Live data from Hacker News

Obscura VPN – Privacy that's more than a promise

obscura.net

1–10 of 170 posts

Re: Obscura VPN – Privacy that's more than a promise

#7
Interesting concept. The blog has a lot more details[1].

One comment/question about the exit nodes. Can someone correct or validate my thoughts:

It’s a WireGuard tunnel from the user to Mullvad, so while Obscura can’t see the user traffic, couldn’t the Mullvad exit node see the traffic, and using knowledge of the users WireGuard public key, associate all that users traffic with that key? So even if they can’t associate it with an IP, they could still potentially identify and track you.

This assumes they use a customised version of WireGuard to somehow log & associate each decrypted IP packet against the users public key.

1. https://obscura.net/blog/bootstrapping-trust/

Re: Obscura VPN – Privacy that's more than a promise

#8
post #6

This looks like two-hop Tor but I guess it's faster because you pay for it.

From the OP:

How does Obscura compare to Tor?

We have immense respect for the Tor project (and encourage you to support it), but its volunteer-run network can be slow and susceptible to DDoS issues, making it infeasible for everyday use.

Obscura uses two dedicated, high-performance hops for maximum speed and reliability – meaning you get many of Tor’s privacy benefits without sacrificing everyday usability.

Re: Obscura VPN – Privacy that's more than a promise

#9

Interesting concept. The blog has a lot more details[1]. One comment/question about the exit nodes. Can someone correct or validate my thoughts: It’s a WireGuard tunnel from the user to Mullvad, so while Obscura can’t see the user traffic, couldn’t the Mullvad exit node see the traffic, and using knowledge of the users WireGuard public key, associate all that users traffic with that key? So even if they can’t associa…

Also, Obscura can collect metadata on when you use the service, how much data you send/receive, etc.

Even if Mullvad doesn't do it, someone else might. Mullvad is, I expect, now a valuable target because it is the VPN service of choice for so many people concerned with security. Does Mullvad have the budget and expertise to protect itself against determined, highly-resourced attackers?

Finally, is it possible for a third party, intercepting traffic between Obscura and Mullvad, to identify the public key used to encrypt it? I don't think so - the only way to validate a signature is with both keys; that's kind of the point. But maybe there is an attack I'm unaware of?

Post reply on HN