Live data from Hacker News

Warp – Mobile VPN

blog.cloudflare.com

231–240 of 500 posts

Re: Warp – Mobile VPN

#231

It seems to me that in practice, Cloudflare's mission is not actually to build a better Internet, but to offer an alternative, proprietary network (one could call it the CloudflareNet), and convince content providers and consumers to use that network. Because I don't want any single company to have too much power, I'll stick with the standard Internet, which is not owned by any single company. However, I realize that…

I disagree with this statement. We haven't pushed incompatible standards or any other nonsense. We've literally pushed out the latest standards and enabled more encryption (see Universal SSL making SSL free years before Let's Encrypt; see enabling IPv6; enabling HTTP/2; etc. etc.). As for HTTP/3... so will we. See: https://blog.cloudflare.com/http-3-from-root-to-tip/ , https://blog.cloudflare.com/the-road-to-quic/ an…

Okay. How does a user who is using Cloudflare's Warp accept incoming connections to a port?

If they cannot then it is not the internet. It's more akin to a 'web' only service.

Re: Warp – Mobile VPN

#232

Earlier quoted context omitted.

FWIW, you guys have also pushed this nonsense: https://www.amp.cloudflare.com/ So one could argue you are both pushing the latest standards and the latest nonsense. ;)

I too dislike amp, but I don't see this as cloudflare's fault. If anything they're offering a competitor to google who we typically criticize for creating and abusing amp.

I agree. And considering many of Google's competitors, like Microsoft, have had to support AMP as well, I recognize that AMP support is an unfortunate necessity in dealing in a world where it exists.

Hence the ;) face, it's meant as a friendly jab, not a critical accusation. jgrahamc is awesome.

Re: Warp – Mobile VPN

#233
post #11

Earlier quoted context omitted.

I read the privacy sections in your blog post, and it feels like WARP offers anonymity, maybe not from CF, but perhaps from everyone else.

Note that the blog post does not say "anonymity" or any similar word. We aren't trying to hide you completely from everyone (use Tor for that). We are securing and accelerating the connection between your device and Cloudflare. This is meant to deal with the reliability, performance and security challenges of using mobile Internet around the world. And we have strong privacy guarantees.

Yes, I got that. But, because CF offerings are very popular, you're going to end up with a lot of people coming from a relatively small number of IP addresses, right?

It's worth thinking about...we had this situation before with AOL. That is, a pretty large number of people in diverse geographic areas, all coming from a small number of IP addresses.

People do use that "relative" anonymity for lots of things, not all of them good. Also, it may create some issues for things like geolocation, regional content restrictions, credit card fraud detection, SMTP blacklisting, rate limiting, and so forth. Because your offering is free, and CF is well known, I'm guessing it will grow fast. Not suggesting anything change about it, just that it may create something that site owners need to react to.

Re: Warp – Mobile VPN

#234
post #154

I'd wager that the Super Secret Plan is geared towards further centralizing the Internet. Preferably on Cloud Flare's infrastructure. This is one part of a tug-of-war that's going on in recent years between Internet network operators and cloud providers, with the cloud providers slowly but surely winning. For better or worse, we are moving away from a distributed Internet composed of many autonomous networks into a f…

I don’t think this would fly for a number of reasons, but CloudFlare isn’t exactly a world leader or even a household name. They’re a newcomer in this space and for once they’re actually open with their community (us). If CloudFlare is the villain, then are CenturyLink & Comcast the heroes? By my estimation, we’re more likely to see any kind of doomsday scenario like that executed by cable companies and telcos — whic…

CloudFlare is definitely large enough to raise concerns about centralization of the Internet. You don't have to be a household name for that (e.g. Akamai isn't either). Their site says that their infrastructure "powers nearly 10% of all Internet requests".

They aren't a villain, they're an illustration of market forces currently favoring centralization. Like CenturyLink and Comcast, for that matter.

Re: Warp – Mobile VPN

#235

I'd wager that the Super Secret Plan is geared towards further centralizing the Internet. Preferably on Cloud Flare's infrastructure. This is one part of a tug-of-war that's going on in recent years between Internet network operators and cloud providers, with the cloud providers slowly but surely winning. For better or worse, we are moving away from a distributed Internet composed of many autonomous networks into a f…

[deleted]

Re: Warp – Mobile VPN

#236

While this might improve user experience for some, I don't see the greater value in a VPN solution like this. It's the fast path to replacing the decentralized internet with a few proprietary CDNs. I'm much more excited about those projects that actually try to fix the raised issues: Unencrypted connections -> TLS / Letsencrypt TCP sucks on mobile/roaming devices -> QUIC & HTTP/3

Cloudflare pushed out free TLS years before Let's Encrypt and we are actively working on and supporting QUIC and HTTP/3. But QUIC/HTTP/3 aren't here today, not everyone is using HTTPS and there are other worries in coffee shops etc. hence a VPN service makes sense.

There is a bit of a difference between LetsEncrypt and Cloudflare TLS termination though... one is TLS for everyone, the other is TLS for Cloudflare customers (paying or not). For instance can an Iranian website use Cloudflare TLS? I would wager not. (ironic as they probably need secure transport the most).

I'm not saying Cloudflare isn't doing good things for the Internet but it's a bit disingenuous to equate the 2 efforts. Cloudflare could have done LetsEncrypt, but as a CDN that would make no business sense - which is why we need LetsEncrypt, so they can continue to do the things that don't make good business sense for Cloudflare.

Re: Warp – Mobile VPN

#238

> We built Warp around WireGuard So basically Cloudflare created an app with Cloudflare branding and set up a Wireguard server for everyone. No bad, but just check out the original: https://www.wireguard.com While I am not a big fan of VPNs in general, I have to admit, that Wireguard performs exceptionally well. I tested it a week ago and the added latency is pretty much just the network latency and the bandwidth los…

They've also written they're own client in rust https://github.com/cloudflare/boringtun

Re: Warp – Mobile VPN

#239

An aside from the comment, but I don't appreciate the derisive tone of their first paragraph: > a handful of elite tech companies decide to waste the time of literally billions of people with juvenile jokes that only they find funny. I sort of agree, but it's not nice, and not necessary. It also isn't particularly classy to then go on to say "and we're so much better, because we do useful things". (I do happen to fin…

I actually loved that intro. Check out Stackoverflow for a horrendous example of an April fools "joke" today.

Re: Warp – Mobile VPN

#240

Earlier quoted context omitted.

I disagree with this statement. We haven't pushed incompatible standards or any other nonsense. We've literally pushed out the latest standards and enabled more encryption (see Universal SSL making SSL free years before Let's Encrypt; see enabling IPv6; enabling HTTP/2; etc. etc.). As for HTTP/3... so will we. See: https://blog.cloudflare.com/http-3-from-root-to-tip/ , https://blog.cloudflare.com/the-road-to-quic/ an…

Okay. How does a user who is using Cloudflare's Warp accept incoming connections to a port? If they cannot then it is not the internet. It's more akin to a 'web' only service.

> If they cannot then it is not the internet. It's more akin to a 'web' only service.

CGNAT means that the same is true of "mobile" connections in general, so it's not like Warp is changing anything for the worse here. Though the Tor network does allow you to host a .onion-linked service over such a connection, but that - while quite handy - seems more like a special case to me.

Post reply on HN