Live data from Hacker News

WARP is here

blog.cloudflare.com

31–40 of 386 posts

Re: WARP is here

#31

Earlier quoted context omitted.

Great eye! We haven't figured out how to expose them yet for sites not using Cloudflare. We do have some experience solving this problem for Spectrum [1] we're hoping to lean on. The most important thing to us is users don't expect us to keep their IP private, as that is not the intent of WARP. 1- https://blog.cloudflare.com/mmproxy-creative-way-of-preservi...

Are you going out of your way to forward the original IP to the end recipient? What's the point of that? Is it to support IP authenticated logins or similar?

Most likely so the receivers of abusive traffic can contact the original ISP rather than Cloudflare having to deal with abuse reports.

Re: WARP is here

#32

Earlier quoted context omitted.

Can't the same be said about any of the huge hosting companies such as OVH, Hetzner, 1&1, AWS, etc. And any VPN provider that hosts their servers and routes their traffic through unknown datacenters? I'd rather trust Cloudflare that has a great track-record (+Public Canary and are on US Privacy Shield), than any random VPN provider.

Maybe I'll feel better if some other company releases a product that directly competes with Warp.

Aren't there a lot of them?

The bigger VPN providers also offer Wireguard and a simple UI (Basically click the map and you're connected).

Re: WARP is here

#33
post #11

The article mentions that WARP is exposing the end user's IP to websites they visit. I'd be interested in how they do that, especially with HTTPS websites where they can't MITM and inject headers. > WARP is not designed to allow you to access geo-restricted content when you’re traveling. It will not hide your IP address from the websites you visit.

This split tunneling article may be useful. https://www.macobserver.com/news/tmo-scoop/cloudflare-warp-s...

Re: WARP is here

#34
post #11

The article mentions that WARP is exposing the end user's IP to websites they visit. I'd be interested in how they do that, especially with HTTPS websites where they can't MITM and inject headers. > WARP is not designed to allow you to access geo-restricted content when you’re traveling. It will not hide your IP address from the websites you visit.

Great eye! We haven't figured out how to expose them yet for sites not using Cloudflare. We do have some experience solving this problem for Spectrum [1] we're hoping to lean on. The most important thing to us is users don't expect us to keep their IP private, as that is not the intent of WARP. 1- https://blog.cloudflare.com/mmproxy-creative-way-of-preservi...

Although Warp doesn't mask IP addresses, it should be useful for these two use cases:

1) Communicating with insecure websites (HTTP instead of HTTPS)

2) Using unsecured wireless networks (e.g. Wi-Fi at a coffee shop)

Beyond these two cases, is there any advantage to using Warp? Does Warp provide any benefits for email (secure IMAP/SMTP), file sharing (BitTorrent), or other protocols?

Re: WARP is here

#35
post #11

The article mentions that WARP is exposing the end user's IP to websites they visit. I'd be interested in how they do that, especially with HTTPS websites where they can't MITM and inject headers. > WARP is not designed to allow you to access geo-restricted content when you’re traveling. It will not hide your IP address from the websites you visit.

Great eye! We haven't figured out how to expose them yet for sites not using Cloudflare. We do have some experience solving this problem for Spectrum [1] we're hoping to lean on. The most important thing to us is users don't expect us to keep their IP private, as that is not the intent of WARP. 1- https://blog.cloudflare.com/mmproxy-creative-way-of-preservi...

Thank you for your reply. I see that it's rather easy to do that for websites running behind CF as you terminate the traffic and can just set the corresponding header.

But for websites outside your network I don't see any obvious way how to do that. Wouldn't this being possible imply that it's possible to spoof traffic? That would open a whole can of worms for the web and even the internet at large.

But I also get your point that you don't want people to see WARP as a regular VPN to protect a users IP address from being exposed to the other side. Since it's not easy for a user to see which sites run behind CF and which ones don't while browsing they must keep this in mind. Or they can just firewall all CF IPs minus the ones used by WARP (assuming none are shared with other CF products and a list can be obtained).

Re: WARP is here

#36
post #26

> WARP, instead, is built for the average consumer. It’s built to ensure that your data is secured while it’s in transit. So the networks between you and the applications you’re using can’t spy on you. It will help protect you from people sniffing your data while you’re at a local coffee shop. It will also help ensure that your ISP isn’t hoovering up data on your browsing patterns to sell to advertisers. Most of thos…

They also states: > Before today, there were approximately two million people on the waitlist to try WARP. That demand blew us away. It also embarrassed us. The common refrain is consumers don’t care about their security and privacy, but the attention WARP got proved to us how wrong that assumption actually is.

[deleted]

Re: WARP is here

#38
post #11

The article mentions that WARP is exposing the end user's IP to websites they visit. I'd be interested in how they do that, especially with HTTPS websites where they can't MITM and inject headers. > WARP is not designed to allow you to access geo-restricted content when you’re traveling. It will not hide your IP address from the websites you visit.

I can confirm.

Last night i was testing it and geo-location was visible...

Re: WARP is here

#39

Earlier quoted context omitted.

Great eye! We haven't figured out how to expose them yet for sites not using Cloudflare. We do have some experience solving this problem for Spectrum [1] we're hoping to lean on. The most important thing to us is users don't expect us to keep their IP private, as that is not the intent of WARP. 1- https://blog.cloudflare.com/mmproxy-creative-way-of-preservi...

Although Warp doesn't mask IP addresses, it should be useful for these two use cases: 1) Communicating with insecure websites (HTTP instead of HTTPS) 2) Using unsecured wireless networks (e.g. Wi-Fi at a coffee shop) Beyond these two cases, is there any advantage to using Warp? Does Warp provide any benefits for email (secure IMAP/SMTP), file sharing (BitTorrent), or other protocols?

It looks decent for hiding your traffic from your ISP

Re: WARP is here

#40

I was openly critical of Cloudflare when they announced Warp the first time. My accusations were over-reaching, and I ultimately retracted them. But I'm still skeptical, and I still won't use Warp. Here's what still bothers me: Cloudflare is a single company with points of presence all over the world, handling traffic for websites all over the world (including some big ones), and now trying to attract consumers world…

When I look at friends and family, they use their phones for everything because Computer UX failed. And they will switch to whatever public WiFi is available because their expensive yet small mobile data plan. I can see how some people would benefit from this kind of VPN.

Another commenter on this thread said that there are already VPN services with Wireguard support and easy-to-use apps. Why not recommend those to friends and family?
Post reply on HN