Live data from Hacker News

Warp – Mobile VPN

blog.cloudflare.com

351–360 of 500 posts

Re: Warp – Mobile VPN

#351
post #149

> We built Warp around WireGuard So basically Cloudflare created an app with Cloudflare branding and set up a Wireguard server for everyone. No bad, but just check out the original: https://www.wireguard.com While I am not a big fan of VPNs in general, I have to admit, that Wireguard performs exceptionally well. I tested it a week ago and the added latency is pretty much just the network latency and the bandwidth los…

I consider myself fairly competent, and I couldn’t understand the wireguard documentation enough to setup my own install without resorting to algo [0]. There’s real value in wrapping a system like WireGuard into a product, because it democratizes technology rather than making it available only to those knowledgable enough to understand how to set it up. I think Warp is great in that regard. [0]: https://github.com/tr…

When did Algo get WireGuard support? Used to use Streisand as it has more protocols, but WireGuard is all I would want now.

Might have to set this up again!

Re: Warp – Mobile VPN

#352
post #342
post #329

VPNs are "trust me" security, and Cloudflare certainly has a better reputation than many VPN services, so, in that regard, Cloudflare's entry is welcome, but... I've been using Tor as a privacy-friendly VPN, so Cloudflare getting into this business will make it feel a bit different, every time I see an error Web page that says Cloudflare is blocking a Tor exit node from viewing a page that Cloudflare hosts. Perhaps C…

> Perhaps Cloudflare could figure out how to block competitor Tor less (even if there's abuse coming in through Tor)? That might be difficult, but an excellent show of good faith. they are: https://blog.cloudflare.com/cloudflare-onion-service/

Indeed, we've gone to great lengths already to make the experience over Tor less painful -- for example supporting Proxy Pass: https://blog.cloudflare.com/cloudflare-supports-privacy-pass... in addition to the onion service that rrix20 mentioned.

Re: Warp – Mobile VPN

#353
post #239

An aside from the comment, but I don't appreciate the derisive tone of their first paragraph: > a handful of elite tech companies decide to waste the time of literally billions of people with juvenile jokes that only they find funny. I sort of agree, but it's not nice, and not necessary. It also isn't particularly classy to then go on to say "and we're so much better, because we do useful things". (I do happen to fin…

I actually loved that intro. Check out Stackoverflow for a horrendous example of an April fools "joke" today.

Screenshot for people reading this outside of 4/1/2019:

https://i.imgur.com/zCNbOTl.png

Re: Warp – Mobile VPN

#354

Earlier quoted context omitted.

We thought about the trust aspect of it (we have gone through numerous VPN related threads here on news.yc and r/privacy and this has been one of the top concerns). Here's how we plan to convince folks (in our own naive way) we mean business (do serveral or all among): 1. OpenSource vpn server and client, with ability to Cloud-SSH to the server and view what's running. 2. Hands-off, one-click, spin up VPN servers on…

Sounds like something HN readers will like, but which also would be completely commercially unviable.

True. That's the part where we might need to think hard: A business plan. We haven't thought that far yet, tbh.

Our intention is to: Put the control of the mobile device back in the hands of the consumer and empower them with simple but powerful tools. Think keybase, Stripe, or pre-2014 WhatsApp in terms of UX.

Mobile VPN is key part of that vision, including building other apps around it.

A lot of things triggered this:

1. The prism/carrier-iq snafu from 7yrs back.

2. The uptick in government censorship prevelant in multiple nations (India, Turkey, Pakistan, Russia, etc).

3. Rise of app-economy and the relentless tracking behaviour that entails, esp from Facebook.

4. pi-hole and it's elegant solution to shut out trackers. Though I first saw this solution impl by Sam Hocevar (one of the VLC devs) in 2002 (?): http://sam.zoy.org/writings/internet/doubleclick.html

5. Not very many firms developing products like DuoSecurity did but for the end-consumer. There's a few I could find, like SecureMix (glasswire developer), Objective-See (LuLu Firewall), Jigsaw (primarily for journalists?), Purism, and KeepSafe.

Re: Warp – Mobile VPN

#355

I wonder if when accessing a Cloudflare website if they'll be presenting the website owner with the original origin IP, or passing along the 1.1.1.1 endpoint IP addressed when staying within their network.

We'll be presenting the original IP. If you wish to block or otherwise take action on, e.g., malicious traffic from the IP being used to connect to Warp, you'll be able to do so.

And then at some point CF protected sites can dis- or enable to only allow warp VPN users per filter?

Re: Warp – Mobile VPN

#356
Would really be nice to see this on F-Droid or available as an apk somewhere. There are still a few of us (dozens!) that are holding onto the fantasy that Android isn't just a Google service.

Re: Warp – Mobile VPN

#357
post #329

VPNs are "trust me" security, and Cloudflare certainly has a better reputation than many VPN services, so, in that regard, Cloudflare's entry is welcome, but... I've been using Tor as a privacy-friendly VPN, so Cloudflare getting into this business will make it feel a bit different, every time I see an error Web page that says Cloudflare is blocking a Tor exit node from viewing a page that Cloudflare hosts. Perhaps C…

Basically run Tails as the host OS

then setup a computer at various data centers/locations around the world that you can route your traffic through (its a VPN now)

and then either

1) run a Virtual Machine in that which connects through VPN

2) run a remote machine which connects to the outside through VPN

Re: Warp – Mobile VPN

#358
post #101

Earlier quoted context omitted.

This is precisely my setup, and I couldn't be happier. I have a lot of internal infrastructure including pi-hole, confluence and a number of self-hosted services. WireGuard lets me go anywhere on my laptop and its like I never left home, and I just keep two configurations for when I want to forward only internal IP addresses, or all my traffic.

> I have a lot of internal infrastructure including pi-hole, confluence Confluence as in the Atlassian software? What do you use it for at home?

Torturing people

Re: Warp – Mobile VPN

#359
This is awesome! I love CloudFlare's services and I'd trust them to provide a really secure, fast VPN (free to boot!)

  1. Is there a public endpoint for boringtun/noise? For playing with
  2. Any chance the client (desktop) will be open source? Would love to help if possible.  
  3. Any interest in a WebRTC (and webRequestBlocking) based chrome extension/client? 
  That would probably not need anything special installed on desktops and would be awesome

Re: Warp – Mobile VPN

#360
post #350
post #329

VPNs are "trust me" security, and Cloudflare certainly has a better reputation than many VPN services, so, in that regard, Cloudflare's entry is welcome, but... I've been using Tor as a privacy-friendly VPN, so Cloudflare getting into this business will make it feel a bit different, every time I see an error Web page that says Cloudflare is blocking a Tor exit node from viewing a page that Cloudflare hosts. Perhaps C…

An interesting trick - if Cloudflare allows it - would be Device -> Tor -> This -> Internet. Tor provides anonymity, this provides protection against exit nodes maliciously modifying traffic (you can find a number of examples of this just by searching).

Yes!

Routing VPNs through Tor is a great way to avoid site discrimination against Tor users. But there are two key problems. One is that you degrade Tor anonymity, because Tor can't switch circuits (normally at ~10 minute interval). And also because you typically must pay for VPN services.

The other problem is that Tor only routes TCP traffic. So when you use TCP-based VPNs routed through Tor, and are using HTTPS or some other TCP flavor, you get the TCP-in-TCP horrors. There's too much error correction.

So yes, Cloudflare would need to allow Warp via Tor. Or maybe even better, Warp via Tor via Warp. And also it would need to protect Tor anonymity.

Cool idea, though :)

Post reply on HN