4 ms·
I'm not clear on the technical details here. > Obscura’s servers relay your connection to exit servers but can never decrypt your traffic. Doesn't that rely o
by Reubend 2y ago
I'm not clear on the technical details here.
> Obscura’s servers relay your connection to exit servers but can never decrypt your traffic.
Doesn't that rely on us trusting that the server runs the code they claim it does? Or is there a way to prove that their server can't get the decryption key (i.e. by proving that it's not possible for them to switch the final hop, or add undisclosed hops in between)?
- prophesi 2y agoThe client is open source, and I believe the E2E encryption is done when the client creates a new Wireguard tunnel. At least, that's what I'm seeing here[0]. Still poring over the code. [0] https://github.com/Sovereign-Engineering/obscuravpn-client/blob/main/src/quicwg.rs https://github.com/Sovereign-Engineering/obscuravpn-client/b...
- dongcarl 2y ago(Carl from Obscura here) Here's what [one of our FAQ entries](https://obscura.net/#faq-trust https://obscura.net/#faq-trust) say: > Additionally, our app displays your current exit hop’s WireGuard public key on its “Location” page. You can check this key against what Mullvad publishes [here](https://mullvad.net/servers https://mullvad.net/servers) to ensure that you’re connected via a genuine Mullvad exit hop! Let me know if that's unclear!
- Reubend 2y agoThat makes sense. Thanks for explaining!