Live data from Hacker News

Obscura VPN – Privacy that's more than a promise

obscura.net

151–160 of 170 posts

Re: Obscura VPN – Privacy that's more than a promise

#151

Earlier quoted context omitted.

1) Hetzner has more than one /16. Probably not in the same rack though. Might be adjacent rows. Organizations which have their own IP ranges can use them at Hetzner, too. 2) Exit circuits are not the only type of circuit.

>Organizations which have their own IP ranges can use them at Hetzner, too. If you own the nodes you can just log the encrypted traffic with metadata like user IP (if its an entry-node, which requires a Guard-flag), source and destination Tor-node and timestamp to send it to a centralized logging server. No need to host them in the same rack. The problem of three nodes being in one rack is traffic analysis of an exte…

You're speaking as if the only reason to run Tor nodes is to attack Tor.

Re: Obscura VPN – Privacy that's more than a promise

#152

Earlier quoted context omitted.

Basically when you go at the point of state threat actors. Things get real spooky. The censorship , the what not. I feel sad that we have given governments such major accesses in the name of unification. We need more decentralization at the political level & economical level as well (like most money goes to your city , then state , then at the country , very nominal amount) Let city decide what it wants with major to…

Town halls where only people with an agenda to push or retired and bored people show up?

You can change that much easier than changing something at the national level

Re: Obscura VPN – Privacy that's more than a promise

#153
post #52

Just to note here - with Mullvad you can pay via gift card that you can find at various retailers (to get a one-time code that you can use to create an account). Of course they can see your IP address but there is no payment/contact information on the system.

You can also mail them an envelope full of cash last I checked.

Re: Obscura VPN – Privacy that's more than a promise

#154

Why do all of these new VPN solutions want some form of Crypto payment that has to go through KYC regulations to acquire... doesn't that somewhat defeat the purpose? Mullvad with cash seems like a super ideal way to go. Why can't I just mail you $20 and call it a day?

There are a couple of options for acquiring crypto without KYC. One might sell goods and services for crypto (I have done it myself, sold a videogame console P2P through a local libertarian group chat), or buy crypto with cash via P2P or in a country with looser KYC laws, and lastly they could just mine it themselves. Having significant money through mining might seem improbable, but we can't forget the market dynami…

That whole comment is "With a way harder method than going to the ATM".

I understand that it's possible to get crypto through obscure methods. However if you're selling a privacy focused solution, ideally you shouldn't have to spend 3-4 weeks to acquire the funds to purchase it.

Re: Obscura VPN – Privacy that's more than a promise

#155

Earlier quoted context omitted.

Timing attacks are notably not a part of Tor's threat model, i.e. they are a real concern: https://support.torproject.org/about/attacks-on-onion-routin...

hmm. that is interesting , would you mind sharing some solution , what if I add some insane latency (I know unusable but if it prevents timing attacks) my conspiracy spidey sense is sensing something fishy... Maybe timing attack is not part of .onion addresses ?

Mixnet would be a solution. Like what you described, have inbound packets held for some period of time and released as a group so that you cannot as easily correlate the inbound and outbound traffic.

The downside is that it gets much slower, and feels 'bad' as an end user. Each packet takes longer.

Re: Obscura VPN – Privacy that's more than a promise

#156

Earlier quoted context omitted.

Also I had read somewhere about a really strange conspiracy theory which really made me question if we can really be against government and big tech (since "lobbying" is made official) but if 5 eyes (the billionaires?) really wanted (heck only if UK + australia wanted , australia police is given the ability to remotely plant data in nation's interest and uk also is getting apple to force data to be leaked in the appl…

OK, story time. I have friend/old-coworker that left my current employer for our state's version of the FBI. While no worker in his agency handled CSAM cases full-time, they all have to do rotations. There is a lot he could not tell me about the work he did, and how they managed the detain suspects. But I do remember him telling me that he witnessed things that he thought were not even possible. Considering we were b…

Dude , I am not kidding , but this gave me so many goosebumps.

Goosebumps on my f'ing face.

And I was thinking this on 5 eyes level but you are saying a single country can do that?

When I had discovered that conspiracy theory which I now believe is true to some degree.

I then used to think, what if they want you to believe that you hold a chance. They don't want you to know they can get you as you are saying it. They want to give you the illusion of freedom. They will target their opposition , journalists with this if all goes south. There are also secret courts.

May I ask , if they can always get you why don't they use this in making their opposition go poof. If I am being extra conspiracist now , is it that they want you to give the freedom b/w 2 systems both of which don't change things really that much. Both political parties are kind of the same thing

but dude what the actual fuck.

They can use csam to break general encryption by saying it's bad for children etc, they can use csam to punish those they want.

I am now seriously wondering if I even have real tangible choice in the government.

I am now wondering if I am literally living in 1984. What if these wars and shit are just a distraction , yes they happen but...

Dude I have come to a realisation, I am seriously living in 1984. Reward is given to those who comply , those who aren't skeptics , skeptics are brushed off as conspiracist.

Re: Obscura VPN – Privacy that's more than a promise

#157

Earlier quoted context omitted.

You can't prove it. Apple isn't open source. And with the recent Debacle of Snooper's Law apple e2ee backdoor. Let me tell you something. A company is asked for a backdoor and they are forced to not tell anybody about it. The only reason why it was leaked was because of whistleblower. And so , who knows if they have already signed such thing with the NSA or UK already but for their mac's and other devices

Hell, I honestly believe the NSA does not need a backdoor anyway. They have some absolutely frightening people working for them. I believe some of the best of the best. I do not believe there is such thing as privacy from such organizations. If they want you bad enough, they will get you. Don't have a reason? They'll make one.

Snowden was right after all.

Re: Obscura VPN – Privacy that's more than a promise

#158

Earlier quoted context omitted.

Timing attacks are notably not a part of Tor's threat model, i.e. they are a real concern: https://support.torproject.org/about/attacks-on-onion-routin...

hmm. that is interesting , would you mind sharing some solution , what if I add some insane latency (I know unusable but if it prevents timing attacks) my conspiracy spidey sense is sensing something fishy... Maybe timing attack is not part of .onion addresses ?

The only solution I know of is essentially to do "bandwidth burning" where you inject a bunch of fake traffic as noise. I don't know how you'd do that within the constraints of this system.

Re: Obscura VPN – Privacy that's more than a promise

#159

Earlier quoted context omitted.

> somehow log & associate each decrypted IP packet against the users public key. Mullvad only needs to associate each decrypted IP packet against an assertion that the packet was paid for. I assume each Obscura node would have a public key, but not associated with a user. They notably offer this service for Tailscale (as an add-on) and I imagine that it works similarly (on the backend)

Yeah my thinking is even if they don’t have the users IP, knowing and seeing all the traffic associated with a specific public key would allow them to build a profile of the user. Eg based on the specific sites visited, payload sizes potentially, domains looked up, etc you’d be able to characterise the person. Especially so if anything they did was not encrypted, or they have their own vanity domain (for emails or an…

In Tor, individual websites get individual circuits to prevent this sort of profiling, and I think Obscura would need to do the same for the same level of anonymity.

Re: Obscura VPN – Privacy that's more than a promise

#160

Earlier quoted context omitted.

Hell, I honestly believe the NSA does not need a backdoor anyway. They have some absolutely frightening people working for them. I believe some of the best of the best. I do not believe there is such thing as privacy from such organizations. If they want you bad enough, they will get you. Don't have a reason? They'll make one.

Snowden was right after all.

Probably, but no telling.

Do you remember the "Heartbleed" exploit in SSL many years ago? There were allegations that the NSA knew about and used that exploit for many years before the public ever knew about. However, that is not exactly an easy statement to confirm nor deny.

Edit: I also wanted to add something I remember from a talk I saw with a person who once worked for the NSA. He was intentionally only talking about surface-level concepts, but he did mention that the one thing the NSA has, that most do not, is unlimited time and patience.

He said something along the lines of how they can just sit and watch a server, for example. Say that the server is on version 1.0.0 of whatever. Well, the NSA can find an exploit in version 1.1.0 and keep it under wraps. All they have to do is just wait. The second the server is upgraded to 1.1.0, then boom, they're in.

He also used the example of BYOD ("bring your own device") in workplace settings. Say they cannot can entry into somewhere. Well, if they can compromise someone's personal device, then they can just wait. The second the personal device connects to the network they want/is in close enough proximity to the network they want, then boom, they're in.

Be it one second, one hour, ... 10 years, etc.. They can wait. All it takes is one brief instance of a hole in the defense.

Truly some boogeyman level stuff, but I just hope they use their powers for good when possible. Though, I imagine plenty of other countries also have similar "arms race" abilities, which does complicate matters.

Some days, I just want to get a cabin in the woods, and get away from all this dystopian technology.

Post reply on HN