
Obscura VPN with Carl Dong
Discussed in this episode
Boost this Episode
Send sats directly to the creators. Value for Value.
Plus 1% to Podcast Index, 1% to Boost Bot.
Show Notes
A weekly live show covering all things Freedom Tech with Max, Q and Seth.
Go and check out https://https://obscura.com/ for more information and be sure to follow Carl on twitter at https://x.com/carl_dong
HELP GET SAMOURAI A PARDON
- SIGN THE PETITION ----> https://www.change.org/p/stand-up-for-freedom-pardon-the-innocent-coders-jailed-for-building-privacy-tools
- DONATE TO THE FAMILIES w/ USD ----> https://www.givesendgo.com/billandkeonne
- DONATE TO THE FAMILIES w/ BTC ----> https://pay.zaprite.com/pl_JpxtkLv95T
- SUPPORT ON SOCIAL MEDIA ---> https://billandkeonne.org/
TO DONATE TO ROMAN'S DEFENSE FUND: https://freeromanstorm.com/donate
VALUE FOR VALUE
Thanks for listening you Ungovernable Misfits, we appreciate your continued support and hope you enjoy the shows.
You can support this episode using your time, talent or treasure.
TIME:
- create fountain clips for the show
- create a meetup
- help boost the signal on social media
TALENT:
- create ungovernable misfit inspired art, animation or music
- design or implement some software that can make the podcast better
- use whatever talents you have to make a contribution to the show!
TREASURE:
- BOOST IT OR STREAM SATS on the Podcasting 2.0 apps @ https://podcastapps.com
- DONATE via Monero @ https://xmrchat.com/ungovernable
- BUY SOME STICKERS @ https://ungovernable.network/shop/
FOUNDATION
https://foundation.xyz/ungovernable
Foundation builds Bitcoin-centric tools that empower you to reclaim your digital sovereignty.
As a sovereign computing company, Foundation is the antithesis of today’s tech conglomerates. Returning to cypherpunk principles, they build open source technology that “can’t be evil”.
Thank you Foundation Devices for sponsoring the show!
Use code: Ungovernable for $10 off of your purchase
CAKE WALLET
https://cakewallet.com
Cake Wallet is an open-source, non-custodial wallet available on Android, iOS, macOS, and Linux.
Features:
- Built-in Exchange: Swap easily between Bitcoin and Monero.
- User-Friendly: Simple interface for all users.
Monero Users:
- Batch Transactions: Send multiple payments at once.
- Faster Syncing: Optimized syncing via specified restore heights
- Proxy Support: Enhance privacy with proxy node options.
Bitcoin Users:
- Coin Control: Manage your transactions effectively.
- Silent Payments: Static bitcoin addresses
- Batch Transactions: Streamline your payment process.
Thank you Cake Wallet for sponsoring the show!
MYNYMBOX
https://mynymbox.io
Your go-to for anonymous server hosting solutions, featuring: virtual private & dedicated servers, domain registration and DNS parking. We don't require any of your personal information, and you can purchase using Bitcoin, Lightning, Monero and many other cryptos.
Explore benefits such as No KYC, complete privacy & security, and human support.
Hello, and welcome back to Freedom Tech Friday, a live and interactive show taking place every Friday at 9AM eastern or 2PM London across the ungovernable network. Each week, dig into the latest in Freedom Tech that can be including Bitcoin, Monero, encrypted messengers, privacy tools, and everything in between.
If there's a news item tool or topic that can help you take back some control in today's digital Panopticon, then we want to talk about it. This show and the topics we cover are powered by freedom.tech, a daily news desk that uses AI to monitor hundreds of sources so that we can continue to bring you the signal each and every week.
My name's Q and A, and I'm head of customer experience at Foundation. And as always, I'm joined by Max, head honcho of the Ungovernable Network, and Seth, who is COO at Cakewallet.
This show is live and interactive, and you can help steer it steer the conversation by commenting live, asking questions, boosting the show, or just sharing it with your friends. Top support from the last show covering Seth and his AI empire comes from Late Stage Huddle, who sent in 6,006
sats and said, keep up the good work, gents. Well, thank you for your support as always, Late Stage Huddle. Without further ado, Max, Seth, how's it going? Seth, how many more DGX Sparks have you bought this week?
Only only the four. Only the four. Already already posted about. Okay. Eight total. The cluster's done. Everyone can stop Eight total. Whining. Yeah. Are you are you doubling? Is this gonna be eight, 16, 32?
We'll see. Technically, if you go to 16, then you can run KMAK three. So, I mean There we go. As well, mate. You might as Yeah. It's true. It's true. What's another 40 k? Okay. Mate, let's let's get it done.
Feel Nice job on you. Well, as usual, I feel like the tech mong because I'm still just running an m one Mac that barely barely getting by. And Peasant. Really, really I know. It's it's pathetic.
And I'm really getting drawn to getting something running. Every time I see you post, I just think, oh, it looks like fucking cool. How to use it, but at least I'll Max, I think we're on the same train. We gotta wait for the, new Mac Studio.
Right? Yes. So The five five twelve ones that are out of stock, but the new ones, they're coming out in, a month or something. You know? Very, very enticing. Very enticing indeed. If if all else fails, we can just get a subscription to Seth.
Yeah. Sorry. I'll start selling access soon. Do we get a page rate, Seth? I am new, anyway. No. Rate limited hard for sure. No no no limit resets either. So Appreciate you. Thank you. Nice.
Nice. Well, for those of you that are watching live, you will obviously see that we have a guest with us today. A guest that has spent more than three years working on Bitcoin with the the Chaincode Labs team.
He was often working on the the less glamorous, but arguably more important problem of in its in the stack about, you know, software verification. Does it match the code that you were shown? Reproducible builds, supply chain security.
Basically the stuff that nobody tends to tweet about, but that everybody tends to depend on. After that, he went and pointed that same obsession at a new industry that I think we can all agree badly needed it.
Because if we're being honest about VPNs, it's an industry that's built on horrible YouTube sponsorships, scare tactics, fake top 10 lists, and ownership structures you that you probably need a private investigator to untangle.
And underneath all of that sits one uncomfortable fact that most YouTube influencers tend to overlook intentionally, is that your VPN provider can see who you are and everything that you do, every single one of them. And the whole no logs is unfortunately a pinky promise that nobody can truly verify
because you have no way to check it, which is exactly why a lot of the privacy people will tell you that VPNs, you should be careful with them or choose the right one, and that's why we're here today.
So our guest today, Carl, looked at that and asked a better question. Not not who do I trust, but how do I build this so that trust is not required in in the first place, which is a great way to look at it. His answer was obscure, and I'm I'm sure many of our listeners and viewers are well acquainted with it by now.
Two independent hops run by two separate companies so that nobody knows who you are and can't see what you're doing. And I'm very, very excited to to dive into it. So, Carl, welcome to the show. It's a real pleasure to have you with us. How are you doing, sir?
Thank you so much. That was a hell of an intro. Thank you so much. I'm doing fantastic. Really happy to be on. Good. Good. And I just wanna address the elephant in the We we all like our caffeine at the ungovernable network. And Carl told us before we went live that he's he's abstaining
from caffeine and I know. Doing cold turkey for two months. So I I'm just I just wanna commend him for looking so sprightly. Zero. Okay. Because it's it's like so how's it going, Carl? Are you well?
Yes. Yes. Fantastic. Well, I'll always, you know, happy to be on here and talking Freedom Tech. I gotta be I gotta say, I'm a little bit jealous of your guys', like, podcast name. I'm like, Freedom Tech Fridays. That just rolls off the tongue. You know what I'm saying?
And that's exactly what, like if I were to start a podcast, that's what I wanna talk about. You know? It's like the perfect perfect thing. Yeah. I I I I don't wanna toot my own toot my own horn too much, but, it was all my idea. I'm gonna say all of It was actually. All of it. That was all you, Q.
Let's dive in. Before we get into Obscura call, I would be doing an absolute disservice to you to kind of paint you as just the Obscura guy because you have a long history of working on very cool and very important stuff before that, especially in and around Bitcoin.
So take us back. When did it all start? How did you get into it? Let's set the scene there and talk through some of the work that you did on Bitcoin because it's, you know, very interesting.
I'd be I'd be super happy to I guess because this is sort of longer form, I'm just gonna go into, like, interesting stories and feel free to, like, stop me and whatever. So I actually so I grew up for a part of my life in China, which is very interesting and sort of, like, informs
why I do the things that I do. My dad was just telling me yesterday over dinner this story of how, like, like, the first time that they got dial up in China and they could, like, see the world directly, he went on the Internet and was like, he knows about National Geographic. So he just went to nationalgeographic.com
and ordered probably what is, like, the first subscription of National Geographic from China just so I could, like, you know, I could get the magazines and be exposed to western culture and, you know, the the scientific everything. Right?
And so the Internet was always very beautiful and sort of a beacon of hope and freedom, let's say, for my family and I. I I was in London for a while for primary school and then went back, and that's sort of when the great firewall came up. I remember a a very fateful March,
when you know, the day before, I was sharing, you know, my happy tree friends clips with my friends. And then the next day, it was just like, nope. There's no YouTube. There's no, you know, Facebook. There's there's nothing.
Right? And so I think that really drove me towards, hey. We need freedom tech. Right? I I think, you know, technology should serve the people should, you know, further the, the sovereignty and freedom of of of individuals, let's say.
And so when when I learned about Bitcoin, I was, let's say, very much into it. It was sort of just along the lines. And I think back then, I was in high school when I first learned about it. And I remember I was in in high school in Connecticut, and I learned about it and that I decided to start mining Bitcoin
in my dorm room because our dorms had free electricity. And so what I did was and and okay. Alright. As a a Bitcoin person, I'll my sin. I did not actually mine Bitcoin. I mined I think it was Dogecoin or some it was like I had I had GPU miners.
I know. I'm I'm a trader. Okay? I'm a I'm a trader. I mined script algorithm coins because there was some smart router thing that would, like, smart cell or smart auto mine or whatever and then dump it all into Bitcoin, and and that that's what I did.
My roommate did not appreciate that. That was a very loud rig that I had. And we have this, like, on campus, what's it called, competition called the green cup every year, where all the dorms compete to see who's the greenest as in uses less electricity.
And that year, our tiny we were the smallest dorm on campus, and we were using almost as much electricity as dorms, like, two or three times our size. And they were like, yeah. That's like an accounting error. I was like, yeah. That yeah. Sure. Yeah. Accounting error.
That was really fun. But, obviously, you know, as I as I progressed and I I went to Berkeley and things like that, studied computer science, I was like, hey. I can actually start contributing now.
And I remember I got in the door at Blockstream, got exposed to a lot of the Bitcoin core developers, and then went over to Chaincode. And that's when I started looking at the problem of supply chain security as you were saying, head robot.
So just to just to sort of give a little bit of a context of of what that is. Right? I think the core problem is, okay. We've got, you know, the Bitcoin code base, let's say, that's on GitHub or whatever.
But and but but you download, like, a disk image or, like, an EXE or, like, some kinda executable. Right? Like, how do you know? Right? Even if the code base is, like, all clean and there are no bugs, there's no, like, Bitcoin Core is not trying to steal your money or whatever. Right?
How do you know that that code base is what corresponds to the thing that you downloaded? Right? Because, you know, technically, like, the developer could be like, well, before I upload this disk image, let me insert this backdoor. You know?
And so that, I think, at least for trillion dollar asset, is extremely important. And that's sort of the the the chain of things that I worked on. This is extremely interesting now because I remember, like, what was I submitted a when I first started working at Chaincode on on supply chain security for Bitcoin, I submitted a talk,
and it was like the the title was like supply chain security for Bitcoin and things like that. And back then, there was a kick of, like, all these forgive my phrasing shitcoins that was about, like, supply securing the supply chain with the blockchain or whatever. And then the the conference organizers, this is too hyperbolic.
You know? This is like you know, you're not you know? And I was like, no. No. No. This is this is actual software supply chain security. And nowadays, people are talking about it all the time because it seems like every other week,
there's a supply chain attack on on NPM or or or, you know, Rust, I think, you know, last week or two weeks ago and things like that. It's really things that you don't think about until, like, you get hit.
Right? Oh, thank you, Keith. When Linux, of course. And and so it was an honor to work on that. We worked reproducible builds. We worked on bootstrappable builds. For the nerds out there, we worked out basically how to from, like, a 500 byte, you know, assembly that you can, like, see yourself and and and audit.
Bootstrap all the way to, like, a GCC tool chain that's capable of compiling c and everything else, all the way up to Bitcoin. And so every step along the way can be audited and viewed by, you know, human eyes, rather than it's all all being binary.
And that was quite the achievement. I think on the TOR bug tracker, they have a bug open that's sort of like, hey. Let's let's let's see what we can do to to be like Bitcoin. I think I think GITIAN, so the the sort of instantiation of the supply chain security and reproducible build system for Bitcoin Core prior to mine, GITIAN,
was what inspired, a lot of the sort of the explosion of reproducible builds and things like that across the ecosystem as well. Sorry. I've been talking a while.
Yeah. No. Not at all. Like I say, I'm more than happy for you to to dive in and stuff. It's all very interesting, especially here in, like we we don't get to speak to that many people that work on, you know, such such kind of low level stuff
that's so close to the protocol. So getting to hear all of the details is great. So please feel free to continue and tell any any anecdotes whatsoever because it's all super useful to us.
Yeah. Yeah. I well, let's see. I think what's what's somewhat interesting, let's say, at the time was
I think people think of Bitcoin Core as a very sort of not autistic, but, you know, very very very put together team, let's say. But but you really don't know until you're you're in the middle of it. The the the the level to which we scrutinize every change
and the level to which we scrutinize, especially our dependencies I mean, I remember having, like, fights with people internally
over, like, dependencies because sometimes, you know, I'm like, well, we could just, add this dependency and it would, solve this, you know, solve this problem and, like, we would and and they're they're be like, no. We're not we're just we're just not taking those on. We got to write it in house. And I think that
over time, I mean, at the time you could, you could, I mean, honestly you could say like that, you guys are just nuts. You know? But now it makes, like, so much sense. Right? Like, all of these things are getting busted. Dependencies are becoming less and less real. But I guess also, you know, in this age of AI and whatever, it is more,
tenable to, start writing things and having things inside the code base, and things like that. I think for me, it was such an experience of learning to just solve the things at the right layer.
Less trust is better than I mean, this this also carries the obscure. Right? Like, in Bitcoin, less trust is better than trusting, and no trust is even better. Right? If you can eliminate trust with technology at any point, you do that.
And that's always going to be the case. That's a great sound bite.
I I think coming out from and and there's also, like, a duty of care, I think, within Bitcoin Core that that's very ingrained in the culture when I was there. The duty of care of people who are writing security sensitive software. Right? I think most software engineering is plumbing mostly,
let's say. Just you're just plumbing dependencies together. But it's probably less complicated than actual what an actual plumber does, to be honest. It's it's it's just mangling things together.
But when you are talking about, you know, a trillion dollar asset, there there really is a duty of care, and so we really put a lot into it. So towards the end of that stint, what I was working on was Lip Bitcoin kernel, which is sort of a continuation
of of Flagler work. This is gonna sound a little bit nerdy, but there there used to be a library called Lip Bitcoin consensus, which was sort of trying to a library that was trying to encapsulate what Bitcoin consensus is, let's say.
Because for the longest time, the biggest worry was that if we had multiple competing implementations that and let's say we had, you know, 50% was Bitcoin Core and 50% was somebody else. If there is a bug, not even, like, somebody being malicious or whatever, a bug as to how the two clients interpreted
Bitcoin scripts or or or anything like that, there could be a chain split, and that that would be a a a pretty bad split. So there's there's always been a an effort to encapsulate consensus. The Bitcoin consensus is a previous thing that stalled, and I started Lit Bitcoin kernel, seems to be
going quite well right now. Not not not not thanks to me. I did like the groundwork, the easy work, and and handed it off to the charlatan who's been that that's his GitHub handle. I'm not calling him anything.
Who's who who's been doing great work there. And now we've got sort of multiple clients, multiple projects integrating with LipBake or Kernel. So I'm always very happy to see that even though I did, like, you know, the minimal, like, 3% to get it started.
Yeah. Yeah. It was a good guy to hand it off to. Charlotte is an awesome dude. He's actually been in the mineral space too for a long time, and his his handle is reproducibility matters. So you can tell that he he cares about this stuff too. That that that that did
you know, that that did ingratiate him with me for sure. Reproduce yeah. If you handle reproducibility, it matters. I'm like, this guy knows what's up. It's how you get it in with Carl for sure. For sure. So
it was like you were you were there for a while. What was the motivator or the driver for transitioning out of core? Was it Obscura? Was it just feeling like you had done your part and wanted to move on to other things? Like, what what why why that transition? What was that like for you?
Oh, I think with any transition, there's, like, multiple multiple things that that that are in the mix. Right? But you you touched on, let's say, the the the two main ones. I think it was very just thank you, Gooey.
It was very interesting because what was it? I think it was during COVID that I realized it's a COVID weekend project or something like that that I realized Molvad was offering, you know, Bitcoin.
You could buy Molvad for Bitcoin, but you couldn't do it with Lightning. And so I was like, okay. I should just, like, set up a shop or something like that so that, you know, people can buy Molgrade using Lightning. And I I was corresponding with their CEO at the time, very nice guy, you know, PGP encrypted mail,
you know, very I was like, yeah. This guy knows what's up, even though it's always a pain in the ass sometimes. And PGP email is not fun. But, you know, I set it up in a weekend and sort of just announced it and and and, you know, did minimal maintenance.
But I I just saw more and more people using it and telling each other about it and everything else, and people would come up to me and tell and I was like, this is
a form of joy I have never experienced in my life. I don't I just love seeing people use the stuff that I make and I was like, oh man, this, I gotta chase this high. This this this is a this is a very interesting like, I gotta I gotta I gotta chase this.
So it was very interesting, you know, I I wasn't I wasn't really meaning to go into anything. I was sort of just looking around after I I I got got out from Chaincode, but I remember looking into VPNs because, obviously, I know about VPNs quite a lot. And looking around and I saw Apple iCloud Relay.
I believe it was I believe it was one of the other Bitcoin core developers who told me about Apple iCloud Relay. And I was like, okay. You're not a you're you're not really an Apple guy. You're a Linux guy, so this must mean something.
And so I I took a look at the paper, and I was like, oh, they actually innovate. I did not expect this, but Apple actually did some innovation on this front. And, basically, the crux of it was, you know, they were going to do this two hop relay. The the the the
the the the one the one phrase that I use is, you know, how how they say attention is all you need. In VPNs, it's two hops is all you need, I think. Right? The the single hop VPN, let's say, which is all traditional VPNs, because it's a single hop, it's the only middleman.
Right? They they see who you are. They see the IP address you're connecting from, which is your home IP address that's, like, relatively static and relatively tied to identity.
And they see what websites you're going to because of TLS SNI, because of DNS requests, because of of various other things. Right? They just see the packets. And so if they wanted to, they could correlate, like, your entire browsing history, at least on the host name level, things like that. However, if you do two hops,
right, the tour is doing, like, you know, you know, six hops or more. But if you just do two hops, you have now separated the information of who you are,
So the first hop would see who you are but never where you're going, and the second hop doesn't know who you are. It only sees packets coming from the first hop, and they see the website that you're going to. So this is like a drastic improvement
in the private in in Internet privacy without having to change the IP stack. I think we all wish that the IP stack were were designed differently, but, you know, that's too too widely deployed not now for for anything to change.
But it was a drastic improvement in Internet privacy and VPN privacy, and they coupled that with, mask. And and forgive me if I'm getting too technical and also feel free I'm happy to clarify.
Mask is, this protocol that runs over HTTP three, and so the traffic looks like normal HTTP traffic. It doesn't look like it's it's it's WireGuard traffic or some, you know, undistinguishable traffic. I think it's so interesting because coming this is sort of from my years of dealing with the Chinese great firewall is that I realized
that Internet sensors, what they like to do is they like to like, you have to understand their point of view. Right? They want the good traffic to go through. They don't want the bad traffic to go through, but they they still want economic activity. So they do want, you know, traffic to apple.com, let's say, to go through. Right?
And so the best ways, let's say, to get around this sort of regime is to make your traffic look like good traffic as much as possible, right, which is exactly what mask does. It it it makes the VPN traffic look exactly like normal h t p three traffic.
And I thought this was so ingenious. I remember, like, just whipping up an implementation in in in in both Go and Rust just to prove that I actually understood it. Went to the IETF. It's like sort of the the wizards that design the Internet,
and, talking to them about it, and they they seem to I and was like, is this what you're doing? Is this like am I misreading? And they're like, yeah. This is what we're doing. This is like, you know, you you understood it right. Was like, hell, yeah. And so we we we took that and we ran with it.
And, yeah, we we built Obscura. I built a a fantastic team. Shout out Keith who's who's in the in the chat right now. And and we are now on, we started on from, macOS. We're on WireGuard. We're on iOS. We're on Android.
And just earlier this week, we are now on Windows. So just Linux left. I I I understand that people are very much looking forward to Linux. You have to understand Linux is not one operating system. It is an ecosystem or an infinite fractal of distros that we're trying to support here.
So two weeks. Yeah. Oh, yeah. Yeah. Two weeks. Nice. Nice. I just wanna take a step back and and one comment before I ask my next question. Like, this is such a simply elegant fix to to the problem. It just seems now that somebody's done it, it just seems so obvious.
And I was just thinking about when I first heard about it. Like, oh, that's so simple but now obvious. Why didn't we think about that ten years ago? So hats off. You mentioned around the two hops.
Who who are the two hops? What are the what are the involved parties? Yeah. So the two hops, it's we're the first hop, and Moldad is the second hop. So you connect directly to us through a a a quick base. It's it looks like h t t p three protocol, and then we talk to Moldad on the second hop.
So just to to break that down, I know you you touched on, like, how the hops work and who sees what, but I I really wanna make sure that it's clear for for the listener. So what what does the two hop give the what's the benefit for for the user? Like, what are they sharing with you? What does Movad see about them?
Let's let's kind of walk down that journey. Yeah. A 100%. So, you know, from the user to us, we obviously know sort of whatever payment information you you you give us. And by the way, we accept Lightning. We accept Monero, so we we don't have to know anything.
But you can also use your credit card, and and we we accept everything. But we know sort of, you know, your payment information and that, let's say, you're connecting from your home IP address or something like that. Right? However, you can think of the packets you hand us, let's say, as packets
inside a box that's locked with a key that only Moldad could open. And so when you hand your packets to us, we we just look at it. It's fully encrypted. We have no idea what the fuck is in it. Right? All we can do is hand it over to MolVad.
Right? Because only they have the key to this lockbox.
And so, you know, now, you know, the packet arrives at MolVad's side. The MolVad just sees, okay. Alright. From Obscura's side, there's, like, I don't know. There's there's there's thousands of users handing us packets. We don't know which user it is. We don't we have no idea what they are. They're not gonna share it with us.
We have these lock boxes. We're gonna unlock them and go talk to Google and then hand the lock box back, to to to the user, basically. And so from Obscura side, we know who you are. We have no idea what websites you're visiting or anything about your traffic.
From Moabad side, they have no idea who you are. They're just serving you the Internet. And so that's the separation there, and that's what brings the, superior privacy. I think it the the the phrase is no single party can unilaterally, sort of bind your identity to your browsing history. I think that's a very important guarantee
for, basic level of privacy on the Internet, I think. Yeah. And something I've I've raised before when we chatted about it is that I I think when people hear that, they think the TOR latency hit that you expect when you're using TOR. Like, you think multi hop and you go, oh god. This is gonna be this is gonna be painful.
But in reality, it's it's really not. Like, I I have been using this for a long time now. I mean, I've been, I think I started right bef like, a little bit before y'all went public and have been using it ever since on all my devices that that you don't really notice the hit compared to just regular mobile or just regular IPPN,
both of which are still fantastic. Like, definitely not ragging on them, but it's nice that you get the two hop advantage without feeling like you have this massive hit to latency or throughput or something like that. It it works quite well.
Another thing that I also said, so if anyone's seen a podcast with me and Carl before, but I'm doing this one on Obscura as well, and it's it's nice you can stream high quality video and, like, that it just doesn't it doesn't really hurt your day to day performance.
And I think something that I wanna dig into a little bit too, you touched on it with, like, Mask in Private Relay on Apple, but something that you've really focused on with Obscura is
having much better obfuscation of the fact that you're using a VPN, which obviously is just good from a an OPSEC perspective. It's less visible to your ISP that you're using a VPN, so you stand out less. But also
gives you the advantage of when you're on a network that would actively try to block a VPN, which, like you mentioned, the great firewall, which I would assume most of our listeners are not affected by or getting hit with. No. But there are actually a lot of public networks, coffee shops, stores, etcetera, that try to block VPNs as well.
Usually, just a misguided sysadmin who doesn't understand what they're doing. But sometimes, intentionally, because they don't want people doing sketchy things, whatever.
And that obfuscation helps there as well. Would you mind touching on, like, why that's so much of a focus for you? I know, like, the the great firewalls and influence there, but, like, what users should actually expect out of that and what it what it helps with day to day.
Yeah. A 100%. I think, you know, the obviously, the the the reason why I focus on this is because of my experience with the great firewall. But also, I mean, the same tech that Cisco sold China, let's say, for the great firewall, is the tech that's being used,
you know, at airports and whatever. They you know, there's a toggle for Cisco advanced protection, whatever, and and and they they sort of have this suite on. I think it's it's things like that where you have, you know, corporate firewalls that are trying to, in my opinion, misguidedly,
oh, this is not you know? I I remember when I was at Berkeley, I was at what I was at a cafe, like an in campus cafe. And for the life of me, I could not access I think I was trying to get on the Bitcoin Core IRC for for the Thursday evening or something. Sorry. I r c. I was just like, I couldn't get on. Was like there.
I was like, what is going to what is happening right now? Why is the IRC not did the IRC channel go down? And I was like, no. Like, the corporate firewall just did not allow IRC traffic for some reason. Right?
And so there are many cases like that where I'm gonna give them benefit of the doubt, misguided IT admins say, okay. We're not gonna allow anything other than port four four three. Right? We're we're going to also sniff your packets and try to look at, like, what your SNI is if you're going to anything but, like, mycorporatedocuments.com
or whatever. We're we're going to block that. I I think the the the craziest one that we have seen is a corporate network who will sniff TLS sort of a TLS handshakes and then inject back sort of like corrupt packets just so your your stuff doesn't work. It's kind of nasty.
But that that's that's why we designed our obfuscation. Right? We want to look like normal traffic as much as possible. We do quick, which is becoming increasingly common. In fact, most of you, if you're using Google, if you're using YouTube, most of the assets are now being served over QUIC rather than TCP,
which is sort of the the corollary being HTTP three and HTTP two. Right? And that's that's that that's to us, that's great because that's even more covered traffic, for the rest of us. And one very interesting thing for the people who are very technical, out there, I was talking to the this guy at the ITF, and it's so very interesting.
So one of the biggest problems because a lot of people will say, well, why are you using a VPN? You know? My traffic's all encrypted with TLS, you know, and things like that. Right? And I'm like, that's
that's the most first it's half right, which is the most frustrating type of right, let's say. It's just half right, so I can't say it's completely wrong. But, yes, TLS encrypts your traffic. However, in TLS,
when you start the connection, there there's something called the the the client hello. And in the client hello, there's a field called SNI, which shows in plain text to everybody the website that you're visiting. So that could be, you know, a WikiFeet
or something like that, right, or WikiLeaks or or whatever you're you're visiting that is all in plain text. And before QUIC and before all this obfuscation, this was, very easy to see, very easy to block for middle boxes. And so people started spoofing them, but still it's it's easy to to detect that. With QUIC and HTTP three,
one of the developers for Chrome did this thing called chaos protection whereby he would in QUIC, you can split up packets and rearrange them in whatever order you want. And the middle box is it's the it's sort of the end client's responsibility to reconstruct
them. And so in Chrome, what he did was he would break up the client hello, which is this plain text piece of, you know, you know, the website that you're visiting, and shuffle them all around in different packets and whatever so that for middle boxes to inspect it and block it, it would be super expensive
because now it's like a sorting problem. Right? You have to, like, cache the first few packets and then get all of the the frames out and then sort them and then try to reconstruct this, which is insanely expensive for middle boxes to do for thousands of, connections,
which is, you know, fantastic for for privacy, and that's, you know, also why we use QUIC. We love QUIC. Nice. Nice. Nice. I wanna take a step back for more user focused or facing stuff.
For somebody who either doesn't have a VPN or has been using one of the the lesser alternatives for some time, where does Obscura sit in terms of, like, the basic stuff they would expect? So, like, server locations, device numbers, cross compatibility, that sort of stuff. Where where do you guys sort of fit in into that landscape?
Yeah. So we've been really focused this year just on getting on new platforms. And so, you know, we're we're now on, you know, macOS, iOS, Android, and Windows, and with Linux, just coming.
I think to to sort of take a step back, for us, one of the most important things is that there shouldn't be a trade off between how usable a product is and how private it is. We think that those things can be synergistic at times.
And I think, you know, to a certain extent, Apple has done an okay job in in in that respect, but we really truly think that it is quite a shame that, you know, people have, sort of this, idea in their heads that, like, well, I'm I'm gonna use the hardcore product,
and the hardcore product's gonna be super hard to use. We're like, no. I I mean, it doesn't really have to be that way. We we want the user to be able to choose where along, sort of the the this this the spectrum of hardcore as they want to be because I think for Freedom Tech for privacy,
to win, we need to make sure that our solutions also make sense for the general audience. Right? I think we need to make sure that, we are something that everybody can use. And so we have a relatively simple interface, let's say, but there's always that button of experimental options.
You can look at it. It's it's all the the craziness that's all there. But for day to day use, I'll just say I use it twenty four seven on my Mac, on my iOS. Our our engineers are all all on, you know, Android and Windows and things like that and and and Linux, of course.
And so they use it there. And, of course, as Seth was mentioning before, I I'm using this on the call right now. And it's it's incredible how much, this model has worked out without having to incur, the burden that is you know, visiting a website on tour is it just takes forever. Right? You go grab a coffee and then the page loads.
Nice. Yeah. I I I can't help but want to highlight the irony that one of the hosts is having significant problems with their VPN on the show today. It is not obscure, to be very clear.
But the reason Matt I was like, is there a is there a relay outage that you know about? No. No. Not at all. The reason he's hopping in and out is he's having some networking connection. But are you back with us, Matt? Just a little bit.
I am back with you, I think. There is a storm outside. A tree did just go down, So it could be that, and it also could be the VPN. I'm not sure which one, but, yeah, maybe maybe I need to switch. You you point at a very good point, which is that a lot of times, like, networking problems are so opaque.
Right? Mhmm. Sometimes when, like, a user sends us, like, you know, a support query, we're just like, we don't know what's going on, but maybe a cat stepped over your power cable to your router. Maybe, you know, your ISP is just having a bad day.
Maybe your your, you know, your your your neighbor somehow found a way to emit enough packets to break the spanning tree protocol on your local network. It's so difficult to to know, what is actually wrong. It kinda goes into this is gonna be a little bit off topic here of I think one of the reasons why sort of more
decentralized and and sort of open participation network routing networks, fail in some aspects. Right? So if you think about, you know, volunteer run networks like Tor, it really takes a cat tripping over a wire somewhere
for it to go down, let's say, for for your, you know, route to to not work anymore and you have to go somewhere else. And that just sort of it's not very tenable for, like, business situations where, you know, we're doing a live podcast right now. Yeah.
Yeah. Absolutely. And because of that and I don't have no idea whether it's a cat or a storm or the VPN. I have no no idea. Definitely. But it does mean that I've missed like, probably 60% of what's been said. So my question is probably gonna be a bit random and and not too linked to this, but I do wonder. We were talking before we joined
a little bit about AI usage and explaining how Seth is just a complete addict at this point. Queue is is not far behind either. I wondered how you with seeing it, how has that affected the work that you do? Like, generally, how has it affected Obscura, or are you not touching it at all?
I I I'm I'm glad we held out for forty minutes without talking about AI. Very, very, very well done. This is the right crowd. I don't know, man. It's a new record. No. It's it's I think it definitely changes the way we work. I think I'm a
I don't know. I'm I'm a guy who doesn't really I don't know. Suffer fools is not the not the right word. I just I I I'm I'm very, pissed off a little bit when people, you know, hand me things. It's like, this this is not well thought out. And so I think, like, before Fable, I was always like, this is not
this is just not up to the bar. Is not up to the bar of excellence. This is just actual slop, but, like, I'm I'm having to correct it too much. But after Fable, I was like, I'm kinda sold, man. Like, this is this is kind of really good, and this is like this is really going to change the way we work. I think internally at at Obscura,
we obviously are going to use AI to to speed up some of our work and things like that. However, I think our bar for that is always going to be that there's the there's the famous IBM manual, thing where it's like,
businesses decisions should never be made by computers because computers can never be held responsible. Right? That sort of underpins how I see, you know, AI usage and things like that. It needs, people can use it as a tool because
saying that, you know, you're not not allowed to use a tool like some repositories do, I think that's just ridiculous. Like, it's it's an it's completely unenforceable. It's completely you know, it just doesn't make any sense. And when you when you make rules that are completely unenforceable,
right, you just reward the liars, which I think is, like, really bad precedent to set. For us, it's really about it's a tool that you can use, but at the end of the day, people are responsible for their own outputs. Right? People are responsible
for the PRs that they are writing, for understanding it, for being able to explain it to the team, for being able to to defend it. Maybe, like, this is too much of the Bitcoin court culture of, like, you know, you have to make sure all the PRs are correct or whatever. But I I think this is pretty, you know, par for the course for security
focused, products and things like that. I I am so far from you know, there are people who tell me, okay, I I just don't look at the code anymore. You know? I just I just let it I just program in English down. I'm like Yeah. That doesn't sound horrifying. I don't know. I don't know. It's a little horrifying for me.
Yeah. I think with anything, it's about cautious exploration. Like, figuring out what Yes. What about your existing workflow that smart people are already doing can you optimize around or do away with because you're able to offload it?
Rather than like this, I feel like a lot of people view it very zero or one, like, black or white, where it's no
AI. Good god. We're never gonna touch that. We're never gonna allow it. Or we'll just vibe code everything, and we'll never look at the code like you said. And I think there are there are some specific cases where, like, even that side is totally fine, like, that you don't actually review the code yourself.
Oh, if I'm if I'm writing a crud app, I I'm never writing crud apps with boiled plates ever again. You know what I'm saying? Like Exactly. Exactly.
There are things you can do away with, but in something like like Obscura and something like cake and something like Bitcoin Core, like, you're dealing with people's security or money or privacy,
you have to be really cautious. And yet there are really good things that it can be used for and really good things on the security side, like you you were talking about dependency security and how you manage that. And as projects get bigger and bigger, it becomes almost impossible to
actually keep an eye on all of the upstream dependencies and exactly what they're doing in every release and validate every pin that you wanna migrate to line by line. But, yeah, it does make that more tenable.
But, yeah, it's it's it's gotta be cautious exploration and figuring out how do we amplify the talent we already have rather than Yeah. Replace the talent, which is often the conversation even though it shouldn't be.
Is it sort of fair you you kind of have AI as workers that are then gonna bring you things for you to review and give the green light on things? You can kind Alright. Here here is 20 things that I've picked up that could be a problem or I think could be improved, and then it's your decision to then
push that forward or not. Because, you know, I'm not a technical person. I do everything on the visual side here. So I'll I'll have AI generate a lot of stuff, and then I'll review and adjust and review and adjust. And nothing goes live and nothing is shown until it's dialed in by me as a human being, but it makes the the first 80%
much, much quicker and easier for me to do. So it saves time. I assume that's the same. And what I'm seeing from you, Seth, like, from what you said, it's just it's reviewing all of your code overnight. You wake up, and then you're like, okay. Here are some potential issues or changes.
Yeah. I mean, it's gonna differ, obviously, workflow to workflow. But yeah. I mean, like, our primary one right now is per PR reviews, per release candidate reviews, regular whole repo reviews,
and now dependency scanning, where we're scanning every night all of our upstream dependencies if they change at all, or if we change the PIN specifically of what what exact PIN commit we're using
so that you can keep an eye on that. But it does I mean, it it's always pros and cons because that also does mean that I, like, I woke up with a 117 messages about dependency vulnerabilities that I have to look through. And most of those, like, 99%, are not gonna be something that
we would fix or even need to be fixed. Like, a lot of the work has to go into tuning to make it something that's reasonable. Like, we just started dependency scanning, so it's very noisy right now. But there are always pros and cons with that. And yet, in the same way, we found a a,
I would say, medium severity vulnerability in an upstream dependency. Nothing that affects funds or anything like that, but found that yesterday and would not have found that otherwise. No one else was looking for that even though everything's open source, other people should be looking for that.
So, yeah, it's it's always it's always pros and cons. Yeah. For us, that's the main use. We're slowly iterating it into the code side. But, yeah, I think it has to be has to be cautious on, like, the actual code generation side.
But really good, at least to start as just like an additional code reviewer. It's helpful there. Mhmm. Nice. Carl, I wanted to take you back to obscure just quickly. From an from an outsider, somebody who's tried many different v
it feels like you've you've pretty much with the exception of the the usual when Linux questions, which you've already addressed. It feels like you've got the the complete the finished product. Like, is this end state or what what have you got next? What have you and the team got planned?
Oh, no. We got we got we got big plans. The I think well, there's there's always the question of, you know, having more choice for, let's say, the second hop and the exit hop, let's say, other than Moldad and perhaps other providers and things like that.
And I think one of the biggest problems that haunt the industry is IP reputation. I think it is a problem that is slowly solving itself over time. It gets worse at times. It gets better at times. I know Yelp for a long time was, like, straight up did not return anything.
If it was from, like, I'm all about happy now, they, like, actually return return something. And and so by by the way, so so for context, IP reputation is when you go visit a site and the site is like, looks like you're coming from a VPN.
Goodbye. Which is not the user experience that we want. Not the user experience that that I would everyone I don't know. My parents having or something like that. Right? I think there are multiple ways of doing it. I think
what's the most interesting thing that we're exploring at a technical level is just fine grained split tunneling. What what and what that means we call it smart routing. I think smart routing makes a lot more sense.
It just means let's say, you know, I'm visiting my my bank's, you know, URL. My bank already knows everything about me. Knows where I live. Right? It knows the most about me other than, you know, my closest friends and relatives. And so,
for me, it's okay if my bank doesn't go through the VPN, if they're going to block the VPN. I just wanna be able to exclude it. I don't want to have to, like, micromanage my VPN, turn it on, turn it off, and then, you know, do whatever.
I think the micromanaging is such a terrible experience that I think we should be able to just exclude it. Much like if you guys use uBlock Origin,
which is the the the the best ad blocker in the world, by the way. And if you use uBlock Origin, you could go on a site and you're like, well, it's not working. Let me just turn it off and then reload the page and then everything works. Right? That that sort of, I think, the better way to do it.
In the future, I think we can all also have okay. Maybe, I think we're I was trying to book I was trying to book an office for our team for our off-site or something, and it was like,
we had our off-site in Japan. And all these Japanese sites, they just would not serve you any content if you were not in Japan. And so I was like, okay. Actually, what if for all .jp sites, we used the Japanese server? Right? What if for all whatever sites, we use that server? What if we could build
a list like how uBlock Origin does of, like, what sites are better visited from what country? I think that is sort of the future of where VPN is because at the end of the day, you want to be able to turn on your VPN and never have to even
know or worry about it. It should just deliver you the best version of the website, the best version of the Internet wherever you are, and that's sort of the vision that we're, working towards.
I mean, if if there's one word to focus it is eliminate the the micromanaging of the on off toggle, which I know all VPN users have to do right now. Looking forward to that. There was a a a question posted by an anon on Nosta who goes by security pleb.
And they they were they were asking, can we get a fastest connection feature, and could it automatically rotate the connections in the background?
So fastest connection is probably going to be quick connect. So if you go to your connection page on Obscura and you click quick connect, that's most likely your fastest connection.
Obviously, you know, the network environments change and whatever. We don't guarantee it to be the fastest all the time. But I guess that that that ties into your second question, which is like, we smart migrate between connections?
I think right now there is not too much of a difference between sort of the various exits. If you're talking about sort of the various exits in a single location that Mulvan has, there's not too much variance there.
We do pretty good round robin there, so there shouldn't be too much of a problem. But I'd be happy if he reached out directly and told me what his exam problem was, and we'd be happy to look into it.
Awesome. Well, I'm sure sure when they listen to this, if they're not catching it live, then they'll be sure to get Thank you, security pleb. Yeah. Absolutely. Yeah. Thank you. It was lovely when the the young governables post their questions.
Carl, we are almost up on time. Before we we close out, I just wanna give you an opportunity to to send people to the right places, any documentation,
where to get started, things to look out for, or, you know, just sign both people to your stuff before we wrap up. Because I wanna I wanna help spread the word because this is, again, an incredibly simple product that's well priced, and I I wanna see it, you know, continues to succeed.
Thank you so well, everybody can go to obscura.com. You know, it's spelled that way, you know, wherever it is. Obscura.com. And, you know, we're we're just launched on Windows. Oh, use code windows 26, for 25% off.
That's a that's a freebie right there. Join our Discord. We have a bunch of very interesting people there. I I don't I I I don't know if I'm allowed to say this, but one of our top Discord users is called Linus Sextips, and he's very active,
and he helps people on the Discord. She's every time I see that name pop up on my phone, it gives me a little chuckle. Yeah. We're we're we're networking nerds. We love to hear from you, and we'd love to hear your ideas and what you guys think. So yeah. Oh, and also, you know, we've done an audit last year.
Just click on our blog when you're on obscura.com, and you'll see it. Awesome. Well, I'm gonna be sending Mac straight to your website to to fix his networking issues, hopefully. Yeah. And hopefully, he'll he'll have a bit more of a stable connection next week.
Carl, this has been a real pleasure. The hour has flown by as it always tends to do. Mac, Seth, thank you very much for joining us, and thank you as always to all the ungovernables joining the chat, posting your comments, and just getting involved and helping spread the word. As always, we will be back at the exact same time next week.
Carl, Max, Seth, ungovernables, hope you all have a wonderful weekend. We will see you soon. Cheers, guys. You have a good one.
Thank you for listening to Freedom Tech Friday. To everyone who boosted, asked questions, and participated in the show, we appreciate you all. Make sure to join us next week on Friday at 9AM EST and 2PM London.
Thanks to Seth, Max, and q for keeping it ungovernable. And thank you to Cake Wallet Foundation and my Nim Box for keeping the ungovernable misfits going.
Machine transcript; expect the odd mishearing. Click a passage to play from there.




