Live data from Hacker News

Obscura VPN – Privacy that's more than a promise

obscura.net

141–150 of 170 posts

Re: Obscura VPN – Privacy that's more than a promise

#141
Since I work mainly with workstations, and rarely ever with laptops, is there a plan to bring something like Obscura to a router running DD-WRT or OpenWRT? Or would I have to get a full-fat router running OpenBSD/PFSense in order to hook Obscura into it?

If I get any kind of a VPN system, I would want it to cover the entire network with just a single installation. Targeting routers running open-source firmware would be a great next step after the three main desktop platforms.

Plus, this then allows Obscura to protect any manner of net-enabled device, regardless of installed OS. Even my HaikuOS systems would be protected that way.

My second question involves roaming devices, such as phones -- will there be a mechanism in play that would allow a phone to recognize a “friendly” or “home” network, and disable its own Obscura install in favour of force-redirecting all network communication through the home Obscura? Or would it simply default to running Obscura-within-Obscura?

My last question involves multiple households: is there any plan to provide a bridging solution between multiple households, so they effectively appear like one giant network with a shared Obscura bridge to the Internet? The point being, I have services on my own home network that I would like to share out to my parents and my brother, which is very doable with a home-built VPN, but I also want a VPN that is a lot like Obscura to protect everyone with regards to direct Internet communication.

Re: Obscura VPN – Privacy that's more than a promise

#142
post #25

Earlier quoted context omitted.

It was also developed by the United States Navy and has been criticized for not being as secure as it claims it is. This should come as no surprise since the US military and agencies have a history of demanding backdoors in software, which just means more attack vectors for outsiders to sniff out. I make no claims that commercial VPNs are more secure, but at least they have some level of interest in keeping their pro…

The navy backdoor claims are unsubstantiated FUD unless you can point them out in the freely available and accessible code. Not to mention that they created the tool to also use themselves. They also haven't had any influence or control in the development of todays tor project that has existed for over 20 years and despite a massive amount of attacks and research there has never been found anything. That does not mea…

> That does not mean there aren't serious drawbacks that are more worth pointing out such as why bother with a very complex and noisy backdoor when you can just covertly create enough nodes to do traffic correlation.

Winner winner chicken dinner.

FVEY's annual budget is $1.7bn + $1bn + $122mm (NZ :3) + $4.6bn + $classified billion.

You think those guys can't mount a Sybil attack against https://metrics.torproject.org/ ?!

Re: Obscura VPN – Privacy that's more than a promise

#143
post #58

It would have been nice if they'd have revealed what the payment options are before the final step. Kind of disappointing.

(Carl from Obscura here) Ah we added payment and pricing to our navbar in staging but forgot to push to prod. Doing so now!

Okay, this is… not encouraging.

What happened to the tickets being tracked in the Epic that signified this launch? The entire Epic should have been flagged as resolved/completed before a launch like this should have been triggered. As in, the ticket for the launch should have been dependent on the Epic itself being completed.

That’s how you dot your i’s and cross your t’s to prevent very important things from falling through the cracks.

Re: Obscura VPN – Privacy that's more than a promise

#144

Earlier quoted context omitted.

How would such an attack work?

The threat actor most use to talk about this is a global passive adversary: a threat actor who can see all relevant traffic on the Internet but who can't decrypt or adjust the traffic. This adversary would have the ability to ingest massive amounts of data and metadata[0] it acquires from tier 1 ISPs all over the country[1] and the world[2]. They'll not see raw HTTP traffic because most everything of interest is encr…

https://mullvad.net/fr/blog/introducing-defense-against-ai-g...

and multi-hop addresses https://news.ycombinator.com/item?id=43114966

Re: Obscura VPN – Privacy that's more than a promise

#146

Why do all of these new VPN solutions want some form of Crypto payment that has to go through KYC regulations to acquire... doesn't that somewhat defeat the purpose? Mullvad with cash seems like a super ideal way to go. Why can't I just mail you $20 and call it a day?

There are a couple of options for acquiring crypto without KYC. One might sell goods and services for crypto (I have done it myself, sold a videogame console P2P through a local libertarian group chat), or buy crypto with cash via P2P or in a country with looser KYC laws, and lastly they could just mine it themselves. Having significant money through mining might seem improbable, but we can't forget the market dynamics, someone might have mined a lot of some altcoin before a big boom (e.g. dogecoin) and ended up rich overnight.

Also, let's not forget Monero. Even if you buy Monero in a KYC exchange, the letterbois can only track if you've bought, but can't track where you send it to next. You could then exchange it for bitcoin with someone or using a non-KYC service, and there you have it, an anonymous BTC reserve. Or you could just bypass BTC altogether and use the much superior Monero to buy whatever you want.

Re: Obscura VPN – Privacy that's more than a promise

#147

Earlier quoted context omitted.

The threat actor most use to talk about this is a global passive adversary: a threat actor who can see all relevant traffic on the Internet but who can't decrypt or adjust the traffic. This adversary would have the ability to ingest massive amounts of data and metadata[0] it acquires from tier 1 ISPs all over the country[1] and the world[2]. They'll not see raw HTTP traffic because most everything of interest is encr…

https://mullvad.net/fr/blog/introducing-defense-against-ai-g... and multi-hop addresses https://news.ycombinator.com/item?id=43114966

I'm bearish on introducing noise[0] to resist traffic analysis, and I'm exceptionally bearish when the only layer managing noise injection is "a for-profit entity that can be legally compelled to do things"

But every layer helps; I'd feel more than happy torrenting over Mullvad alone, and I'd definitely use it as an additional layer of defense with other tools to keep me private if my threat model needed to consider stronger risks.

[0] https://news.ycombinator.com/item?id=43109903

Re: Obscura VPN – Privacy that's more than a promise

#149
post #76

Earlier quoted context omitted.

careful not to mail them from close to home, or have any handwriting, or leave any fingerprints

Doesn't matter if you use Windows / Mac because it will ping their services before you jump on the VPN and it will know the before IP and the IP after. :)

Well, the 'after IP' is an IP shared with tends or hundreds of thousands of other people.

But yes the use case for a VPN is pretty narrow. E.g. not wanting your ISP to mess with your traffic and decreasing chances of detection of torrenting

Re: Obscura VPN – Privacy that's more than a promise

#150

Interesting concept. The blog has a lot more details[1]. One comment/question about the exit nodes. Can someone correct or validate my thoughts: It’s a WireGuard tunnel from the user to Mullvad, so while Obscura can’t see the user traffic, couldn’t the Mullvad exit node see the traffic, and using knowledge of the users WireGuard public key, associate all that users traffic with that key? So even if they can’t associa…

(Carl from Obscura here) This is actually quite an interesting point that we’ve been discussing internally. Right now Obscura rotates your WireGuard key on every “Connect”, but in a future release we will start caching (persist) your WireGuard keys on your client. When we flip that switch, we will also enable recurring key rotation and add a button in the UI for manual key rotation. This rotation would make it harder…

Thanks for the reply, and glad to know it’s something you’re already thinking about!
Post reply on HN