net/servers ) to ensure that you’re connected via a genuine Mullvad exit hop! Let me know if that's unclear!

That makes sense. Thanks for explaining!
Post reply on HN