| ▲ | skaul 7 hours ago |
| So two hops, basically. First hop sees your IP address but not the website you're going to, second hop sees website but not IP address. Similar to Private Relay: https://support.apple.com/en-us/102602. |
|
| ▲ | dongcarl 6 hours ago | parent | next [-] |
| (Carl from Obscura here) Yup, exactly! |
| |
| ▲ | skaul 3 hours ago | parent [-] | | Cool work. Can I ask: why not use MASQUE for this, instead of WireGuard-over-QUIC? Is it because it meant less changes on your partner's side? |
|
|
| ▲ | mulmen 6 hours ago | parent | prev [-] |
| But if both services keep logs de-anonymization is a join. |
| |
| ▲ | dongcarl 5 hours ago | parent | next [-] | | (Carl from Obscura here) Very true, but if even 1 of (Obscura, Mullvad) is honest, there's no de-anonymization. For traditional Single-Party VPNs, you just need to compromise 1 party, with Two-Party Relays, you need to compromise both. | | |
| ▲ | mulmen 13 minutes ago | parent [-] | | You certainly think and know more about this than I do so thanks for taking the time. Would adding multiple VPN providers improve the safety of Obscura? Then a compromised VPN provider only exposes a fraction of the traffic. Does that create more risks? Did I just invent Tor but worse? |
| |
| ▲ | PunchyHamster 6 hours ago | parent | prev [-] | | They don't even need to. If you observe enough of them you can correlate traffic patterns between them and find out which one is used by which endpoint |
|