Live data from Hacker News

Warp – Mobile VPN

blog.cloudflare.com

121–130 of 500 posts

Re: Warp – Mobile VPN

#121
I'd wager that the Super Secret Plan is geared towards further centralizing the Internet. Preferably on Cloud Flare's infrastructure.

This is one part of a tug-of-war that's going on in recent years between Internet network operators and cloud providers, with the cloud providers slowly but surely winning.

For better or worse, we are moving away from a distributed Internet composed of many autonomous networks into a future in which the only job of the ISPs is to connect homes and offices to the local POPs (Points Of Presence) of the large cloud providers.

Why do you need connectivity to other networks when you can get Google (w/ Youtube & GCE) and Facebook from a local POP? Add to that all the sites and services that reside on Amazon, Azure, Cloud Flare, Akamai, and maybe a few more large clouds/CDNs, and you don't need a public Internet anymore. Imagine the security and performance benefits of that!

Re: Warp – Mobile VPN

#123

It seems to me that in practice, Cloudflare's mission is not actually to build a better Internet, but to offer an alternative, proprietary network (one could call it the CloudflareNet), and convince content providers and consumers to use that network. Because I don't want any single company to have too much power, I'll stick with the standard Internet, which is not owned by any single company. However, I realize that…

I disagree with this statement. We haven't pushed incompatible standards or any other nonsense. We've literally pushed out the latest standards and enabled more encryption (see Universal SSL making SSL free years before Let's Encrypt; see enabling IPv6; enabling HTTP/2; etc. etc.). As for HTTP/3... so will we. See: https://blog.cloudflare.com/http-3-from-root-to-tip/ , https://blog.cloudflare.com/the-road-to-quic/ an…

You've built a product (warp) based on Wireguard and refused to work with the upstream project - so saying that you're pushing standards is far more nuanced than you make it seem - at best.

https://news.ycombinator.com/item?id=19500725

Re: Warp – Mobile VPN

#124

Earlier quoted context omitted.

> What I found most interesting, was that there were some use-cases when the network with Wireguard performed even better than without it (probably related to congestion control). It could be the different routing. Your ISP's routing might be sub-optimal to certain destinations. After all, it chooses routes based (at least in part) on cost, not performance. There are commercial products that do this sort of tunneling…

Possible but I am not exactly sure what caused the difference. I used fast.com for testing and when I increased the number of parallel connections the performance degradation was lower when using Wireguard. I assumed that it is related to congestion control as Wireguard uses UDP AFAIK and otherwise I would use TCP on the bottleneck part of the connection.

Wireguard might be using UDP, but you're still tunneling TCP on top of it. So the congestion control is still there and kicking.

Re: Warp – Mobile VPN

#125
post #112

Earlier quoted context omitted.

Are there any other legitimate certs issued with IP address altnames?

dns.google 8888.google 8.8.8.8 8.8.4.4

Oddly https://8.8.8.8 doesn't have a legit cert though (even though the cert for 8888.google does have an IP address alt)

Re: Warp – Mobile VPN

#126
post #123

Earlier quoted context omitted.

I disagree with this statement. We haven't pushed incompatible standards or any other nonsense. We've literally pushed out the latest standards and enabled more encryption (see Universal SSL making SSL free years before Let's Encrypt; see enabling IPv6; enabling HTTP/2; etc. etc.). As for HTTP/3... so will we. See: https://blog.cloudflare.com/http-3-from-root-to-tip/ , https://blog.cloudflare.com/the-road-to-quic/ an…

You've built a product (warp) based on Wireguard and refused to work with the upstream project - so saying that you're pushing standards is far more nuanced than you make it seem - at best. https://news.ycombinator.com/item?id=19500725

Forking an upstream project to implement decisions without upstream’s consent is a tried and true open source software process, implemented by thousands of projects over the years. Claiming that they don’t support standards, solely because they don’t support another implementation of those standards, is incorrect and inflammatory.

Re: Warp – Mobile VPN

#127
post #64
post #19

Earlier quoted context omitted.

1.1.1.1 doesn't use eDNS and likely never will: https://developers.cloudflare.com/1.1.1.1/nitty-gritty-detai... So geo-specific things will break... BBC.com should load though since its for out-of-UK people

Site should load just fine without eDNS -- even "geo-specific" ones. They will just route you as if you came from your local Cloudflare PoP rather than your home IP; usually not a big difference since Cloudflare is in so many locations. I'm not having any trouble with bbc.co.uk on 1.1.1.1, maybe it was a temporary hiccup. (Disclosure: I work for Cloudflare but not on this product.)

It was intermittent. Sometimes it worked, sometimes it didn't. The error message given suggested it was trying and failing to find a cloudflare hosted site (which to my knowledge the BBC isn't). Unfortunately I can't remember exactly what the error said.

I'll try it again for awhile and see if I have any issues now.

Re: Warp – Mobile VPN

#128

Earlier quoted context omitted.

> What I found most interesting, was that there were some use-cases when the network with Wireguard performed even better than without it (probably related to congestion control). It could be the different routing. Your ISP's routing might be sub-optimal to certain destinations. After all, it chooses routes based (at least in part) on cost, not performance. There are commercial products that do this sort of tunneling…

Could also be packet-shaping/QoS on the ISP side

Sure. Especially in countries that don't have network neutrality...

Re: Warp – Mobile VPN

#129

Cloudflare, are there plans for ad blocking? Currently using AdGuard DNS and it works well. Router-level ad-blocking would be an attractive premium option.

If Cloudflare provides CDN services for advertisers, you likely won't see adblocking products from them.

That is not something which has factored into the conversation on our (Cloudflare's) end. The bigger issue is even as we make technical improvements, we very much don't want to create a separate Internet. The minute we begin adding, removing, or changing content when it comes through Warp those questions begin to be asked.

Re: Warp – Mobile VPN

#130

It seems to me that in practice, Cloudflare's mission is not actually to build a better Internet, but to offer an alternative, proprietary network (one could call it the CloudflareNet), and convince content providers and consumers to use that network. Because I don't want any single company to have too much power, I'll stick with the standard Internet, which is not owned by any single company. However, I realize that…

I disagree with this statement. We haven't pushed incompatible standards or any other nonsense. We've literally pushed out the latest standards and enabled more encryption (see Universal SSL making SSL free years before Let's Encrypt; see enabling IPv6; enabling HTTP/2; etc. etc.). As for HTTP/3... so will we. See: https://blog.cloudflare.com/http-3-from-root-to-tip/ , https://blog.cloudflare.com/the-road-to-quic/ an…

Sure. What makes anyone use cloudflarenet if you're using different standards? You start by owning the market (which you're moving towards, and in a very good position to do), and then start making changes. All speculation, of course, but I agree with the gp that this is a very real possibility.
Post reply on HN