TFTC: A Bitcoin Podcast - #584: The VPN That Can't Track You with Carl Dong
Episode Date: February 11, 2025Marty sits down with Carl Dong to discuss the launch of Obscura. Carl on Twitter: https://x.com/carl_dong Obscura VPN: https://obscura.net/ 0:00 - Intro 0:36 - Solving private VPN payments 5:48 - Expl...aining VPN hops 12:39 - Fold & Bitkey 14:34 - Censorship game theory 22:13 - VPNs more usable in restricted environs 27:10 - New generation of trustless VPNs 36:59 - User data is a toxic liability 41:16 - New possibilities for internet freedom 50:27 - Obscura's long term vision Shoutout to our sponsors: Fold https://foldapp.com/marty/ Bitkey https://bitkey.world/ Unchained https://unchained.com/tftc/ Join the TFTC Movement: Main YT Channel https://www.youtube.com/c/TFTC21/videos Clips YT Channel https://www.youtube.com/channel/UCUQcW3jxfQfEUS8kqR5pJtQ Website https://tftc.io/ Twitter https://twitter.com/tftc21 Instagram https://www.instagram.com/tftc.io/ Nostr https://primal.net/tftc Follow Marty Bent: Twitter https://twitter.com/martybent Nostr https://primal.net/martybent Newsletter https://tftc.io/martys-bent/ Podcast https://www.tftc.io/tag/podcasts/
Transcript
Discussion (0)
You've had a dynamic where money's become freer than free.
When you talk about a Fed just gone nuts, all the central banks going nuts.
So it's all acting like safe haven.
I believe that in a world where central bankers are tripping over themselves to devalue their currency, Bitcoin wins.
In the world of fiat currencies, Bitcoin is the victor.
I mean, that's part of the bull case for Bitcoin.
If you're not paying attention, you probably should be.
Carl Dong, welcome back to the show.
Glad to be here, Marty.
It's fantastic to be back.
Yeah, last time was back in New York in Williamsburg, right?
That was a long time ago.
I remember you brought some brews in and we had a little beer.
It was great.
talking about uh reproducible builds on bitcoin and geeks a project that you worked on for for
quite some time thank you for that of course of course i mean it was it was a pleasure i mean
everything i'm very lucky that everything i work on is like an obsession of mine you know so it
really doesn't feel like hard work at all it just feels like i am chasing this rabbit hole that i
would have otherwise um been chasing it anyway so yeah well you've been uh working on something
else which we're here to talk about today obscura yeah pn which no 100 i mean um it's been a it's
been a wild wild ride i think we announced it um around the end of last year well i guess we're in
2025 now, so the end of 2023. And I've been working on it since then. It's sort of been an
idea that's been ruminating at the back of my head. I don't know. Well, the audience probably
doesn't know. I lived when I was a kid back in London for a few years. And then I moved back to
Shanghai with my parents. And that's sort of when the Great Firewall came up, all that blocking of
Google and Wikipedia and YouTube and everything.
So I've been using VPNs and like building it out and, and testing
different protocols since I was a kid.
So it's always been at the back of my head that like, okay, like these
protocols probably need a refresh, like the tooling probably needs a refresh.
Um, and so that, I guess that all culminated in that I'm happy to sort
of go into more of a, what Obscura is and everything else.
yeah because i think before you announced subskira in late 2023 you had written
a script or a library that made it very easy to top up mulvad subscriptions with lightning
yeah correct was it mulvad or ivpn no exactly it was it was exactly mulvad um i think this was
back in 2020 this was one of our one of my like you know pandemic weekend projects i want to say
And it was really great because, you know, at the time, and this sort of speaks to how, you know, visionary Molvad was and still is, you know, I had just not seen a VPN company that did what they did, which was do the anonymous user number thing, right?
that that was that was ingenious like why do you you really just need me to pay right i get that
right like you know you need to run your servers and whatever you just need to get me to pay why
do you need my email address like you know just generate a random number i perfectly i'm an adult
i'm perfectly able to keep a random number somewhere safely um and then pay using bitcoin
or whatever um and then i have my vpn like that that is like sort of the perfect flow and it was
one of those moments where i was like okay actually um vpns are sort of one of the perfect
things uh for for you to pay with bitcoin for right because like that payment information is
basically the only part of the personally identify information that they have about you
So you want it to be somewhat pseudonymous, somewhat unstoppable, and things like that. And I was like, okay, they don't accept Lightning yet. Because, you know, integrating Lightning back then as a vendor was, you know, still quite a pain. And so I was like, you know what, I'm just gonna, I just literally emailed. I don't know if it was their supporter, I directly emailed their CTO.
but but but i got got got through to them and the guy was like let's email over pgp encrypted email
and then we got this deal done where i was able to like buy their vouchers and resell them for
lightning and that was that was a great experience it was just like a weekend python script that i
wrote it was uh really fun yeah that was fun and again go back to privacy like you're using vpn
why do you want to use it for privacy as you're perusing the internet and that
payment historically,
whether it was via credit card or debit card is a leaky hole in,
in the boat of privacy, which can, which can get back to you.
And so the center privacy that is afforded on lightning makes a lot of sense.
It's like, okay,
obviously receiving privacy is not ironclad or easy to get to ironclad,
but center, you have a lot of center privacy on lightning.
So adding that and was that hackathon, that weekend project, was that something that set off an idea like, OK, maybe I should go work on my own VPN and build Obscura?
Yeah, yeah, kind of. I think it was. I mean, I've always been looking at it and you're absolutely right about that dichotomy of like, you know, sender privacy and receiver privacy and lightning sender privacy is much more strong.
And I also thought that, you know, with VPN services, you aren't, these aren't like, I don't know, like $50 transactions, right? These are like, you know, $10 at most, let's say, right? And so it made all the more sense to do it over Lightning, rather than the base chain, because otherwise, it'll just be eaten up by fees.
I think I think what really prompted everything was when I went down a deep rabbit hole with looking at right.
I was at PubKey.
I still remember this.
I was at PubKey, and I was chatting with Matt Corallo.
And I was exploring various ways to do different VPN protocols and everything back then.
There's this concept of a performance-enhancing proxy, which makes it such that even though you're adding another hop,
You can oftentimes even improve the performance of the overall connection by just sort of like terminating it in the middle, which helps with the TCP retransmission algorithm.
But anyway, sorry, I can go down too many rabbit holes.
You've got to stop me sometimes.
What Matt was saying was to look at how Apple did their iCloud relay protocol.
And I hadn't thought of it because I was like, okay, it's Apple, it's an iCloud relay.
It sounds very like brandy and markety.
There's probably nothing there.
But he was like, actually look into it.
And I looked into it and I was just sort of blown away by how almost how ingenious sort
of the scheme was.
I mean, a major part of the scheme is this concept of, you know, having two separate parties be your sort of VPN provider rather than one party, right?
So, okay, maybe we should back up sort of a little bit in sort of how VPNs work a little bit, right?
Like the biggest flaw right now that I see, right, in existing VPNs in terms of privacy and everything else is that they act as your primary man in the middle.
They see both your personal information, as in like your connecting IP and you were talking about all the billing information and the credit card information and whatever, and your browsing history.
Now, actually, you know, if you're technical, you're like, well, isn't my, you know, connection secured by TLS or HTTPS or anything like that?
Yes, but there is metadata, let's say, that is in plain text.
Very specifically, you should look at TLS's SNI extension.
And this was like, this was introduced back in, I think, the 90s.
It was the 90s or the 00s such that, let's say, one guy, let's say Cloudflare, can host websites for like hundreds of different websites or whatever, right?
But what it really does is it just, you know, it just puts whatever website you're going to in plain text for everybody to see, including like your ISP or your VPN provider or whatever.
And I mean, like, you know, ISPs since the 2017 repeal of ISP privacy laws, they've been able to sell that data or like personally sensitive data to brokers without your permission, which is like, that's kind of crazy to me.
But anyway, so I think that's sort of a problem in that they're the only man in the middle.
And so users really have to trust when these providers say that, OK, your data is not logged.
You know, we don't keep any, you know, we don't persist any of this information that you give us.
Right. But let's say a provider is actually trustworthy.
Right. They keep to their pinky promise.
They can still suffer a security breach and be compromised and have that data be leaked.
right this is this is sort of why um people who are privacy conscious people who sort of
understand how networking protocols work and how this data gets shuttled around are actually
starting to tell people like hey like stop using a vpn right and i i i saw that as a huge problem
let's say for the industry and also you know there are certain benefits to vpns that we still want to
keep, you know, without some of the others. So what Apple iCloud Relay did was actually quite
neat. They simply said, okay, instead of having one person as your sort of man in the middle that
sees who you are and sort of where you're going, let's have two people, two independent parties
as hops, right? And so you, the first hop, you connect to your first hop who knows who you are
because you're paying them and everything else,
but they can't see any of your traffic.
They just know your personal information
and that you're connecting somewhere, right?
Everything is still encrypted.
And then you have the second independent hop
that has no idea who you are.
They just know that it's one of a thousand users
coming from the first hop
and they actually reach out to that internet
and see your IP packets that are,
but these IP packets are completely unattributable to you.
So that basically splits who you are from what you're doing.
And this was really simple yet effective
and just solves the problem of privacy
and being the only man in the middle
in quite a beautiful way.
It's sort of like Tor Lite almost, right?
Tor has this option called hidden services single hop
and this is basically what it is.
Sup freaks. This is Natty. You don't want to skip because Fold has a great offer for you.
Everyone knows about Fold, the app where you can earn the most Bitcoin rewards for everyday
purchases. I did this yesterday. Me and my wife, we use Amazon to buy quite a few things.
And instead of just putting our credit card into Amazon and buying there, I put my credit card into
Fold and buy an Amazon gift card and upload it to Amazon. Why? Because I get the credit card points
and then I get sats back. Yesterday, I bought a gift card. I made 10,181 sats, about $10.50
in Bitcoin. And it's the only way to do it. If you want to stack Bitcoin passively,
make sure you're using Fold gift cards. Fold has a special deal. I mentioned it earlier.
If you're not shopping with Fold gift cards, you're leaving sats on the table. New users
that sign up to Fold are going to get 20,000 sats in a welcome bonus with their first gift
card purchase. So don't leave sats on the table. Sign up now at foldapp.com slash Marty. Get those
20,000 sats freaks. Sup freaks, this rip of TFTC was brought to you by our good friends at BitKey.
BitKey makes Bitcoin easy to use and hard to lose. It is a hardware wallet that natively
embeds into a two or three multi-sig. You have one key on the hardware wallet, one key on your
mobile device and Block stores a key in the cloud for you. This is an incredible hardware device for
your friends and family, or maybe yourself who have Bitcoin on exchanges and have for a long
time, but haven't taken a step to self-custody because they're worried about the complications
of setting up a private public key pair, securing that seed phrase, setting up a pin, setting up a
passphrase. Again, BitKey makes it easy to use, hard to lose. It's the easiest zero to one step,
your first step to self-custody. If you have friends and family on the exchanges who haven't
moved it off, tell them to pick up a BitKey. Go to bitkey.world, use the key TFTC20 at checkout
for 20 off your order that's bit key dot world code tftc20 we had we had to do a little room
switch at the bitcoin presidio uh we have wi-fi problems sometimes here at the commons in austin
as well so i know it's bitcoin and the bleeding edge of distributed bleeding edge but we can't
figure out wi-fi i i think this is this is totally not not a not a sponsorship but i have had good
experience with unified gear and that's that's all i've had good experiences with all the other
vendors are like you know unified gear but i think we lost you you were explaining uh apple's iCloud
sort of relay system and you're at the point where you were describing the fact that you
hop between two independent actors and that sort of uh masquerades the
the inception point of the data transmission.
Yeah, no, 100%.
I mean, basically what you do is, you know,
you're the user, your packets flow through the first hop
and then to the second hop and to the internet, right?
And so what that basically does is the first hop knows who you are,
but doesn't know any of your traffic.
And the second hop has no idea who you are
and relays your traffic, right?
So this splits that information between those two.
And so nobody has sort of both pieces of the puzzle, let's say, to identify you or de-anonymize you or for the data to be leaked or anything else.
And this is really, you know, simple, yet effective, easily deployable. And, you know, sort of the simplicity of it all is why, you know, at the IETF, which is sort of the body that makes all the new internet standards, you know, like HTTP, DNS, all the good things that we know,
they started a working group, which is sort of their, well, it's a working group. I guess it's
self-explanatory what a working group is. It's a group that works on stuff. They formed a working
group to standardize a version of this on top of HTTP3. So yeah, I got really into that idea
and I looked into it. It's a really solid idea. And well, there's also another part of this idea
that also came into play that got me really riled up as well. So I was talking about how
they standardized this on top of HTTP3, right? And at the beginning, I was like, okay, HTTP3.
So the HTTP protocol has sort of been
through several iterations.
We had, you know, 0.9 was very popular.
I think 1.1 was quite popular.
And then 2.0 came about and was quite popular.
And HTTP3 was somewhat new.
And I was just thinking, okay, all right,
they're just gonna do it on top of HTTP3
because, you know, this is the new thing.
And like, you know, everybody's trying to standardize
around this new protocol and everything else.
But actually that decision was also really ingenious.
And I realized this from thinking back to the days
when I was a teenager back in Shanghai
trying to get around the Great Firewall, right?
And so the Great Firewall blocked all of these sites
like Wikipedia, Google, YouTube,
all of these things that I needed to use.
And, you know, I tried a lot of commercial options.
They were, you know, not that reliable.
I try to set up my own things
with sort of off the shelf protocols
that everybody knew like OpenVPN, StrongSwan,
and sort of later WireGuard.
And they were like swiftly detected and blocked.
Like it would work for a day
and then tomorrow morning I would wake up
and like it's gone basically.
But what sort of sprung out of that was,
you know, this is like a lot of developers
who are just basically locked behind a wall now,
and you know, plenty of them are network protocol engineers.
And so sprung up where like technologies,
and these are just all just proper noun barrages,
like V2ray, Meek, Shadowsocks,
and more recently Hysteria too.
I know, naming is the hardest thing in,
one of the hardest things in software engineering, right?
But beyond these names, let's say,
they had like a common theme to them, right?
And the common theme amongst all of these newer options
that were, let's say, more reliable, let's say,
to get around the great firewall,
was this idea that's sort of part of the lingo
of the internet freedom and everything else,
this idea of collateral freedom,
and more importantly, collateral freedom via obfuscation.
So you have to sort of wrap your head around
the game theory of internet censorship
and people who wanna block things, right?
um internet sensors and and sometimes overzealous network admins that we have here right like you
know cisco has sold the same tech that they sold to the chinese government to let's say uh to to
everybody to to you know airports and hotels and whatever right it's sort of like and network
admins i i'm sorry to to rag on network admins sometimes they're just like they don't know
they're like oh we're under attack like what is the cisco advanced protection thing let's
let's tick that box. Maybe that'll help. I don't know. Right. You know, they they these these
network admins, they generally still want permitted traffic to go through. Right. They don't want
their employees not to be able to access, you know, whatever thing that they want to access.
So they want permitted traffic to go through. So what is your play here? Your play here is that
if on the wire, like at the protocol level, if you can blend in and look like regular internet
traffic, right, by mimicking HTTP, then you're more likely to avoid being detected and blocked
and sort of flow through, right? And so that was, you know, one of the important insights
in that and sort of why they use HTTP3 is that, you know, it allows you to blend in with regular
internet traffic. And HTTP3, unlike HTTP2, doesn't suffer from, this is a sort of a
technical term called TCP over TCP meltdown, whereby, you know, some VPNs, you'll feel that
they get stuttery, as in like, you know, if there's any packet loss, it recovers really
slowly and it stutters and things sort of jump around.
That TCP over TCP meltdown is basically what you're feeling there.
And so that was also another part of it that I felt was really, really ingenious.
I mean, to sort of take it a step back and think about, OK, what does this mean, let's
say, for someone who is using a VPN like that, right? What it means is that in the places where
normally, you know, your other VPNs won't work, let's say, at an airport, at a hotel, in certain
nation states, or, you know, even on some campuses. I remember, I remember trying to use YouTube TV.
Right, right, right. Exactly. All like places, like if you're in a network environment that's
restrictive um now uh it's way more likely that your vpn is going to work it's way harder for them
to detect and block your vpn connection because honestly a lot of a lot of the time unless you're
in the like an authoritarian country or whatever right um they're not actually trying to like
they don't actually have they're not actually actively trying to block you um the network
admins are just a little overzealous and just turned just just ticked something that they didn't
really fully understand what they were doing anyway so that's what's really happening a lot
of the time yeah it's the because i i don't i'll be hand up here don't follow the interworkings
and the iterations of the lower levels of the internet protocol but it is very encouraging
that a company like Apple will create this relay
and then the people working on HTTP will recognize it
and say, hey, maybe we should implement this
to make it better to use.
So the fact that the open internet
still has somewhat of a cypherpunk sort of tilt at its core
to enable the free distribution of data and information
is highly encouraging.
No, 100%.
I mean, it's because I feel like, you know, a lot of it is sort of unspoken, right?
Like, because, you know, the IETF is supposed to be somewhat of a neutral organization and
everything else, right?
And, you know, but these are nerds, you know, these are like people who are just like, we
want that, we want freedom and we want, you know, these things to happen.
And so when they see a good thing, they, they know where to take out.
I was actually, um, so like when I saw all of this, right, I was like, okay, all right.
Like, let me like, I'm someone who doesn't really understand anything until I've like
coded it up.
So I like, I literally, I like implemented one of the, uh, uh, RFCs.
So RFCs are like basically like VIPs in, in, in, you know, internet land.
Um, and you know, I implemented it in Rust and then I implemented in Go just to like
fully understand what was going on um and then i you know i wasn't really i requested a waiver to
go to ietf and was actually invited and i went to the working group and met with the people there
they are so gracious with their stuff and you know they they were they they told me crazy stuff of
like um this uh this guy because because it's not just apple right this is a working group with
people from you know apple cloudflare google fastly um you know you name it and anybody who's
in networking who's who's sort of higher up at the protocol design level were there um they were
telling me their crazy battles with um you know their their technical term for it was like middle
boxes right which is basically like sort of your isp and whatever right like their crazy battles
with middle boxes and how they you know um introduce things in the protocol to just like
make the middle boxes like a little confused and a little you know uh throw them off their game or
whatever and it's a good time it's definitely a good time and yeah the ietf is a great um
great organization for sure yeah this rip was brought to you by our great friends at unchained
as bitcoin's role in the global financial landscape evolves understanding its potential
impact on your wealth becomes increasingly crucial whether we see measured adoption or
accelerated hyper bitcoinization being prepared for various scenarios can make the difference
between merely participating and truly optimizing your position. This is important, freaks. This is
why Unchained developed the Bitcoin Calculator, a sophisticated modeling tool that helps you
visualize and prepare for multiple Bitcoin futures. Beyond traditional retirement planning,
it offers deep insights into how different adoption scenarios could transform your wealth
trajectory. What sets this tool apart is the integration with the Unchained IRA, the only
solution that combines the tax advantages of a retirement account with the security of self-custody
In any future state, maintaining direct control of your keys remains fundamental to your Bitcoin
strategy. Go explore the potential futures at unchained.com slash TFTC. Bitcoin is going up.
Make sure you're protecting it the right way. Make sure you have a good partner that is Unchained.
Go to unchained.com slash TFTC.
Bringing it back to Obscura and how it compares to incumbent VPN providers. I think you mentioned
it in the beginning but that's one thing where it's mulvat or ivpn which are the providers that
i've sort of trusted uh throughout the years it is this pinky promise as as you said and as you
market on your website that uh it's really don't it's trust don't verify because you can't verify
you just have to trust that they're deleting the data but because of the technical um sort of uh
functionalities that have been opened up with this relay system on http3 it seems like you can
actually um you can actually have more confidence that data isn't being logged and obscura doesn't
have the ability to to do it in the first place exactly yeah exactly it's it's it's sort of like
you know uh what's better than not logging can't log right like it's it's it's you don't you don't
have to trust um our word for it like you know we have our source code on github so to bring it to
highlight like the the you know i was just talking about the two advances right like the two pop
relay architecture right and sort of it being based on http and quick and unreliable transport
and all those and obviously you know we put our own spin on those two and how we implemented it
I've what I what my understanding was, was that these are the ingredients for a new generation of VPN services.
Right. And these VPN services is going to be different.
These are VPN services that like don't rely on trust for privacy, as I was saying before, and are also hard to block and hard to detect while maintaining good performance.
Right. And actually, so with our two party setup, as we were talking about, we need two independent parties. Right. We operate the first hop and we're actually very proud to partner with Molvat, which we see as one of the most trustworthy VPN providers out there to operate the second hop.
right and or what we call the exit hop and so we are completely independent companies we don't
share keys with each other or whatever um and so your your internet you know data is split between
these two hops um and for for obfuscation for you know getting around these network filters and
firewalls and all those things um we do exactly what i was saying was you know we tunnel these
packets over um quick or uh which is sort of the basis of http3 which gives us the benefit of you
know being hard to detect or block as in it will work in places where your vpn has failed to work
before um and and this this this you know as i was saying before this this came from
years of my fights and duels with the with the great firewall trying to get around it and
And understanding sort of like what is, because I think one of the interesting dynamics, I want to say, is that for, you know, cryptographers and people who work on networking protocols in sort of, let's say, the first world or places where, let's say, internet censorship is like not here and now.
they like to make sure that the cryptography is right and and make sure that you know everything
is perfectly blind and everything else and I that's that's a really worthy goal but in a
practical sense you know sometimes for network filters let's say like any a network admin at
whatever right there they they've got a very simple mindset they're like this traffic looks
too random or this traffic is too well protected or doesn't look like http i'm just gonna stop it
like i don't i don't care what you're you know encrypted and whatever i'm just gonna like you're
gone um so it's an interesting dynamic uh to explore let's say um but yes so you know to take
it back you know our wire guard packets are you know your wire guard packets up you know perhaps
some of your listeners have heard about wire guard and how it's a great protocol and it was
it it still remains one of the greatest protocols um uh and the wire guard packets are end-to-end
encrypted from the user to mulvat servers so we as the second hop we never see any of your plain
text information, not even the SNI metadata that I was talking about, right? And with sort of,
you know, QUIC and HTTP3's unreliable transport, we made it really hard for, you know, network
admins to block that first hop from the user to us, to Obscura. We made it really hard to block
and we've done it without sacrificing performance across the board. And yeah, and, you know, we take
people's trust very seriously. You know, you know that our last conversation was about me
working on Bitcoin Core's build system and everything else. Right. And so trust is always
on my mind. We want to be we want to be trustworthy, but we also want to minimize
the amount of trust that anybody has to place in us. And so our entire source code is on GitHub
hub for people to see um and you know me you know we're working on reproducible builds and we'll
we'll roll them out for people so people can verify yeah now it's very exciting because it
seems just having followed the project since you announced it and um getting access to
the website before you launch look at how you guys are marketing it i think
kudos on the design the name naming's hard i think obscure is an incredible name for a vpn product
and i think the way in which you guys communicate how you're differentiated
uh compared to other vpns is is very clear and understandable on the website and i guess that's
the question i have do you obviously you're partnering with molvab to be that exit hop
and do you think this will become quickly become a standard in the vpn world once oh i
launch? I believe so. I think there's going to be, let's say, I think that this is what the next
generation of VPN providers are going to look like. I think that there is a crisis of confidence
almost in, you know, existing VPN providers. I don't think that that is the case for providers
like Molvad, who have like proven time and time again, let's say that they are trustworthy,
you know, removing subscription, all those things. But I think for the rest of the industry,
there's sort of a crisis of confidence. Because, I mean, I think what's happened, right, is that
like, you know, you've got these companies, there's growing scrutiny, there was like recently,
like a government document telling people not to use consumer VPNs. They've sort of flooded
youtube if you're ever on youtube that's like you know they've flooded youtube with all these
ads and exaggerated claims and scare tactics to who like you know to someone who's like
like a like someone who like knows the the low-level networking stuff i'm like
you're stretching it a little bit like you're stretching it a little bit what you're saying
um and you know even after users sign up they have all these predatory pricing strategies where
It's like really cheap the first year and then they jack up the price for the next year and you're just paying insane amounts.
And, you know, even behind the scenes, these companies are, there's this interesting graph.
I think it was Windscribe that made the graph.
There's an interesting website that they put up of the VPN ownership map.
Um, and it turns out these VPNs are like, a lot of these companies are what I call like
the many headed hydras, let's say.
Um, these are, these are basically a, a graph of VPN providers that are all owned by a parent
company like, uh, you know, Zip Davis or, or, or Cape or, or one of these.
Um, and it's, it's, it's questionable ownership, right?
and oftentimes when they're part of sort of these conglomerates you know they use the other arms of
their hydras to astroturf a little bit right like let's get on that top xvpn of 2015 25 list or
let's get on whatever and i look at these lists and all i all i'm looking for is like is molvat
there like if molvat's like not on one of those lists or not on the radar of these lists i'm like
come on like this is just not a serious um kind of a thing so this is i'm sort of describing this
crisis of confidence right but i i think sort of the next generation of vpn services really has to
address um you know the original sin let's say of vpn services and sort of this privacy and trust
problem and i really think this is what what it's going to look like and i'm really excited for it
Yeah. I mean, bringing Don't Trust Verify to the VPN world is extremely exciting.
I think you're being a bit polite to the competitive landscape by not naming names, but like companies like ExpressVPN and others who are deploying millions of dollars of ads on very popular podcast with questionable security and particularly of data, of user data.
And from what I understand, a lot of these companies, as you mentioned earlier, are selling data to third parties to juice their revenues.
And I think it's important if you care about privacy and maybe not even care about it but desperately need it depending on where you are in the world and what you're doing, being able to verify that this isn't being logged, you're not being tracked, and you can't be tracked is very important.
100%.
Um, and I, I, you know, I, I think it's, uh, I have a few thoughts there.
Let me make sure I've touched on everyone.
The, um, you know, I, I, I don't like to, um, sort of, um, name too many names mostly
because, um, I think that this should be, and, um, maybe I'm too naive, but I think
this should be an industry wide, um, sort of effort, right?
I think that, like, there's a chance for this industry to be elevated as in, OK, you guys aren't doing this today. You could be doing this tomorrow. Right. Like you could improve. We could make this industry a better place. And so I hope that, you know, these providers maybe come up with their own schemes, maybe to come up with, you know, innovations.
You know, it's, it's, it's, it's not a, um, it's not a, uh, you know, I, when you lose kind of situation, it's an industry that we can all, um, improve upon.
And I hope that, um, I hope that we do.
Um, yeah.
Uh, right.
Yeah.
Sorry for putting you on the spot there a little bit, but the, um, no, this is great.
And obviously, I mean, as it pertains to the audience of this podcast, going back to what we discussed earlier, you have the ability to pay privately via Lightning as well.
Yeah.
Which is important.
Oh, 100%.
That's super important to us.
I think our stance, let's say, and not to dwell too much on the privacy part once more, but it's, you know, I think there's this good stance to take, which is that, like, users' personal data is toxic waste to us.
Like, we want a service to be as convenient as possible, right? But where possible, we don't want your data. We do not want to, you know, store anything or whatever. It is toxic waste to us. We wouldn't know what to do with it.
Uh, and so when, when it comes to technologies like lightning, where, you know, we, we really
don't have to store anything other than, you know, a proof, um, we're very happy to implement
that, you know, obviously, you know, I've, I've, I've been, I've worked on Bitcoin core
and, and big fan of lightning and everything else.
Um, and, uh, and actually, um, um, my wife, uh, uh, Val, uh, works on LDK.
And so she keeps me abreast of the, you know, the developments and everything else.
And it's been really great.
Yeah, and I do want to point out that, you know, other than the privacy aspects of Obscura, right, we really care about the usability of our product.
And that's seen, let's say, in our macOS app where we've tried to make every single user flow as smooth as possible.
But also in that, you know, I was talking about before, this is a VPN that will work in places where other VPNs didn't, right?
So even if you didn't care about the privacy piece, we've got your back and we have improvements.
Yeah.
What do you think this does now that this product hits the market?
Not only for the VPN space, but for just freedom generally on the Internet.
Do you think this opens up new possibilities in terms of what people can work on and what they can get done without having to sacrifice privacy, speed, whatever it may be?
Yeah, I mean, I think in general, you know, everybody uses their VPN for different reasons.
I'm not going to speculate on what.
But I think a general sense that I keep hearing from, you know, the users who've been sort of beta testing our product is that, like, they turn it on and because, you know, while we've optimized all of our protocols and everything works smoothly, they almost forget that it's there.
But they feel safer. They feel that, you know, they are protected and that they could, you know, be free, let's say, and speak freely and browse freely, let's say, on the Internet without worrying about if their ISP is looking at what they're doing or like, you know, their boss knows that they're on Reddit, you know, at 2 p.m. or something like that or things like that.
And I really believe that the internet is our digital commons.
I would venture to say our glorious digital commons.
It deserves to be open and private.
That is our mission at Obscura, to make the internet open and private by default.
And I think in a larger sense, politicians are always going to try to erode our freedoms online, right?
I think, you know, the American Constitution gave the American people great rights in sort of the physical landscape because that was basically all there was back then, right?
And with this new digital landscape, I think politicians are trying to erode our freedoms online.
And we really have the duty as technologists to wield our skill and our programming skills and whatever to defend our rights in this digital space.
And so that's sort of part of the reason why I love working on stuff like Bitcoin and VPNs and everything else.
I believe that it's a very important tool for us.
yeah yeah i mean this is making me even more optimistic and i have been recently because it
does feel like privacy is winning you've had i'm not sure if you saw i'm sure you did this is your
beat but the uh telecoms companies here in the u.s got backdoored and you had the government
come out and say hey u.s consumers you should be using end-to-end encrypted apps they essentially
had to right bend the knee and say all right like this is not good we don't want this backdoor
or people getting hurt because of these backdoors that exist in these telecom companies.
And we have the OpenSecret team here in the commons in Austin.
They've been doing some really cool stuff with Neutrino enclaves
to make sure that app developers have tools to make it so that they can better secure user data
and prevent the possibility from it being stolen by hackers
or nefarious state actors whatever it may be um and it seems like to your point and your ultimate
goal of making sure that people can browse um quickly and privately on the internet and just
make it the default it seems like we're getting closer in in 2025 no totally and you know one
One more point that I'll make is that this is sort of at the edge of our understanding, I want to say, right?
I think most products have been made with the assumption of, you know, at least the person providing the product would be able to see everything, right, and be able to do everything.
And that allows that provider to be much more flexible, much more it's easier to code, really, like it's easier to design and code and everything else.
Right. And so when when companies are making products like this that are end to end encrypted, it is a it is a challenge, but it is not an insurmountable challenge.
It's a challenge that's really worth taking on. And I think that it's a cause worth championing because I feel like because of the difficulty of the work, a lot of the time consumers have this dichotomy of, you know, oh, if it's private, it's probably going to be less easy to use.
or if it's easy to use, it's sort of not private.
That dichotomy gets instilled in people's heads.
But I don't think it has to be that way.
I think that if we work hard,
if we really think about how to design these systems,
we can actually make products that are as usable
as let's say the non-private alternatives and whatever
and have that into an encryption,
have, you know, preserve our glorious digital commons.
That's right.
And so help me better understand the composability of the protocol
and the code base that you've written.
Right now you're using MOLVAD as one of the exit nodes.
Do you envision a future where you'll have a suite of potential exit node
partners that you could choose from as an end consumer
or just create diversity at the exit node level?
Yeah, I would. Yeah, I would really hope so. We we've made it we made our protocol such that any provider that operates sort of a wire guard based service we can basically hook into.
And so, you know, we're obviously launching with Mulvat because, you know, we have a partnership with them and they are also, you know, what we think of as the most trustworthy.
I think many people think of them as the most trustworthy VPN provider.
But we would hope that, you know, the industry opens up and people become other people's second hops and things like that, right?
Um, and I think an important point is, is that I think the VPN industry also needs to keep, um, keep informed of the things that are going on at, um, at the ITF. I mean, all of these advancements, you know, came out of, uh, you know, working, working groups there. Um, you know, obviously Obscura, at Obscura, we have our own little tweaks to make it just a little bit faster, a little bit smoother and everything else.
But, you know, there are things coming down the line that I think are really, really cool, like Privacy Pass. Privacy Pass is coming out of Cloudflare's research team, I believe. This is from a few weeks ago, not a few weeks ago, a few years ago now. They also have a working group. It's meant to solve the CAPTCHA problem, basically.
So if you browse online right now, you have all these captchas all over the place. And Cloudflare was basically like, okay, what if you can solve a captcha and store it in your browser as proof for the next, I don't know, couple of days and don't have to see it for a couple of days, right?
Like why, why, like, you know, you just proved that you're a human here.
Why doesn't this other thing know that you're a human?
You just offer up the proof again, you know?
And so there, there are a lot of interesting things coming down the line.
I'm really excited for, yeah, for, for, for, you know, our launch and what we've built
and the future of the internet.
Yeah.
If you could reduce the amount of times I have to identify the buses in a, in a picture,
that would be incredible.
and the slow ones the ones where they're like fading for like five seconds you're like dude i
don't and then and then it fades in and it's like the same bus and you're like oh dude i i'm not
doing this again that or the puzzle piece they're getting like even more complex where it's like
all right turn the shape and make sure it's pointing in the same direction as once again
that puzzle piece one gets me because i'm such a i'm like a perfectionist i'm like
i just i need to make sure i don't think it actually cares but i'm like i need to make
sure it's pixel perfect uh and for obscuras how do you view the long-term vision of the country
or country the company uh is a vpn just sort of the the beachhead product that you plan on
building a suite of products around or um is it vpn only for the foreseeable future
Well, we're very focused on obscure VPN. And I think that, you know, there's a lot of improvements, let's say, to be made to the existing functionality of VPNs and whatever.
And of course, we're launching on the 11th with $6 a month and everything on macOS.
And so we're really focused on the user experience and the usability of our VPN.
I think that the long-term vision, of course, our mission is to make the internet open and
private by default.
And what we want to do, in my eyes, is really get the VPN experience to be as smooth and as private as we can, be the best VPN that we can, and move up the stack.
Um, I think that there are, um, so this was, this was sort of out of the IATF.
There are a bunch of sort of organizations that, that sort of manage standards in the
internet protocols, but there's this, there's this sense that, um, you know, the internet
is layers, right?
Is, is, is, you know, we have layer one to layer five or layer seven or whatever.
But VPNs provide you IP privacy, which is at the addressing layer.
And you can go up these layers to the transport layer, to the application layer, right?
So, you know, even though I'm talking through a VPN right now, right?
Like my name is right here, right?
And so, you know, you really have to go up the layers in order to offer better privacy.
And I think we can do that.
And we really want to be the company that is on the user side in terms of that I want to make sure that our users understand that we're always going to make decisions that are for their privacy and for their betterment and will work hard to earn their dollar.
well i'm very pumped that you particularly are working on this because i think for anybody who's
unaware of carl's work uh in the bitcoin space that's listening or watching this you should go
back and listen to the episode recorded i believe in 2019 about reproducible builds and geeks and
how important that is to ensuring that you're actually downloading the code that you're
supposed to be downloading and that you can verify that um uh when you're when you're downloading
bitcoin and that was very hard and sometimes thankless work but extremely important and uh
if you're bringing that talent to the vpn world i'm extremely bullish on obscura and our ability
to actually have a free open and private internet moving forward so i'm pumped for you i know you've
been working on this for quite some time and uh less than a week away from launch here so
i'm excited i'm running mac os so i'm going to download it as soon as i have uh have access to
it and take it for a spin yeah sounds good thank you so much marty and thank you and where can
people go to download obscura we'll link to it in the show notes obviously but um it's yeah
obscure.net obscure.net that's how you spell it obscure.net obscure.net all right we'll send
people there carl hopefully we can catch up uh hopefully it doesn't take six years for us to
catch up between this episode and the next we can do it for sure 100 always glad to be on
really appreciate it marty all right thank you peace and love freaks
Thank you.
