Live data from Hacker News

Obscura VPN – Privacy that's more than a promise

obscura.net

121–130 of 170 posts

Re: Obscura VPN – Privacy that's more than a promise

#121

Earlier quoted context omitted.

> I have approached Mullvad many times with abusive user reports which they seem to simply ignore. What would you like them to do? Considering that AIUI they outright don't log or monitor users at all, I can't think of anything they could do with your reports.

Yes that is the crux of the issue. However many times when I reported bad actors to Mullvad the attacks were multi day attacks that were ongoing. It would have been trivial for Mullvad to add a filter to check for future packets from that VPN ip to my server IP and flag the associated account. However I believe even this approach is far to manual and invasive. I think there would be a better way using AI to analyze a…

Lets face it man , they can't do anything.

they can't have AI detection or any other thing to help you. Simply put they can't help you. If they have to , then they aren't that private.

And they are in the business of privacy.

I wonder why threat actors are abusing your website ? I think you have also used cloudflare anti DDOS ? so the problem isn't DDOS , then what exactly is the problem ? are they signing up and abusing your free service or something like that ?

Re: Obscura VPN – Privacy that's more than a promise

#122
post #84

Earlier quoted context omitted.

Okay, but this is a given if you don't run your own ISP. Your ISP can also see that you connect to Tor. Your data is still encrypted.

It ultimately depends on your threat model. But assuming a state actor has access to NetFlow data, an attack could work like this: * State actor determines that an IP belonging to a VPN company had a session on example.com around t1-t2 * You -> VPN server at t1 * VPN server -> example.com at t1+latency * More traces from both sides until around t2 as you browse the site By correlating multiple samples, and accounting…

Basically when you go at the point of state threat actors. Things get real spooky. The censorship , the what not.

I feel sad that we have given governments such major accesses in the name of unification.

We need more decentralization at the political level & economical level as well (like most money goes to your city , then state , then at the country , very nominal amount)

Let city decide what it wants with major town hall discussions.

Re: Obscura VPN – Privacy that's more than a promise

#123
post #9

Earlier quoted context omitted.

Also, Obscura can collect metadata on when you use the service, how much data you send/receive, etc. Even if Mullvad doesn't do it, someone else might. Mullvad is, I expect, now a valuable target because it is the VPN service of choice for so many people concerned with security. Does Mullvad have the budget and expertise to protect itself against determined, highly-resourced attackers? Finally, is it possible for a t…

Timing attacks are notably not a part of Tor's threat model, i.e. they are a real concern: https://support.torproject.org/about/attacks-on-onion-routin...

hmm. that is interesting , would you mind sharing some solution , what if I add some insane latency (I know unusable but if it prevents timing attacks)

my conspiracy spidey sense is sensing something fishy...

Maybe timing attack is not part of .onion addresses ?

Re: Obscura VPN – Privacy that's more than a promise

#124

Earlier quoted context omitted.

> no databases of user info Depends on the payment method. Accounting is mandatory in Sweden. As a customer of [payment] services, these entities would allow us to request this information if we chose to do so. In short, your payment actions with these two methods are not anonymous and the GDPR and other relevant data protection regulations may apply if you are making a payment by credit card, PayPal, Swish or by ban…

Sure, but if privacy matters to you, you have the option of buying credit anonymously and applying it to an anonymized account number. And if your threat model includes nation states, you're definitely not buying anything with a credit card. I also think if you're after payment details, there's more lucrative targets, eg Stripe.

OK. I was just wondering about your "zero trust" (aka "no database of user info etc") comment in the face of those and other Swedish laws that apply to Mullvad, is all.

What you're now telling me is only if I, as a user, don't give Mullvad my info, they wouldn't have to store that. I mean, that's one way or one way of looking at it, alright.

Re: Obscura VPN – Privacy that's more than a promise

#125
post #83

Earlier quoted context omitted.

> real untraceable anonymity and is 100% free. And 50% of the time it works every time... A lot of things simply don't work if you're using tor. You get blocked, you get blacklisted, accounts get terminated, and so on.

Run Mullvad over Tor instead of Mullvad over this Obscura thing ;-)

tor generally doesn't recommend running vpn over tor makes any of your opsec any more safer , in fact I can argue that it makes your opsec worse

but if a website is working on mullvad and not on tor and you are forced to use that website , then yes compromise your opsec a little bit I suppose

Re: Obscura VPN – Privacy that's more than a promise

#126

Earlier quoted context omitted.

That wasn't the question, though. The answer is yes - this is the same concept as Apple's Private Relay.

No, it isn't similar to Private Relay as its entire premise for 2 hop (versus 3 for Tor) hinges on anonymous authorization (via Privacy Pass ) at the exit node.

But isn't that apple id + privacy relay as well.

I think you have misread things. They aren't comparing private relay with tor but rather with obscura for which the answer is a yes

Re: Obscura VPN – Privacy that's more than a promise

#127

Earlier quoted context omitted.

Multiple questions here : 1)How can I trust that you are sending the data to mullvad only , is there some way of proving this instead of trusting you ? 2) What if all the VPN companies merge together to create such network with 2-3 hops yet still having maximum privacy. 3)Off-topic? But couldn't this theoretically be done if lets say the mullvad vpn connects via https to something like piping server but instead of a…

(Carl from Obscura here) 1) Here's what [one of our FAQ entries]( https://obscura.net/#faq-trust ) say: > Additionally, our app displays your current exit hop’s WireGuard public key on its “Location” page. You can check this key against what Mullvad publishes [here]( https://mullvad.net/servers ) to ensure that you’re connected via a genuine Mullvad exit hop! 2) I really hope that the VPN industry comes together and…

Thanks. I do wonder why you are a mac only app.

Mac apps by default ping the apple servers before they can connect to wireguard over quic and what not.

So its definitely not as secure as using linux or bsd.

Please I want to understand what makes linux / cross platform development harder.

It was for zeditor , arc browser and what not. Things make me treat as third class citizen and mac users as first kind of feels a little .. weird.

Re: Obscura VPN – Privacy that's more than a promise

#130
post #83

Earlier quoted context omitted.

Run Mullvad over Tor instead of Mullvad over this Obscura thing ;-)

tor generally doesn't recommend running vpn over tor makes any of your opsec any more safer , in fact I can argue that it makes your opsec worse but if a website is working on mullvad and not on tor and you are forced to use that website , then yes compromise your opsec a little bit I suppose

The point is not opsec but speed, under the GP's assumption that Mullvad exit nodes have better reputation than tor exit nodes. Not sure if the case, I don't use Mullvad.
Post reply on HN