| ▲ | maxloh 7 hours ago |
| I don't understand the point of this. Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura. Why should I choose this over Mullvad? |
|
| ▲ | maxloh 7 hours ago | parent | next [-] |
| Mullvad is a Swedish company, which has stricter privacy protection laws in place. According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user. The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company? [0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/ |
| |
| ▲ | dongcarl 5 hours ago | parent | next [-] | | (Carl from Obscura here) I love folks who are also reasoning through security models! A few things to note here: - We believe that all software running on a user's computer should be open source, so you can audit and build your own client: https://github.com/Sovereign-Engineering/obscuravpn-client - With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers). - The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely. | | |
| ▲ | maxloh 5 hours ago | parent [-] | | The "Obscura and Mullvad" argument actually makes sense. Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time. Another question: How does the Obscura client get the Mullvad exit server’s public key? Are they hardcoded at compile time, fetched from Mullvad's server, or fetched from Obscura's server? The latter seems to be dangerous if there isn't some kind of signature verification done on the client side before using the key. | | |
| ▲ | dongcarl 3 hours ago | parent [-] | | Good question! It's the latter right now (which is not ideal), but I think Mullvad is going to sign their server pubkeys pretty soon and we'll switch to that. We do currently show it in the app and there's an easily clickable link so you can verify against Mullvad's website for the pubkey |
|
| |
| ▲ | miohtama 6 hours ago | parent | prev | next [-] | | The EU is working to make what Mullvad is doing illegal. https://codamail.com/articles/privacy-law-directory/internat... "EU surveillance co-operation" | |
| ▲ | autoexec 5 hours ago | parent | prev | next [-] | | Yeah, it's basically not possible to offer an actually secure and private service in the US. If men with guns and gag orders haven't shown up at their new york office yet, they will as soon as this VPN gets popular enough to show up on their radar. At that point if they have any integrity they'll shut their service down like Lababit did rather than allow it to be compromised by the state. | |
| ▲ | NordStreamYacht an hour ago | parent | prev | next [-] | | Sweden was compromised years ago, Assange's case is proof. | |
| ▲ | ignoramous 6 hours ago | parent | prev [-] | | I wouldn't be so sure; Ex A: The terrifying expansion of Sweden’s state surveillance, https://edri.org/our-work/the-terrifying-expansion-of-sweden... |
|
|
| ▲ | dongcarl 6 hours ago | parent | prev | next [-] |
| We think Mullvad is a great privacy tool, which is why we partnered with them! As for what's different: We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays): https://www.privacyguides.org/articles/2024/11/17/where-are-... With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised. More on this here: https://obscura.com/#how Also, all our apps are open-source as well: https://github.com/Sovereign-Engineering/obscuravpn-client Disclaimer: I'm the creator of Obscura. |
| |
| ▲ | frizlab 6 hours ago | parent [-] | | How do you compare with iCloud Private Relay (with the obvious exception that private relay only works on macOS, and in specific apps only)? | | |
| ▲ | dongcarl 5 hours ago | parent [-] | | We're heavily inspired by them (see our original blog post which is a bit more technical here: https://obscura.com/blog/bootstrapping-trust/) The differences are: - We allow you to choose an exit location (I believe iCloud Private Relay restricts you to the same location) - Our exit hop is Mullvad instead of Cloudflare+Fastly+Akamai - We use QUIC for transport instead of HTTP/3 (which is built on QUIC and has a bit more overhead) | | |
| ▲ | Barbing 5 hours ago | parent [-] | | Same country at least - the iCloud Private Relay options, iOS: “1: Maintain general location 2: Use country and time zone Maintain your general location to receive localized content, or enhance your privacy by using a broader IP address based on your country and time zone. Safari Private Browsing always uses an IP location from your country and time zone.” |
|
|
|
|
| ▲ | bossyTeacher 6 hours ago | parent | prev [-] |
| Because its CEO is known as the sponsor of the Orebro party? 1.5k comments discussion for context: https://news.ycombinator.com/item?id=48717469 |
| |