MultiOBX

Secure connection

One key.
No e-mail, no password.

MultiOBX encrypts all traffic from your computer or phone and routes it through our server. Instead of a login and password you have a single 24-character key. We do not store it and cannot remind you of it if you lose it.

While the tunnel is up, nothing leaves the device around it. If the tunnel drops, the internet goes away until it reconnects; it does not fall back to a direct connection.

Diagram: this computer, the gate, the internet through the tunnel THIS COMPUTER DIRECT GATE TUNNEL INTERNET
The rules that close the direct route are put in place before the tunnel comes up and are removed only when you press "Disconnect".
24characters in the key, nothing else to type
0names, e-mails or passwords in the database
5devices per key
1button that opens the direct route: "Disconnect"

01Getting started

Get a key

Press "Create a key". The key is shown once, write it down right away. There is no registration and nothing to confirm.

Pay for time

Days are added to the key. You can pay with a voucher or with a numbered order. There is no subscription with automatic charges: when the days run out the tunnel stops coming up, and what happens next is up to you.

Install the app

Enter the key in the app. Up to 5 devices can be attached to one key. Each gets its own address inside the tunnel and its own WireGuard key pair; the private key is generated on the device and never sent anywhere.

More about how it works

02What data we have

We have

  • A digest of the key. Not the key itself.
  • The public keys of your devices and their addresses inside the tunnel.
  • The date your paid time ends.
  • Order numbers, if you placed any.

We do not have

  • Your name, e-mail or phone. There is nowhere to enter them.
  • A password. It does not exist.
  • Browsing history. The servers keep no connection logs.
  • Your computer's name. A device gets a random name from a word list.

Through the tunnel you are still you. If you sign in to your mail, the site recognises you by your login, not by your address. The tunnel hides the address and the route, not the person.

What a key digest is

The digest is the result of a one-way function applied to the key (in our case HMAC-SHA256 with a secret kept in a separate file on the server). Computing the digest from the key is easy; the reverse is not possible. When you enter the key, the server computes the digest again and compares it with the stored one. If they match, you are in. So a stolen database lets nobody sign in, and a lost key cannot be recovered, not even by us.

03Limitations

Hyper-V and WSL on Windows
Hyper-V virtual machines and WSL have their own network stack, and Windows rules do not apply to it. Traffic from there can bypass the tunnel.
The first seconds after boot
Until the service has started, there are no rules yet. Persistent rules that apply from system boot are not implemented yet.
Android and iOS
Both systems let some of their own service requests bypass any tunnel: connectivity checks, time, a few services. This is a platform limitation.

How the protection works, point by point

04Pricing

1 week
115
7 days
1 month
350
30 days
3 months
1005
335 ₽ per month
90 days
6 months
1860
310 ₽ per month
180 days
best value
1 year
3420
285 ₽ per month
365 days

The longer the term, the cheaper each month works out. Payment is made from the account page after the key is created. Details on the pricing page.