Live data from Hacker News

Warp – Mobile VPN

blog.cloudflare.com

221–230 of 500 posts

Re: Warp – Mobile VPN

#221

Earlier quoted context omitted.

I disagree with this statement. We haven't pushed incompatible standards or any other nonsense. We've literally pushed out the latest standards and enabled more encryption (see Universal SSL making SSL free years before Let's Encrypt; see enabling IPv6; enabling HTTP/2; etc. etc.). As for HTTP/3... so will we. See: https://blog.cloudflare.com/http-3-from-root-to-tip/ , https://blog.cloudflare.com/the-road-to-quic/ an…

FWIW, you guys have also pushed this nonsense: https://www.amp.cloudflare.com/ So one could argue you are both pushing the latest standards and the latest nonsense. ;)

I too dislike amp, but I don't see this as cloudflare's fault. If anything they're offering a competitor to google who we typically criticize for creating and abusing amp.

Re: Warp – Mobile VPN

#222

Cloudflare is one of the companies I trust and use . But in every company's life cycle, there will be a time when some other company (Google, Facebook and other usual evils) comes forward to buy this company out, will they hold off? or will they go public? What happens next is a store for another time!

Always continually evaluate your assumptions of who you trust, and always ensure you aren't up a creek if you have to switch providers because of an acquisition. That's why products built on open standards are great: They mean there are already alternatives readily available if you need to switch.

Re: Warp – Mobile VPN

#223

Just as an aside, I thought that was an exceptionally well-written product announcement, or press release, or whatever you'd call it. It was long, but I didn't mind reading the whole thing. It answered all the basic questions about why I should use it, how they plan to make money, and with enough technical detail that I understood essentially how it works. It was very much the opposite of the marketing material you g…

I had the same reaction. As I was reading the article, I started asking myself "Hold on, what's in it for you? You're still a private company. How are you going to make money?". I then reached the "Ok, Sure, But You’re Still a Profit-Seeking Company" section. It's as if the article was reading my mind.

Every free product comes with a catch. When this catch is not clearly explained by the company, I always feel it's because the reason is too "shady" to acknowledge publicly (like Gmail and Facebook gathering data for advertisers). I'm probably naive to believe the reason here is vastly different, but the tone and style of this article puts Cloudflare closer to Apple than to Google privacy-wise in my eyes.

Re: Warp – Mobile VPN

#224
post #215
post #178

Earlier quoted context omitted.

Captchas. Cloudflare made Tor unusable. This might have changed but in the past it made using Tor for anything beyond onion sites extremely annoying.

Though admittedly, if you get a lot of requests from one ip and you can't really know if they are legit or not, what would you do?

I don't have the numbers, but from what I've heard the amount of legitimate traffic from TOR is rather small compared to the heaps of bots and abuse.

Yes there's the argument that TOR provides protection for those in apressive states, but given the pros/cons of blocking TOR altogether I can at least understand the reasoning.

Re: Warp – Mobile VPN

#225

Just as an aside, I thought that was an exceptionally well-written product announcement, or press release, or whatever you'd call it. It was long, but I didn't mind reading the whole thing. It answered all the basic questions about why I should use it, how they plan to make money, and with enough technical detail that I understood essentially how it works. It was very much the opposite of the marketing material you g…

> exceptionally well-written product announcement

Yup... a rare beast these days. My niece is a gifted writer - one of less than a half dozen that I personally know.

She graduated recently and had her pick of several positions due to her portfolio of work.

Re: Warp – Mobile VPN

#226
post #154

Earlier quoted context omitted.

I don’t think this would fly for a number of reasons, but CloudFlare isn’t exactly a world leader or even a household name. They’re a newcomer in this space and for once they’re actually open with their community (us). If CloudFlare is the villain, then are CenturyLink & Comcast the heroes? By my estimation, we’re more likely to see any kind of doomsday scenario like that executed by cable companies and telcos — whic…

No one is the villain here, it's not that simple. These are companies that respond to market pressures. Routing around the network operators (both figuratively and literally) makes a lot of sense for large cloud providers. Especially so if there are no network neutrality rules in place to enforce free access to consumers (as opposed to consumer ISPs demanding payment for pushing content to their subscribers). Also, t…

> Also, the content from Google, Facebook and a couple other cloud providers is what consumers actually want.

What content from Google and Facebook? If you are referring to YouTube and Instagram - that's one part of the total internet content consumed. Hard to totally ignore the news sites, blogs and streaming services.

Re: Warp – Mobile VPN

#227

I wonder if when accessing a Cloudflare website if they'll be presenting the website owner with the original origin IP, or passing along the 1.1.1.1 endpoint IP addressed when staying within their network.

We'll be presenting the original IP.

If you wish to block or otherwise take action on, e.g., malicious traffic from the IP being used to connect to Warp, you'll be able to do so.

Re: Warp – Mobile VPN

#228
Currently I use PIA VPN when browsing. When I go to Cloudflare sites, I often get captchas because, in the past, I imagine someone was using PIA to abuse a Cloudflare site.

So what happens when people start using Warp to hide their IP so they can hack, scan, scrape, upload malware, etc? Is Cloudflare going to show captchas to Warp users and slow down their experience? What is the plan to mitigate abuse on a free VPN that doesn't log?

Re: Warp – Mobile VPN

#229
post #149

> We built Warp around WireGuard So basically Cloudflare created an app with Cloudflare branding and set up a Wireguard server for everyone. No bad, but just check out the original: https://www.wireguard.com While I am not a big fan of VPNs in general, I have to admit, that Wireguard performs exceptionally well. I tested it a week ago and the added latency is pretty much just the network latency and the bandwidth los…

I consider myself fairly competent, and I couldn’t understand the wireguard documentation enough to setup my own install without resorting to algo [0]. There’s real value in wrapping a system like WireGuard into a product, because it democratizes technology rather than making it available only to those knowledgable enough to understand how to set it up. I think Warp is great in that regard. [0]: https://github.com/tr…

> I couldn’t understand the wireguard documentation enough to setup my own install without resorting to algo

Not sure what you mean. Algo has no relationship to WireGuard; it's basically a customized StrongSwan setup under the hood, which utilizes IKEv2 (not WireGuard) as the transport.

Re: Warp – Mobile VPN

#230
post #173

Cloudflare, are there plans for ad blocking? Currently using AdGuard DNS and it works well. Router-level ad-blocking would be an attractive premium option.

You should really want those to be separate services. The incentives get weirdly snarled if you expect your VPN to also block ads. Making it a plugin that you could plug another app into might be cool, though?

I think he's asking because you can't easily combine DNS services. If you're using a service to block ads via dns then you aren't using 1.1.1.1. If you want to use 1.1.1.1 then you need to either host your own forwarding dns server or forego ad blocking.
Post reply on HN