The VPN industry runs on a promise. Pick almost any provider and the pitch is the same: "we don't keep logs." You hand over your entire internet connection and, in return, you get a pinky-promise that nobody is writing anything down.
For a lot of privacy-minded people, that promise stopped being good enough a while ago. A no-logs policy is only as honest as the company making it, and even an honest company can be hacked, subpoenaed, or quietly acquired.
Obscura VPN is trying to answer to that problem. Instead of asking you to trust its word, it splits the job across two independent companies so that neither one can tie your identity to your browsing. The first hop is Obscura's own servers; the exit hop is run by Mullvad. a respected VPM company out of Sweden. Your traffic is end-to-end encrypted to Mullvad's keys, so Obscura literally can't read it, and Mullvad never sees who you are.
The person behind it is Carl Dong, a former top-5 Bitcoin Core contributor who signs off his own website as "head-janitor" and "I fight for the users." I sent him a set of questions around Obscura. Here's the conversation.

You went from being a top contributor to Bitcoin Core to founding a VPN company. What convinced you the VPN space needed rebuilding rather than just improving?
"Don't Trust, Verify" is a cornerstone of the cypherpunk principles I grew up with. I see this Trust Minimization as crucial when building human-centric, security- and privacy-critical technologies. Yet the VPN industry is riddled with scandals (e.g., Onavo), broken promises, and "no-log" pinky promises. This never sat right with me.
When I saw what Apple's iCloud Private Relay was doing under the hood, I saw what the next generation of VPNs would look like: VPNs that are verifiably private and that outsmart internet censorship. I wanted to make this a reality outside of Apple's walled garden. The world doesn't need another VPN company; it needs a totally new approach to privacy.
Your whole pitch takes direct aim at the "no-logs" model everyone else uses. Why has that promise become inadequate?
The VPN industry is living in the past. Three conglomerates dominate and give the illusion of choice, while betraying their users' trust and operating a payola scheme using media cut-outs to push their talking points. The no-logs pinky-promise has never been adequate for software that can access the entirety of your internet traffic, and verges on being useless in 2026 when LLM-driven cyberattacks run rampant.
At the end of the day, even honest VPN providers who abide by their no-logs policy can be hacked. Users are waking up to this, and there's been an increasing call within the cybersecurity community to stop using VPNs altogether. Obscura is a direct answer to this: you no longer have to trust any single company's word for your internet privacy. That's the way it should have always been.
Walk our readers through the two-party relay in plain terms. How does it actually change the trust model compared to a normal multi-hop VPN?
When you use a traditional VPN, a single company sees your identity (via your connecting IP + your payment information) and your internet traffic. Using a multi-hop option doesn't change the fact that it's still a single company, and oftentimes just adds additional latency for no good reason.
With Obscura's Two-Party Relay, we use a fully independent company (Mullvad) as our second exit hop, with Obscura as the first hop. All of your internet traffic is encrypted to a key controlled by Mullvad's servers, and only relayed through Obscura's servers. That way, Obscura's relay servers never see your actual internet traffic, and Mullvad's exit servers never see your identity (connecting IP or payment information).
For those familiar with Tor, it's like if Tor only had 2 hops, but the hops were dedicated, high-performance hops optimized for maximum speed and reliability.
A skeptic could say you've just moved the trust problem around. Now users trust two companies instead of one, and the two of you could collude or be compelled together. How do you respond?

I'd first lightheartedly point out that using traditional VPNs is just moving trust from your (possibly regulated) ISP to a single wholly unregulated private company. π
In all seriousness though, our goal with Obscura is to make sure there's no single party that can jeopardize your internet privacy. No one entity should have that power. With Obscura, as long as either Obscura or Mullvad isn't compromised, no one can correlate your personal identity with your internet activity. This is strictly better than trusting either your ISP or a traditional VPN's pinky-promise.
Let's get technical. Your stealth protocol is built on QUIC to mimic HTTP/3 traffic. Why QUIC specifically, and how does it hold up against serious censorship?
We chose QUIC not only because it looks like HTTP/3, but also because its Unreliable Datagram extension allows us to avoid the TCP-over-TCP meltdown problem that plagues TCP-based VPNs. I'd encourage folks to read this for more details.
As for outsmarting censorship, QUIC has been notably harder for middleboxes to do Deep Packet Inspection on. QUIC allows messages to be fragmented and shuffled across UDP datagrams, which means censorship systems have to reassemble them, making it far more costly. I don't know of any QUIC censorship system currently deployed that does reassembly. More information can be found here.
You accept Monero and Bitcoin over Lightning, need no email, and log in with just a random account number. But Obscura still sees the user's connecting IP. How anonymous can a user really be, and where's the honest limit?

We view consumer data as toxic waste. We don't want it, don't need it, and do as much as possible to make sure you don't have to give us any. Aside from what you mentioned, our website is also accessible over Tor.
But you're absolutely right. We can still see the user's connecting IP address. That will not change unless humanity completely rethinks the OSI stack, which will make the IPv6 transition look like a walk in the park. π
The fact that we can't avoid seeing your connecting IP address is the point of Obscura though: if we have to see it, then the most private thing to do is to completely decouple that information from your internet traffic. That's what our Two-Party Relay does.
You've open-sourced the client and talk a lot about reproducible builds, clearly something you carried over from Bitcoin Core. For a non-developer, why do reproducible builds matter for a VPN?
I did a lot of reproducible builds work for Bitcoin Core, so this is near and dear to my heart. I believe that reproducible builds matter for any piece of open-source security-critical software. Even if the published source code is not malicious, that says nothing about the app you download. It essentially answers this question: does the app that I download correspond to the source code that is on GitHub (or whatever other forge you may use).
For Bitcoin Core, a malicious app could mean loss/theft of funds. For VPNs, a malicious app has access to the entirety of your internet traffic and can leak that regardless of the security of your VPN provider.
At Obscura, we of course take reproducible builds seriously. We already have a prototype for Android reproducible builds, and are looking to make other platforms work as well.
Obscura is $8/month, and reviewers note that stacking two providers can cost more than one. Beyond the privacy story, how do you make the economics work as a small team without VC pressure to monetize users?
First, we have no user data to monetize. Second, I think in the tech world we've vastly overcomplicated our businesses. For a business to work, you need your costs to be lower than your revenue over time. That's it. We aren't going to construct a massive data center. We aren't going to put tens of millions into R&D in a lab in Switzerland. We're a small group of six people, working remotely, charging fair prices. As long as we keep our customers happy, we don't have anything to worry about. My goal was never to compare yachts with Bezos.
There's a classic tension between maximum privacy and everyday usability, with Tor as the usual cautionary tale. Where do you draw that line?
The goal is for my mom to use Obscura, and she does! (Hopefully not just because I'm her son.)
I don't think that tension between privacy and usability is always inherent: a VPN doesn't have to be complicated. You should flip a switch and it should just work and you should forget you have it on. The goal is to be seamless. Power users and technical folks who want more should always have the ability to tinker, and we offer that, but the goal is to build a product so good that both feel right at home.
Oftentimes we've also found that giving users a choice is the way to go: while cryptocurrencies may be the most private way to pay for Obscura, my mom is likely to want a credit card option. π
Looking at the next few years, with encryption under legislative pressure and tracking everywhere, what worries you most about online privacy?
Every day there is another story about a country or international body proposing new rules that jeopardize the open and free internet we all love. Sometimes these are well-meaning protections that legislators don't fully grasp the ramifications of; other times their motivations are less noble.
What all these scenarios have in common is that, somewhere along the way, behavior that was once considered odd and Orwellian became normalized. You go grab a coffee and you give them your phone number, then you download an app (and allow location permissions), and before you know it companies know every aspect of your life.
Then when you read about how the government can legally purchase this data from data brokers, you start to appreciate just how much of your life can be reconstructed to where you essentially have given away every aspect of your privacy for a free coffee on your birthday. (I'm as guilty as anyone.) So what really worries me is our own complicity in trading privacy for convenience. And I hope with Obscura and other smaller privacy-focused start-ups we can make an easier, simpler to use tech that helps protect people and allows them to make better privacy decisions where there is no trade-off between convenience and privacy.
Finally, a fun one. Your site has a "Cursed Knowledge" page. What's the most cursed thing you've learned about how the internet actually works since starting Obscura?
I think the TLS SNI extension has gotta be one of the most cursed things about how the internet works.
Most people assume that if a connection is encrypted by TLS, then it's fully encrypted. What they don't know is that there's a part of every TLS connection called the SNI where the server's domain name is in plaintext, completely unencrypted! In fact, ISPs and middleboxes often use this as a way to enact internet censorship, since it's a much more reliable mechanism than trying to match connections with DNS requests.
Last year, Obscura was erroneously blocked by a few US ISPs, and SNI was exactly what they used. Of course, using a VPN protects you against that, but it's still quite cursed that TLS has this at all. Hopefully Encrypted Client Hello gets adopted soon so that we can have actual secure TLS!
Whether Obscura's split-trust model is right for you is up to you to decide, but it's definitely a different approach to a problem the VPN world has glossed over for years. The client is open source, so you don't have to take any of this on faith. You can read the code, check your exit hop's key against Mullvad's published list, and verify the claims yourself.
You can learn more at obscura.com, and the source is up on GitHub.