Remix.run Logo
skaul 7 hours ago

So two hops, basically. First hop sees your IP address but not the website you're going to, second hop sees website but not IP address. Similar to Private Relay: https://support.apple.com/en-us/102602.

dongcarl 6 hours ago | parent | next [-]

(Carl from Obscura here)

Yup, exactly!

skaul 3 hours ago | parent [-]

Cool work. Can I ask: why not use MASQUE for this, instead of WireGuard-over-QUIC? Is it because it meant less changes on your partner's side?

mulmen 6 hours ago | parent | prev [-]

But if both services keep logs de-anonymization is a join.

dongcarl 5 hours ago | parent | next [-]

(Carl from Obscura here)

Very true, but if even 1 of (Obscura, Mullvad) is honest, there's no de-anonymization.

For traditional Single-Party VPNs, you just need to compromise 1 party, with Two-Party Relays, you need to compromise both.

mulmen 13 minutes ago | parent [-]

You certainly think and know more about this than I do so thanks for taking the time. Would adding multiple VPN providers improve the safety of Obscura? Then a compromised VPN provider only exposes a fraction of the traffic. Does that create more risks? Did I just invent Tor but worse?

PunchyHamster 6 hours ago | parent | prev [-]

They don't even need to. If you observe enough of them you can correlate traffic patterns between them and find out which one is used by which endpoint