conv.

All stories
TechActive · 34h

Obscura launches two-hop VPN designed so it can't see user traffic

A new VPN service claims architectural impossibility of logging by splitting identity and activity across separate operators.

What to know

  • Obscura claims architectural impossibility of logging by splitting identity (visible to Obscura) from traffic (visible only to Mullvad exit servers), accepting only randomized account numbers and cryptocurrency.
  • The two-hop relay design is not novel; technologists note similarities to Apple's iCloud Private Relay and decades of prior multi-hop systems, raising questions about competitive differentiation.
  • Key technical and trust concerns remain unresolved: whether the architecture actually prevents collusion between operators, whether QUIC obfuscation is effective against sophisticated censors, and whether cryptocurrency payment claims hold up against modern chain analysis.
  • Community consensus leans skeptical on whether Obscura offers meaningful privacy advantages over the more mature Mullvad (its partner), which is already open-source and operates the same exit infrastructure.

The dispute Whether the split-relay architecture actually prevents collusion between Obscura and Mullvad if both were compelled to cooperate, and whether it meaningfully improves on Mullvad alone. · positions read across 27 posts and comments

many voices

The design is sound in principle but not novel; users should just use Mullvad directly.

  • “I don't understand the point of this. Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product.”

    maxloh · Hacker News ↗
some voices

The Mullvad partnership and no-email signup are positive signals, but trust concerns exist around US jurisdiction.

  • “it is worth noting the official partnership with mullvad which is certainly a positive signal”

    john_strinlai · Hacker News ↗
some voices

Cryptocurrency payment privacy claims are misleading given modern chain analysis capabilities.

  • “No-KYC cryptocurrency is largely a thing of the past, and outfits like Chainanalysis can associate a Lightning or Monero address to a human with near-perfect accuracy. The fact that Obscura's FAQ doesn't acknowledge this makes me feel like…”

    MassPikeMike · Hacker News ↗

Obscura VPN service providerMullvad Exit hop operator and privacy-focused VPN partnerdongcarl Obscura team member

How it unfolded 5 developments, newest first · click a bar or a number to jump postscomments

Peak 6 pieces in one half hour at Sep 22, 4 PM; 28 pieces over 35 hours (1 post · 27 comments) Sep 22, 3:01 PM — quietSep 22, 3:31 PM — 3 pieces · 1 post · 2 comments — Hacker News 3Sep 22, 4:01 PM — 4 pieces · 4 comments — Hacker News 4Sep 22, 4:31 PM — 6 pieces · 6 comments — Hacker News 6Sep 22, 5:01 PM — quietSep 22, 5:31 PM — 2 pieces · 2 comments — Hacker News 2Sep 22, 6:01 PM — quietSep 22, 6:31 PM — 1 piece · 1 comment — Hacker News 1Sep 22, 7:01 PM — quietSep 22, 7:31 PM — quietSep 22, 8:01 PM — 1 piece · 1 comment — Hacker News 1Sep 22, 8:31 PM — quietSep 22, 9:01 PM — quietSep 22, 9:31 PM — 1 piece · 1 comment — Hacker News 1Sep 22, 10:01 PM — quietSep 22, 10:31 PM — 1 piece · 1 comment — Hacker News 1Sep 22, 11:01 PM — 1 piece · 1 comment — Hacker News 1Sep 22, 11:31 PM — quietYesterday, 12:01 AM — 2 pieces · 2 comments — Hacker News 2Yesterday, 12:31 AM — quietYesterday, 1:01 AM — quietYesterday, 1:31 AM — quietYesterday, 2:01 AM — quietYesterday, 2:31 AM — quietYesterday, 3:01 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 3:31 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 4:01 AM — quietYesterday, 4:31 AM — quietYesterday, 5:01 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 5:31 AM — quietYesterday, 6:01 AM — quietYesterday, 6:31 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 7:01 AM — quietYesterday, 7:31 AM — quietYesterday, 8:01 AM — quietYesterday, 8:31 AM — quietYesterday, 9:01 AM — quietYesterday, 9:31 AM — quietYesterday, 10:01 AM — quietYesterday, 10:31 AM — quietYesterday, 11:01 AM — quietYesterday, 11:31 AM — quietYesterday, 12:01 PM — quietYesterday, 12:31 PM — quietYesterday, 1:01 PM — quietYesterday, 1:31 PM — 1 piece · 1 comment — Hacker News 1Yesterday, 2:01 PM — quietYesterday, 2:31 PM — quietYesterday, 3:01 PM — quietYesterday, 3:31 PM — 1 piece · 1 comment — Hacker News 1Yesterday, 4:01 PM — quietYesterday, 4:31 PM — quietYesterday, 5:01 PM — quietYesterday, 5:31 PM — quietYesterday, 6:01 PM — quietYesterday, 6:31 PM — quietYesterday, 7:01 PM — quietYesterday, 7:31 PM — quietYesterday, 8:01 PM — quietYesterday, 8:31 PM — quietYesterday, 9:01 PM — quietYesterday, 9:31 PM — quietYesterday, 10:01 PM — quietYesterday, 10:31 PM — quietYesterday, 11:01 PM — quietYesterday, 11:31 PM — quietToday, 12:01 AM — quietToday, 12:31 AM — quietToday, 1:01 AM — quietToday, 1:31 AM — quiet 1–2345
4 PMyesterday8 AM4 PMnow · 2:01 AM ET
  1. 5

    Technical questions raised about exit hop anonymity

    Commenters asked how the exit server can route traffic without knowing the connecting IP address, and whether the architecture actually prevents both operators from correlating data if they cooperate.

    “How is this possible? If the exit server doesn't know your IP, how does it know where to send the traffic?”
    — Wowfunhappy
    • I hate to be the one to throw stones at an outfit that is trying to do something good, protecting people's privacy.But the claim in Obscura's FAQ that paying with Bitcoin or Monero offers more privacy than paying with a credit card is sadly misguided. No-KYC cryptocurrency is largely a thing of the past, and outfits like Chainanalysis can…

      MassPikeMikeHacker News1d agoview on Hacker News ↗
    2 more of the top 3 · 10 posts in this stretch
    • With a name like this, I’m reminded that privacy is only as good as your entry node being used widely/not being too “obscure.”https://www.wnycstudios.org/podcasts/otm/articles/harvard-bo... is a good example: because the person making the threat was one of the few people on the campus network using Tor at the time the threatening emails were sent…

      btownHacker News12h agoview on Hacker News ↗
    • It would be cool if there were a way to use it the other way around. A Mullvad server as the entry point and an Obscura server as the exit point. My main problem with Mullvad right now is that its servers are blocked almost everywhere or generate an excessive number of Captchas. With other VPNs, that’s been much less of an issue so far…

      RandomGerm4nHacker News22h agoview on Hacker News ↗
    all of them →
  2. 4

    Skepticism over cryptocurrency payment privacy claims

    MassPikeMike raised concerns that Obscura's marketing of Bitcoin Lightning and Monero as privacy-superior to credit cards is outdated, noting that chain analysis firms can now associate cryptocurrency addresses to individuals with high accuracy.

    “No-KYC cryptocurrency is largely a thing of the past, and outfits like Chainanalysis can associate a Lightning or Monero address to a human with near-perfect accuracy.”
    — MassPikeMike
    • I hope MPTCP would be more popularMany src-dst connections but as a single logical connection. There's no way any middlebox could easy capture full data even metadata.http2/QUIC can do something similar with frames (and hopefully multipath)Don't place your whole stream inside a single src-dst IP connection. Demux them into many paths over the…

      estHacker News1d agoview on Hacker News ↗
    1 more of the top 2 · 2 posts in this stretch
    • Discussed (just a bit) at the time:The Decoupling Principle: A Practical Privacy Framework [pdf] - https://news.ycombinator.com/item?id=33897450 - Dec 2022 (3 comments)Perhaps we should arrange a new thread about this?

      dangHacker News1d agoview on Hacker News ↗
    all of them →
  3. 3

    Obscura co-founder clarifies multi-party relay architecture

    In response to comparisons with Mullvad, dongcarl (an Obscura team member) explained the distinction as a Multi-Party Relays system where no single entity can be trusted to remain uncompromised, contrasting with traditional single-party VPNs.

    “We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays)… With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised.”
    — dongcarl
    • We think Mullvad is a great privacy tool, which is why we partnered with them!As for what's different: We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays): https://www.privacyguides.org/articles/2024/11/17/where-are-...With Multi-Party Relays you no longer have a trust a single entity not being malicious or…

      dongcarlHacker News1d agoview on Hacker News ↗
    2 more of the top 3 · 9 posts in this stretch
    • As others have pointed out, this is like Apple iCloud Private Relay, and other multi-hop privacy systems that have been built on and off over the last several decades (Tor included).We wrote a research paper on the general principle a few years ago:

      barathrHacker News1d agoview on Hacker News ↗
    • > the first VPN that can’t log your activity and outsmarts internet censorship.I guess they never heard of Zero Knowledge Systems:

      wahernHacker News1d agoview on Hacker News ↗
    all of them →
  4. 2

    Community questions the novelty and trust model

    Hacker News commenters noted that the two-hop relay design resembles Apple's iCloud Private Relay and prior multi-hop systems, and questioned why users should trust a US-based company over the Swedish Mullvad partner.

    “This is like Apple iCloud Private Relay, and other multi-hop privacy systems that have been built on and off over the last several decades.”
    — barathr
    • Mullvad is a Swedish company, which has stricter privacy protection laws in place.According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.The only scenario where Obscura…

      maxlohHacker News1d agoview on Hacker News ↗
    2 more of the top 3 · 6 posts in this stretch
    • i am very skeptical of most vpn companies, and while i haven't looked too hard at obscura, it is worth noting the official partnership with mullvad (https://mullvad.net/en/blog/mullvad-partnered-with-obscura-v...) which is certainly a positive signalside note: i really wish more companies did the no email + randomized account number flow. there is…

      john_strinlaiHacker News1d agoview on Hacker News ↗
    • This sounds pretty neat, and I do dig the website, though I can’t help but think it’s an odd combination to have bitmap/pixelated fonts and graphics inside perfect squircles.Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled…

      osnxkwmxkwndHacker News1d agoview on Hacker News ↗
    all of them →
  5. 1

    Obscura launches multi-hop VPN with claimed logging impossibility

    Obscura announced a VPN service using a split-relay architecture where Obscura's servers cannot decrypt user traffic and Mullvad exit servers cannot see user identity. The service requires only a randomized account number, accepts Bitcoin Lightning and Monero, and uses QUIC-based obfuscation to evade network filters.

    “Obscura is built such that we can't see your traffic in the first place.”
    — Obscura

What people are saying 13 voices from 1 site · best of 27 · verbatim

Still unanswered
  • If the exit server doesn't know the user's IP, how does it route traffic back to them?
  • Can Obscura and Mullvad simply correlate their respective logs on demand to defeat the architectural separation?
  • Is QUIC-based obfuscation actually effective against sophisticated state-level censors?