This was already discussed last week: https://news.ycombinator.com/item?id=43016574 The security on the whole thing still relies on the idea that those two providers, who are partnering to offer this service and sharing the cost, would only try to attack you separately and not together. I don't buy it.
Would you agree it’s strictly better than a single provider?
Obscura VPN – Privacy that's more than a promise
131–140 of 170 posts
Re: Obscura VPN – Privacy that's more than a promise
#132Earlier quoted context omitted.
My boy, Tim Cook, ain't a snitch though. (At least, I hope not).
Also I had read somewhere about a really strange conspiracy theory which really made me question if we can really be against government and big tech (since "lobbying" is made official) but if 5 eyes (the billionaires?) really wanted (heck only if UK + australia wanted , australia police is given the ability to remotely plant data in nation's interest and uk also is getting apple to force data to be leaked in the appl…
I have friend/old-coworker that left my current employer for our state's version of the FBI. While no worker in his agency handled CSAM cases full-time, they all have to do rotations.
There is a lot he could not tell me about the work he did, and how they managed the detain suspects. But I do remember him telling me that he witnessed things that he thought were not even possible. Considering we were both developers, I take his word for it.
Anyway, I once asked him, "What is stopping you all from beaming CSAM on a person's computer, and then targeting that individual?" He paused for a second and said, "Well, we would never do that..." I asked again, "Sure, but what is stopping you all from doing that?" He said, "Well, nothing... but we wouldn't do that..."
Right then, my heart had this sinking feeling. While he is probably right, it did instill a sense of "Well, you never know..." in me. Do I believe most people convicted of CSAM are guilty? Absolutely. Everyone? Perhaps not. Still, good luck convincing a tech illiterate jury of your peers that "the government did it to me!" As far as I am concerned, once charged with such crimes, one is guilty until proven innocent.
I have always believed that if 'they' want you bad enough, then they will get you. By 'they', I mean any of the powers that be -- government, organized criminals, etc..
Re: Obscura VPN – Privacy that's more than a promise
#133Earlier quoted context omitted.
My boy, Tim Cook, ain't a snitch though. (At least, I hope not).
You can't prove it. Apple isn't open source. And with the recent Debacle of Snooper's Law apple e2ee backdoor. Let me tell you something. A company is asked for a backdoor and they are forced to not tell anybody about it. The only reason why it was leaked was because of whistleblower. And so , who knows if they have already signed such thing with the NSA or UK already but for their mac's and other devices
I do not believe there is such thing as privacy from such organizations. If they want you bad enough, they will get you. Don't have a reason? They'll make one.
Re: Obscura VPN – Privacy that's more than a promise
#134Earlier quoted context omitted.
The threat actor most use to talk about this is a global passive adversary: a threat actor who can see all relevant traffic on the Internet but who can't decrypt or adjust the traffic. This adversary would have the ability to ingest massive amounts of data and metadata[0] it acquires from tier 1 ISPs all over the country[1] and the world[2]. They'll not see raw HTTP traffic because most everything of interest is encr…
Could they go to synchronous packet transfer and static payloads? - users only ever talk to nodes in 8kb chunks, and they TX/RX 12 packets per second. - nodes only talk to each other in 128kb chunks. Up to 8x / second, no lower than 1x/second
Truly constant rate anonymity networks dramatically add resistance to passive traffic analysis, but they move users from a low-latency/high-throughput network to 56k dialup speeds :) Not only does this suck so most people won't use it, but the people who do chose to use it will glow neon bright to adversaries. The use of the system will be a strong indicator that, even if you don't know what the user is doing, the user is doing _something_ interesting.
And even if there was desire, these networks are intrinsically limited in size and scale if they want to maintain constant rate. Herbivore[0] is an interesting proposal in this space - use a DC-net partitioned into smaller cliques to give in-group anonymity but mass participation. And most use chaff packets – A has nothing to send so sends encrypted random data to maintain the constant rate guarantee... I'm trying to find the paper I read that suggests a global passive adversary who goes "hands on" in the network could use a combination of watermarks generated through packet dropping/artificial queues + knowledge of which packets are chaff to build a trace, but I'm struggling. If I do I'll drop it here.
For fun, go check out https://groups.google.com/g/alt.anonymous.messages – this is probably the classic example of a (very) high-latency but very strong anonymizing mix network.
[0] https://www.cs.cornell.edu/people/egs/papers/herbivore-tr.pd...
Re: Obscura VPN – Privacy that's more than a promise
#135Earlier quoted context omitted.
tor generally doesn't recommend running vpn over tor makes any of your opsec any more safer , in fact I can argue that it makes your opsec worse but if a website is working on mullvad and not on tor and you are forced to use that website , then yes compromise your opsec a little bit I suppose
The point is not opsec but speed, under the GP's assumption that Mullvad exit nodes have better reputation than tor exit nodes. Not sure if the case, I don't use Mullvad.
so I would argue that tor + mullvad is still a worse opsec than tor and it still has roughly the same / slightly worse speed with tor.
but I would also argue that tor + mullvad is a better model than obscura + mullvad for opsec but not for speed.
TLDR: Don't use tor with vpn's unless you are forced to (like website block , because then you are kind of forced to reduce your opsec a little bit)
Re: Obscura VPN – Privacy that's more than a promise
#136Mullvad with cash seems like a super ideal way to go. Why can't I just mail you $20 and call it a day?
Re: Obscura VPN – Privacy that's more than a promise
#137Earlier quoted context omitted.
No, it isn't similar to Private Relay as its entire premise for 2 hop (versus 3 for Tor) hinges on anonymous authorization (via Privacy Pass ) at the exit node.
But isn't that apple id + privacy relay as well. I think you have misread things. They aren't comparing private relay with tor but rather with obscura for which the answer is a yes
For authentication? Yes.
Private Relay has Tor-like guarantees (with 2 hops) baked into the protocol, as it uses anonymous authorization tokens (which can't be tied to Apple IDs they represent) at exit node.
https://www.apple.com/privacy/docs/iCloud_Private_Relay_Over...
Re: Obscura VPN – Privacy that's more than a promise
#138Earlier quoted context omitted.
This comment is wrong and not funny. 1) you didn't read path selection constraints: https://spec.torproject.org/path-spec/path-selection-constra... >We do not choose more than one router in a given network range, which defaults to /16 for IPv4 and /32 for IPv6. (C Tor overrides this with EnforceDistinctSubnets; Arti overrides this with ipv[46]_subnet_family_prefix.) 2) There is currently no exit-node hosted at Hetzne…
1) Hetzner has more than one /16. Probably not in the same rack though. Might be adjacent rows. Organizations which have their own IP ranges can use them at Hetzner, too. 2) Exit circuits are not the only type of circuit.
If you own the nodes you can just log the encrypted traffic with metadata like user IP (if its an entry-node, which requires a Guard-flag), source and destination Tor-node and timestamp to send it to a centralized logging server. No need to host them in the same rack.
The problem of three nodes being in one rack is traffic analysis of an external attacker, who doesn't own the nodes. If someone already owns the nodes it doesn't matter where they host them.. Using your own IP range for an attack would just be more complicated, less effective than just buying nodes worldwide and is an OPSEC risk.
So the only reason to run tor nodes on your own IP range on Hetzner servers is if you work together with an organization which has access to ISP and datacenter traffic and probably work together with the datacenter owner to attack Tor users through a correlation attack.
>Exit circuits are not the only type of circuit. Connections to onion services are sent over 6 nodes, not 3. You talked about 3 nodes, so I assumed you talk about the typical Guard or Bridge Node -> Mid-Node -> Exit-Node circuit. The only reason to have less nodes are single-hop onion services. They are an edge-case..
EDIT: fixed grammer
Re: Obscura VPN – Privacy that's more than a promise
#139Earlier quoted context omitted.
It ultimately depends on your threat model. But assuming a state actor has access to NetFlow data, an attack could work like this: * State actor determines that an IP belonging to a VPN company had a session on example.com around t1-t2 * You -> VPN server at t1 * VPN server -> example.com at t1+latency * More traces from both sides until around t2 as you browse the site By correlating multiple samples, and accounting…
Basically when you go at the point of state threat actors. Things get real spooky. The censorship , the what not. I feel sad that we have given governments such major accesses in the name of unification. We need more decentralization at the political level & economical level as well (like most money goes to your city , then state , then at the country , very nominal amount) Let city decide what it wants with major to…
Re: Obscura VPN – Privacy that's more than a promise
#140Earlier quoted context omitted.
Governments do not even need any of the providers to comply, they can access global NetFlow data. This is conveniently not discussed by any commercial VPN provider.
Could you protect against NetFlow analysis by pushing a bunch of noise over the VPN tunnel at all times? I'd assume it would at least make the analysis significantly more challenging.
This might or might not extend to VPN nodes depending on your threat model - I'd personally assume every single node offered to me by a company in exchange for money is malicious if I was concerned about privacy.