- cross-posted to:
- privacy@lemmy.ml
- cross-posted to:
- privacy@lemmy.ml
I’m sharing this one because I’m curious what more knowledgeable people think about this one. Please take a peek at the article before joining the discussion, as my limited quote might have dropped useful information
The VPN industry runs on a promise. Pick almost any provider and the pitch is the same: “we don’t keep logs.” You hand over your entire internet connection and, in return, you get a pinky-promise that nobody is writing anything down.
For a lot of privacy-minded people, that promise stopped being good enough a while ago. A no-logs policy is only as honest as the company making it, and even an honest company can be hacked, subpoenaed, or quietly acquired.
Obscura VPN is trying to answer to that problem. Instead of asking you to trust its word, it splits the job across two independent companies so that neither one can tie your identity to your browsing. The first hop is Obscura’s own servers; the exit hop is run by Mullvad. a respected VPM company out of Sweden. Your traffic is end-to-end encrypted to Mullvad’s keys, so Obscura literally can’t read it, and Mullvad never sees who you are.
“Mullvad”. The VPN company funding right wing politics in Sweden. No thank you
I think https://nym.com/ is also worth considering if you want something more secure than a VPN.
How in the heck can you pay for something like that with cash?! I looked in their FAQs, but I didn’t see if you just mailed them an envelope with 20s or what.
You got it. Snail mail stuffed with dough.
They work fine already but could be better. Open source and contact to the dev over PGP but they could have a public issuetracker or a semipublic read-only one or so.
Currently this is really just a companies thing, not legislations. If you live in frankfurt and choose frankfurt, your traffic will go through an obscura server in frankfurt and then a mullvad server in frankfurt. Not amazing if you want to make tracing harder by using servers in different countries.
Speeds are fine, the android client is reliable. LAN bypass works, no split tunneling is annoying though
In my opinion I don’t see adding another player as a useful step, especially when their selling point is “company trust.” Why trust two companies when you only need one? A good rule of thumb in cybersecurity is to minimize attack surface and going through two companies seems to add more unnecessary complexity and seems to require more trust, counter to their selling point.
Mullvad already collects next to nothing and if you pay with monero there’s almost no link to you, so I’m not sure why you wouldn’t just use Mullvad outright. Mullvad also has server multihop functionality if you want that specific feature too.
A good rule in cybersecurity is to minimize attack points yeah. But it should not be “optimize minimize” rather, “minimize where it will improve the current model of things” (“premature optimization is the root of all evil”). In this case, the digital surface attack of “2/1” is counterweighted with, essentially, reducing the financial / legal surface attack to “1/2”.
Well mullvad has multihop already with better control than obscura, but it is the same company.
I understand their multihop like that the second server accept all traffic from other mullvad servers without knowing your location, while the first has another wireguard layer so they cant see your traffic. Great and enough if you dont fear mullvad being coerced into changing their logging.
With obscura, mullvad accepts all traffic from obscura servers too, but the servers are operated by different legal entities.
This is made less useful by lower actual technical barriers. Like the servers could be in the same datacenter, while on Mullvad they could be in different countries!
Lots to improve for now but you gotta start somewhere
Eh, far safer to chain your own vpns. At least the you know tunnel A cannot see tunnel B’s traffic. Who’s to say if Obscura is correctly doing as they say, or just decrypting it and forwarding over another tunnel. You can’t verify that yourself.
You can do this on Linux but not on Android for example. And even on Linux it is not trivial. Mind to share a guide? I am curious
It works a little different on Android, but you can still chain OpenVPN, Wireguard, and TOR all at the same time, caveat is your apps have to support a proxy setting. Use firewall permit only localhost connections.
Or if you have a server somewhere, set that up to do the chaining and have your mobile connect to that.
Not OP, but I was curious too. There’s a guide that looks legit for running your own multi-hop wireguard: https://vpnlab.io/en/guides/multihop-wireguard-chain-setup-guide-50
And a more sketchy/AI looking python project: https://github.com/a904guy/VPN-Chainer





