Privacy first VPN. Two-party relay and no logs. No email needed. Block ads, trackers, malware. Available on iOS, macOS, Android, Windows, and Linux.

233 points•Flimm•8 days ago•140 comments•

140 comments

barathr8 days ago
As others have pointed out, this is like Apple iCloud Private Relay, and other multi-hop privacy systems that have been built on and off over the last several decades (Tor included).

We wrote a research paper on the general principle a few years ago: https://conferences.sigcomm.org/hotnets/2022/papers/hotnets2...

dang8 days ago
Discussed (just a bit) at the time:

The Decoupling Principle: A Practical Privacy Framework [pdf] - https://news.ycombinator.com/item?id=33897450 - Dec 2022 (3 comments)

Perhaps we should arrange a new thread about this?

barathr7 days ago
Happy to discuss further if it's of interest.
dongcarl8 days ago
Good to see you here Barath :-)

I didn't realize Chris Wood was also an author!

maxloh8 days ago
I don't understand the point of this.

Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.

Why should I choose this over Mullvad?

maxloh8 days ago
Mullvad is a Swedish company, which has stricter privacy protection laws in place.

According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.

The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?

[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/

dongcarl8 days ago
(Carl from Obscura here)

I love folks who are also reasoning through security models! A few things to note here:

- We believe that all software running on a user's computer should be open source, so you can audit and build your own client: https://github.com/Sovereign-Engineering/obscuravpn-client

- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).

- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.

miohtama8 days ago
The EU is working to make what Mullvad is doing illegal.

https://codamail.com/articles/privacy-law-directory/internat...

"EU surveillance co-operation"

ignoramous8 days ago
I wouldn't be so sure; Ex A: The terrifying expansion of Sweden’s state surveillance, https://edri.org/our-work/the-terrifying-expansion-of-sweden...
autoexec8 days ago
Yeah, it's basically not possible to offer an actually secure and private service in the US. If men with guns and gag orders haven't shown up at their new york office yet, they will as soon as this VPN gets popular enough to show up on their radar. At that point if they have any integrity they'll shut their service down like Lababit did rather than allow it to be compromised by the state.
NordStreamYacht8 days ago
Sweden was compromised years ago, Assange's case is proof.
dongcarl8 days ago
We think Mullvad is a great privacy tool, which is why we partnered with them!

As for what's different: We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays): https://www.privacyguides.org/articles/2024/11/17/where-are-...

With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised. More on this here: https://obscura.com/#how

Also, all our apps are open-source as well: https://github.com/Sovereign-Engineering/obscuravpn-client

Disclaimer: I'm the creator of Obscura.

frizlab8 days ago
How do you compare with iCloud Private Relay (with the obvious exception that private relay only works on macOS, and in specific apps only)?
LeoPanthera8 days ago
A lot of people are abandoning Mullvad because their CEO is directly funding a far-right political party.

As they should, IMHO.

KoolKat238 days ago
Purity politics, doesn't work sorry, just highlights hypocrisy.

I can't see how this has any bearing on the functioning of Mullvad, if they were campaigning on circumventing privacy rights it'd be a different story.

mephju8 days ago
That actually signals that the CEO has a legit reason for Mullvad to work really well.
duskdozer8 days ago
Do you know if there are other/general replacements for their browser extension that allows choosing a server/location per domain?
bossyTeacher8 days ago
Because its CEO is known as the sponsor of the Orebro party?

1.5k comments discussion for context: https://news.ycombinator.com/item?id=48717469

KoolKat238 days ago
I still don't see the relevance. Modern purity politics is silly. Is there a conflict of interest for Mullvad? If not, I don't see the issue.
omnimus8 days ago
That indeed can be a problem for many.
skaul8 days ago
So two hops, basically. First hop sees your IP address but not the website you're going to, second hop sees website but not IP address. Similar to Private Relay: https://support.apple.com/en-us/102602.
mulmen8 days ago
But if both services keep logs de-anonymization is a join.
dongcarl8 days ago
(Carl from Obscura here)

Very true, but if even 1 of (Obscura, Mullvad) is honest, there's no de-anonymization.

For traditional Single-Party VPNs, you just need to compromise 1 party, with Two-Party Relays, you need to compromise both.

PunchyHamster8 days ago
They don't even need to. If you observe enough of them you can correlate traffic patterns between them and find out which one is used by which endpoint
dongcarl8 days ago
(Carl from Obscura here)

Yup, exactly!

skaul8 days ago
Cool work. Can I ask: why not use MASQUE for this, instead of WireGuard-over-QUIC? Is it because it meant less changes on your partner's side?
john_strinlai8 days ago
i am very skeptical of most vpn companies, and while i haven't looked too hard at obscura, it is worth noting the official partnership with mullvad (https://mullvad.net/en/blog/mullvad-partnered-with-obscura-v...) which is certainly a positive signal

side note: i really wish more companies did the no email + randomized account number flow. there is a certain popular "pro-privacy" product beloved by many here that requires an email address and refuses to offer a similar account number method, which has turned me off the product.

dongcarl8 days ago
(Carl from Obscura here)

Yeah we thought the randomized account number flow was an ingenious idea, so we did that and made the last digit a Verhoeff checksum to check for mistypes!

Though sometimes people forget to write the number down and... There's not much we can do.

mulmen8 days ago
> there is a certain popular "pro-privacy" product beloved by many here

Please don’t speak in riddles. Just say what you mean.

t-writescode8 days ago
They’re almost certainly referencing Signal.
john_strinlai8 days ago
for what purpose? there is nothing to be gained from pointing fingers, and takes the discussion in an even more unrelated direction.

although i guess people's curiosity is also dragging my comment in an unrelated direction anyways. lose-lose situation.

my main point is that the account number method is really nice, and a great selling point for such privacy-conscious products. not offering it in a privacy-conscious product is enough signal that it has made me choose not to purchase the product. that's the important bit, and where i was hoping to drive the conversation.

ignoramous8 days ago
> ... a certain popular "pro-privacy" product beloved by many here ...

If you're talking about Proton VPN, they do support "credential-less accounts" through their official apps, I believe? At least, on Android since 2024: https://www.androidpolice.com/proton-vpn-works-without-accou...

john_strinlai8 days ago
i am hesitant to really narrow it down, but it is not proton (i am a very early proton customer)
ysnp7 days ago
I am a little surprised people jump to Proton as beloved by HN. Proton has a lot of detractors and tends to be a target of some conspiracy/controversy. HN darling definitely suggests Kagi, who are not significantly impressive in terms of privacy-tech which I assumed was why pro-privacy was in air quotes.
dustyharddrive8 days ago
In case you're alluding to a certain metasearch engine, they do not verify email addresses.
baal80spam8 days ago
privacy <> anonymity

Proton VPN ensures privacy.

water-drummer8 days ago
Privacy without anonymity is just privacy with a backdoor waiting to be unlocked.
john_strinlai8 days ago
i am not talking about proton.
osnxkwmxkwnd8 days ago
This sounds pretty neat, and I do dig the website, though I can’t help but think it’s an odd combination to have bitmap/pixelated fonts and graphics inside perfect squircles.

Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled with care. Right now it feels like the designer had a bunch of ideas and didn’t know how to bring them together in a cohesive identity.

Bonus point for the TRON reference at the end! “I fight for the users!”

dongcarl8 days ago
(Carl from Obscura here)

I'm a sucker for retro 8-bit graphics and fun mascots, so we went with that, but when we experimented with 8-bit for actual UI and long text we immediately found it to be super unusable and unreadable :-(

> Bonus point for the TRON reference at the end! “I fight for the users!”

Ah ofc the HN poster knows the reference :-) I've had it as my email signature since high school I think.

Read the full thread on Hacker News →

Related stories