Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. GPT-6 Sol and Luna(openai.com)
    432comments
  2. Claude Opus 5.5(anthropic.com)
    656comments
  3. OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005(cryptocellar.org)
    340comments
  4. 'We hacked the FBI:' Hackers say they have data on all FBI employees(404media.co)
    53comments
  5. SAML: A Fractal of Bad Design(trailofbits.com)
    26comments
  6. Claude Opus 5.5 Intelligence, Performance and Price Analysis (Max)(artificialanalysis.ai)
    49comments
  7. WordPress: Unauthenticated path traversal leading to conditional RCE(github.com/wordpress)
    56comments
  8. What California is learning from solar panels built over irrigation canals(kqed.org)
    16comments
  9. Native apps written in TypeScript and CSS(github.com/geastack)
    7comments
  10. Did OpenAI solve the wrong Navier-Stokes problem?(scientificamerican.com)
    13comments
  11. OpenAI is well positioned to fast-follow Jev(arcturus-labs.com)
    166comments
  12. Unreal Agent(unreallabs.ai)
    42comments
  13. MUNI Heritage Weekend in San Francisco(lawrence.lu)
    30comments
  14. An update on how we confirm your age group on Discord(discord.com)
    7comments
  15. Show HN: JevBench, a reproducible benchmark for typed decision models(benchmarkheaven.com)
    1comments
  16. Markdown in /src(htmx.org)
    14comments
  17. How did AMD Ryzen get 50% faster in two years?(lemire.me)
    24comments
  18. Show HN: Training a model to identify AI web content from structure alone(arxiv.org)
    4comments
  19. 16-bit Intel 8088 chip (c. 1985)(allpoetry.com)
    12comments
  20. A Faster Shortest Path Algorithm(vals.ai)
    4comments
  21. Overreliance on AI contributed to missile strike on Iran school – Pentagon(bloomberg.com)
    117comments
  22. Launch HN: Coverage Cat (YC S22) – Umbrella insurance via your personal agent(coveragecat.com)
    19comments
  23. George Lucas Returns to Earth, Bearing Gifts(commonedge.org)
    17comments
  24. There's a high chance of devices being sold with GrapheneOS preinstalled in 2027(grapheneos.social)
    87comments
  25. The JavaScript Midlife Crisis(maroun-baydoun.com)
    5comments
  26. Apple has added persistent 'ads' to iOS, and it's driving users crazy(techradar.com)
    390comments
  27. People hooked on vapes try a new way to quit: cigarettes(bloomberg.com)
    42comments
  28. Writing Rust code that's fast by asking agents to make the code faster(minimaxir.com)
    46comments
  29. Solitaire Alone Together(solitairealonetogether.com)
    29comments
  30. Porsche puts wireless EV charging into production(electrek.co)
    52comments

Obscura: The first VPN that can't log your activity

37 pointsby 1h agoobscura.com
43 comments
1h agoHN ↗

This sounds pretty neat, and I do dig the website, though I can’t help but think it’s an odd combination to have bitmap/pixelated fonts and graphics inside perfect squircles.

Seems like you guys have two distinct ideas of a visual identity completely at odds there. Shape contrast is nice and can be rather fun to play with, but it has to be handled with care. Right now it feels like the designer had a bunch of ideas and didn’t know how to bring them together in a cohesive identity.

Bonus point for the TRON reference at the end! “I fight for the users!”

1h agoHN ↗

i am very skeptical of most vpn companies, and while i haven't looked too hard at obscura, it is worth noting the official partnership with mullvad (https://mullvad.net/en/blog/mullvad-partnered-with-obscura-v...) which is certainly a positive signal

side note: i really wish more companies did the no email + randomized account number flow. there is a certain popular "pro-privacy" product beloved by many here that requires an email address and refuses to offer a similar account number method, which has turned me off the product.

39m agoHN ↗

there is a certain popular "pro-privacy" product beloved by many here

Please don’t speak in riddles. Just say what you mean.

28m agoHN ↗

for what purpose? there is nothing to be gained from pointing fingers, and takes the discussion in an even more unrelated direction.

although i guess people's curiosity is also dragging my comment in an unrelated direction anyways. lose-lose situation.

my main point is that the account number method is really nice, and a great selling point for such privacy-conscious products. not offering it in a privacy-conscious product is enough signal that it has made me choose not to purchase the product. that's the important bit, and where i was hoping to drive the conversation.

22m agoHN ↗

Because it creates confusion as proven by the responses mistakenly assuming that you were referring to proton.

12m agoHN ↗

and if i mention the company, the responses are all about the company instead of the feature.

next time i will just keep my thoughts to myself and we'll all be happy.

19m agoHN ↗

Incorrect. Pointing out bad products is a warning to other people to not waste time on it. We should be doing it more, not less.

I also have no idea what company/service you're talking about

10m agoHN ↗

There is even less to be gained by issuing vague unactionable warnings and/or accusations...

8m agoHN ↗

it's not a warning or accusation...

this isn't some hidden feature you get caught with your pants down over. if you try to sign up to something and it doesn't offer an account number, you know that it doesn't offer an account number instantly.

no time wasted for you. it's not some nefarious plot by the company.

it's just a business decision. i was hoping to talk about the business decision of that particular sign up flow.

12m agoHN ↗

They’re almost certainly referencing Signal.

31m agoHN ↗

i am hesitant to really narrow it down, but it is not proton (i am a very early proton customer)

30m agoHN ↗

Then why comment at all? This is the danger of speaking in riddles.

33m agoHN ↗

privacy <> anonymity

Proton VPN ensures privacy.

29m agoHN ↗

Privacy without anonymity is just privacy with a backdoor waiting to be unlocked.

59m agoHN ↗

Basically a middle-man for a Mullvad VPN, where if Mullvad decides to pull out of their agreement with this company, you lose your connection and are hopefully refunded.

The single point of failure for this product is Mullvad and its leadership's changing opinions.

58m agoHN ↗

I don't understand the point of this.

Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.

Why should I choose this over Mullvad?

46m agoHN ↗

Mullvad is a Swedish company, which has stricter privacy protection laws in place.

According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.

The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?

[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/

4m agoHN ↗

We think Mullvad is a great privacy tool, which is why we partnered with them!

As for what's different: We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays): https://www.privacyguides.org/articles/2024/11/17/where-are-...

With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised. More on this here: https://obscura.com/#how

Also, all our apps are open-source as well: https://github.com/Sovereign-Engineering/obscuravpn-client

Disclaimer: I'm the creator of Obscura.

57m agoHN ↗

I love the website, messaging and idea. Well done. if you guys need a place to host, please consider controlplane.com

50m agoHN ↗

How does this prove Obscura and Mullvad can't just both gather tracking data and then just combine it on demand?

48m agoHN ↗

and how is it better than just connecting to mullvad over nordvpn or something?

31m agoHN ↗

If you're already a Tailscale user, seems like this solution is nearly identical to using Mullvad as an exit node.

You would go with this solution if you don't trust Tailscale or NordVPN, I guess.

48m agoHN ↗

I don't like 'us vs others' kinda comparisons, it's just marketing trick, which means they care more about sales than your privacy.

Secondly, Mullvad did what Obscura does now years ago.

Furthermore who needs a gamified VPN tool?

46m agoHN ↗

So like OHTTP but for UDP traffic? I suppose they are using MASQUE CONNECT-UDP?

They are careful to not exactly claim the same anonymity properties of Tor, though I think a lay reader will read that differently (ie, that they do have the same anonymity property as Tor).

That said being able to verify the inner wireguard conn to mullvad is nice. Of course you have to trust them that they aren't colluding with mullvad to share your identity/ip. But same goes for OHTTP.

45m agoHN ↗

Your traffic is still unencrypted by the VPN provider at the other end of the Wireguard connection, I am not sure how this changes that?

34m agoHN ↗

But if both services keep logs de-anonymization is a join.

18m agoHN ↗

They don't even need to. If you observe enough of them you can correlate traffic patterns between them and find out which one is used by which endpoint

22m agoHN ↗

Good to see you here Barath :-)

I didn't realize Chris Wood was also an author!

17m agoHN ↗

a vpn company is a paid for MITM attack surface.

13m agoHN ↗

It’s often ‘impossible’ and until it happens /s

3m agoHN ↗

Carl from Obscura here

Happy to answer any questions y’all might have!