<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: dongcarl</title><link>https://news.ycombinator.com/user?id=dongcarl</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 27 Sep 2026 10:03:02 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=dongcarl" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>> <a href="https://obscura.com/check/" rel="nofollow">https://obscura.com/check/</a> does this page know the difference between a direct mullvad user and an obscura user, if so, how?<p>We don't actually, try visiting it with Mullvad turned on!<p>> Packet padding but no docs about this?<p>Yeah it's an experimental feature, we're not 100% happy about how we implemented it so we've left it experimental and are working on a v2.</p>
]]></description><pubDate>Wed, 23 Sep 2026 03:50:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=49811437</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49811437</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49811437</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>Yeah it'd be a cool addition to combat internet surveillance but in practicality it may have a lot of problems:<p>1. Deteriorated performance if it's across unequal links (3G vs. Fibre WiFi)<p>2. Many countries have single exits to the global internet so they'd be able to assemble everything there<p>3. The most important plaintext data is probably in the TLS SNI which usually sits in a single packet for TLS in HTTP/3</p>
]]></description><pubDate>Wed, 23 Sep 2026 03:49:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=49811427</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49811427</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49811427</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>Basically:<p>Your device <-> Obscura Relay <-> Mullvad Exit <-> Internet<p>So the exit server knows the IP of the Obscura Relay, but never sees your device's IP, lmk if that's clear!</p>
]]></description><pubDate>Wed, 23 Sep 2026 03:43:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=49811395</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49811395</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49811395</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>Yup! Mostly less changes on Mullvad's side. Also QUIC has less overhead than MASQUE by definition.</p>
]]></description><pubDate>Wed, 23 Sep 2026 03:42:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=49811384</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49811384</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49811384</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>Good question! It's the latter right now (which is not ideal), but I think Mullvad is going to sign their server pubkeys pretty soon and we'll switch to that.<p>We do currently show it in the app and there's an easily clickable link so you can verify against Mullvad's website for the pubkey</p>
]]></description><pubDate>Tue, 22 Sep 2026 23:57:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49809877</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49809877</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49809877</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>I believe if your device connects directly to Mullvad they will have your real IP (to know where to send reply packets)</p>
]]></description><pubDate>Tue, 22 Sep 2026 21:41:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808541</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808541</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808541</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>I love folks who are also reasoning through security models! A few things to note here:<p>- We believe that all software running on a user's computer should be open source, so you can audit and build your own client: <a href="https://github.com/Sovereign-Engineering/obscuravpn-client" rel="nofollow">https://github.com/Sovereign-Engineering/obscuravpn-client</a><p>- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).<p>- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.</p>
]]></description><pubDate>Tue, 22 Sep 2026 21:33:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808439</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808439</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808439</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>I totally agree for traditional Single-Party VPNs, which is why we are a Two-Party Relay. More here: <a href="https://obscura.com/blog/bootstrapping-trust/" rel="nofollow">https://obscura.com/blog/bootstrapping-trust/</a></p>
]]></description><pubDate>Tue, 22 Sep 2026 21:25:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808334</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808334</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808334</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>Very true, but if even 1 of (Obscura, Mullvad) is honest, there's no de-anonymization.<p>For traditional Single-Party VPNs, you just need to compromise 1 party, with Two-Party Relays, you need to compromise both.</p>
]]></description><pubDate>Tue, 22 Sep 2026 21:24:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808315</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808315</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808315</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>We're heavily inspired by them (see our original blog post which is a bit more technical here: <a href="https://obscura.com/blog/bootstrapping-trust/" rel="nofollow">https://obscura.com/blog/bootstrapping-trust/</a>)<p>The differences are:<p>- We allow you to choose an exit location (I believe iCloud Private Relay restricts you to the same location)<p>- Our exit hop is Mullvad instead of Cloudflare+Fastly+Akamai<p>- We use QUIC for transport instead of HTTP/3 (which is built on QUIC and has a bit more overhead)</p>
]]></description><pubDate>Tue, 22 Sep 2026 21:21:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808279</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808279</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808279</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>I could be wrong but in Tailscale if you use Mullvad as an exit node, the traffic flows directly from your device to Mullvad's servers.<p>Whereas with Obscura, your traffic flows to the Obscura relay, then the Mullvad exit.</p>
]]></description><pubDate>Tue, 22 Sep 2026 21:18:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808247</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808247</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808247</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: The first VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>Other than the obvious hassle? XP<p>If you connect to Mullvad over NordVPN:<p>- You're giving both Mullvad and Nord some payment information (with Obscura you only give that to us, Mullvad has no idea)<p>- You don't get our QUIC-based obfuscation (see more here: <a href="https://obscura.com/blog/bootstrapping-trust/" rel="nofollow">https://obscura.com/blog/bootstrapping-trust/</a>)</p>
]]></description><pubDate>Tue, 22 Sep 2026 21:16:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808231</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808231</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808231</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>This doesn't prove it. However, Obscura makes it so that there's no *single party* that if hacked or otherwise compromised would hurt your internet privacy.</p>
]]></description><pubDate>Tue, 22 Sep 2026 21:14:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808204</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808204</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808204</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>Can't speak to Iran, but we use QUIC for transport (with an experimental TCP/TLS mode).<p>I believe QUIC has been harder to block for censors, esp with Chaos Protection on by default in Chrome. See: <a href="https://gfw.report/publications/usenixsecurity25/en/" rel="nofollow">https://gfw.report/publications/usenixsecurity25/en/</a></p>
]]></description><pubDate>Tue, 22 Sep 2026 21:11:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808172</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808172</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808172</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>Actually it's WireGuard over QUIC Unreliable Datagrams!<p>See: <a href="https://obscura.com/blog/bootstrapping-trust/" rel="nofollow">https://obscura.com/blog/bootstrapping-trust/</a></p>
]]></description><pubDate>Tue, 22 Sep 2026 21:07:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808115</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808115</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808115</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>I'm a sucker for retro 8-bit graphics and fun mascots, so we went with that, but when we experimented with  8-bit for actual UI and long text we immediately found it to be super unusable and unreadable :-(<p>> Bonus point for the TRON reference at the end! “I fight for the users!”<p>Ah ofc the HN poster knows the reference :-) I've had it as my email signature since high school I think.</p>
]]></description><pubDate>Tue, 22 Sep 2026 21:06:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808102</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808102</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808102</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>(Carl from Obscura here)<p>Yeah we thought the randomized account number flow was an ingenious idea, so we did that and made the last digit a Verhoeff checksum to check for mistypes!<p>Though sometimes people forget to write the number down and... There's not much we can do.</p>
]]></description><pubDate>Tue, 22 Sep 2026 21:00:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49808027</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49808027</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49808027</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>Carl from Obscura here<p>Happy to answer any questions y’all might have!<p>Also, the technical folks may be more interested in our original post: <a href="https://obscura.com/blog/bootstrapping-trust/" rel="nofollow">https://obscura.com/blog/bootstrapping-trust/</a></p>
]]></description><pubDate>Tue, 22 Sep 2026 20:57:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=49807977</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49807977</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49807977</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>We think Mullvad is a great privacy tool, which is why we partnered with them!<p>As for what's different: We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays): <a href="https://www.privacyguides.org/articles/2024/11/17/where-are-all-the-mprs/#a-solution-multi-party-relays" rel="nofollow">https://www.privacyguides.org/articles/2024/11/17/where-are-...</a><p>With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised. More on this here: <a href="https://obscura.com/#how" rel="nofollow">https://obscura.com/#how</a><p>Also, all our apps are open-source as well: <a href="https://github.com/Sovereign-Engineering/obscuravpn-client" rel="nofollow">https://github.com/Sovereign-Engineering/obscuravpn-client</a><p>Disclaimer: I'm the creator of Obscura.</p>
]]></description><pubDate>Tue, 22 Sep 2026 20:56:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49807969</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49807969</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49807969</guid></item><item><title><![CDATA[New comment by dongcarl in "Obscura: VPN that can't log your activity"]]></title><description><![CDATA[
<p>Good to see you here Barath :-)<p>I didn't realize Chris Wood was also an author!</p>
]]></description><pubDate>Tue, 22 Sep 2026 20:39:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=49807743</link><dc:creator>dongcarl</dc:creator><comments>https://news.ycombinator.com/item?id=49807743</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49807743</guid></item></channel></rss>