// ITS FOSS — LINUX & OPEN SOURCE
We View Consumer Data as Toxic Waste
The VPN industry runs on a promise. Pick almost any provider and the pitch is the same: "we don't keep logs." You hand over your entire internet connection and, in return, you get a pinky-promise that nobody is writing anything down.
For a lot of privacy-minded people, that promise stopped being good enough a while ago. A no-logs policy is only as honest as the company making it, and even an honest company can be hacked, subpoenaed, or quietly acquired.
Obscura VPN is trying to answer to that problem. Instead of asking you to trust its word, it splits the job across two independent companies so that neither one can tie your identity to your browsing. The first hop is Obscura's own servers; the exit hop is run by Mullvad. a respected VPM company out of Sweden. Your traffic is end-to-end encrypted to Mullvad's keys, so Obscura literally can't read it, and Mullvad never sees who you are.
The person behind it is Carl Dong, a former top-5 Bitcoin Core contributor who signs off his own website as "head-janitor" and "I fight for the users." I sent him a set of questions around Obscura. Here's the conversation.
"Don't Trust, Verify" is a cornerstone of the cypherpunk principles I grew up with. I see this Trust Minimization as crucial when building human-centric, security- and privacy-critical technologies. Yet the VPN industry is riddled with scandals (e.g., Onavo), broken promises, and "no-log" pinky promises. This never sat right with me.
When I saw what Apple's iCloud Private Relay was doing under the hood, I saw what the next generation of VPNs would look like: VPNs that are verifiably private and that outsmart internet censorship. I wanted to make this a reality outside of Apple's walled garden. The world doesn't need another VPN company; it needs a totally new approach to privacy.
The VPN industry is living in the past. Three conglomerates dominate and give the illusion of choice, while betraying their users' trust and operating a payola scheme using media cut-outs to push their talking points. The no-logs pinky-promise has never been adequate for software that can access the entirety of your internet traffic, and verges on being useless in 2026 when LLM-driven cyberattacks run rampant.
At the end of the day, even honest VPN providers who abide by their no-logs policy can be hacked. Users are waking up to this, and there's been an increasing call within the cybersecurity community to stop using VPNs altogether. Obscura is a direct answer to this: you no longer have to trust any single company's word for your internet privacy. That's the way it should have always been.
When you use a traditional VPN, a single company sees your identity (via your connecting IP + your payment information) and your internet traffic. Using a multi-hop option doesn't change the fact that it's still a single company, and oftentimes just adds additional latency for no good reason.
With Obscura's Two-Party Relay, we use a fully independent company (Mullvad) as our second exit hop, with Obscura as the first hop. All of your internet traffic is encrypted to a key controlled by Mullvad's servers, and only relayed through Obscura's servers. That way, Obscura's relay servers never see your actual internet traffic, and Mullvad's exit servers never see your identity (connecting IP or payment information).