Live data from Hacker News

Warp – Mobile VPN

blog.cloudflare.com

71–80 of 500 posts

Re: Warp – Mobile VPN

#71

I wonder how well this works when using using wifi on and accessing a corporate intranet. I discovered https://myhrportal didn't work when I pinned my DNS to 8.8.8.8.

What made you think your corporate HR portal's DNS entry would be global? You're going to at least need a TLD there, buddy.

Re: Warp – Mobile VPN

#72
I just signed up. cloudflare is on the short list of Internet companies that I trust (with the usual small bit of doubt and skepticism!). With just a few reservations, I also trust G Suite, Firefox, and a few hosting companies I do business with.

I have been supporting FSF, ACLU, etc. for years, but the practical considerations that prompted me to be a bit more trusting are Cloud Search in GSuite, Cloudflare offering HTTPS to help get the web more secure, and a deep appreciation for having Firefox available (containers are so easy to use and make me feel more secure in my use of the web).

Re: Warp – Mobile VPN

#73
post #58
post #49

> 1. We don't write user-identifiable log data to disk; That's great... but you do log user-identifiable info? How I read that is "we log things that can identify you but just keep it in memory for X amount of time". Myself and other privacy-minded folks would like to know more details there, especially as this is a freemium service.

>A VPN for People Who Don’t Know What V.P.N. Stands For I don't think their target audience includes those people (privacy minded folks.)

True. But that doesn't preclude you from offering the same amount of privacy. I suppose they want to catch abusers or find some other way of monetizing it, but that has nothing to do with the demographic they're chasing.

Re: Warp – Mobile VPN

#74

Earlier quoted context omitted.

We do not currently plan to allow third-party WireGuard clients to connect to the service.

Asked differently, do you plan on explicitly disallowing/banning it if people unofficially ran the reference implementation against Warp? It would be nice to know the policy there. For those of us that do know what a VPN is, and are okay not having access to support, getting things to work without a desktop app would be nice.

I think my answer was pretty clear. We do not currently plan to allow stock WireGuard clients to use Warp. I say, currently, because things can always change.

It's important to appreciate that we have literally millions of users for the 1.1.1.1 App and we are rolling out a free VPN for them. That is a huge support and network burden that we have to deal with to make that experience work well. Yes, we use WireGuard under the hood (and have open sourced our Rust code), but the additional cost of supporting people connecting from their WireGuard clients means that we don't want to support that _today_. Please bear with us while we get through a massive roll out.

Re: Warp – Mobile VPN

#75

Earlier quoted context omitted.

It it just me or does it sound wrong to call wireguard, the kernel module, third party software in this context? That's literally the reference implementation.

It is wrong. Warp is the third-party implementation. It would be amazing if it could be made to work from standard wireguard, but I suppose there's a chance that if desktop versions arrive, you'll be able to extract the keys. The only thing stopping that would be if Cloudflare broke the protocol.

We can argue about the terminology but from the perspective of the company other WireGuard clients (including the official ones) are 'third-party' in the sense that we don't control them. That makes supporting users of those clients more expensive for us (e.g. we currently have a mobile app for Warp, someone calls our support asking for help with a Linux client...)

Re: Warp – Mobile VPN

#76

I just signed up. cloudflare is on the short list of Internet companies that I trust (with the usual small bit of doubt and skepticism!). With just a few reservations, I also trust G Suite, Firefox, and a few hosting companies I do business with. I have been supporting FSF, ACLU, etc. for years, but the practical considerations that prompted me to be a bit more trusting are Cloud Search in GSuite, Cloudflare offering…

maybe you've forgot Cloudbleed https://en.wikipedia.org/wiki/Cloudbleed Thanks for downvoting.

Re: Warp – Mobile VPN

#77
While this might improve user experience for some, I don't see the greater value in a VPN solution like this.

It's the fast path to replacing the decentralized internet with a few proprietary CDNs. I'm much more excited about those projects that actually try to fix the raised issues:

Unencrypted connections -> TLS / Letsencrypt

TCP sucks on mobile/roaming devices -> QUIC & HTTP/3

Re: Warp – Mobile VPN

#78
There’s a lot of claims about how mobile internet sucks and this makes it not suck. But then it’s revealed it’s a WireGuard based VPN. What I don’t understand is how my internet will be so much faster than any other use of WireGuard?

Re: Warp – Mobile VPN

#79

While this might improve user experience for some, I don't see the greater value in a VPN solution like this. It's the fast path to replacing the decentralized internet with a few proprietary CDNs. I'm much more excited about those projects that actually try to fix the raised issues: Unencrypted connections -> TLS / Letsencrypt TCP sucks on mobile/roaming devices -> QUIC & HTTP/3

Cloudflare pushed out free TLS years before Let's Encrypt and we are actively working on and supporting QUIC and HTTP/3. But QUIC/HTTP/3 aren't here today, not everyone is using HTTPS and there are other worries in coffee shops etc. hence a VPN service makes sense.

Re: Warp – Mobile VPN

#80

I just signed up. cloudflare is on the short list of Internet companies that I trust (with the usual small bit of doubt and skepticism!). With just a few reservations, I also trust G Suite, Firefox, and a few hosting companies I do business with. I have been supporting FSF, ACLU, etc. for years, but the practical considerations that prompted me to be a bit more trusting are Cloud Search in GSuite, Cloudflare offering…

maybe you've forgot Cloudbleed https://en.wikipedia.org/wiki/Cloudbleed Thanks for downvoting.

I trust Cloudflare to do their best, generally respect privacy, and not act maliciously.

I don't trust cloudflare to not make mistakes (like Cloudbleed). I don't trust myself to not make mistakes. I don't think there is anyone I trust not to make mistakes. It's just not a reasonable criteria.

Post reply on HN