Live data from Hacker News

Warp – Mobile VPN

blog.cloudflare.com

151–160 of 500 posts

Re: Warp – Mobile VPN

#151

It seems to me that in practice, Cloudflare's mission is not actually to build a better Internet, but to offer an alternative, proprietary network (one could call it the CloudflareNet), and convince content providers and consumers to use that network. Because I don't want any single company to have too much power, I'll stick with the standard Internet, which is not owned by any single company. However, I realize that…

> Because I don't want any single company to have too much power,

Yes. Agreed. But if not Cloudflare as a pushback alternative to those trying to own the internet, then who?

It seems to me the "standard internet" is getting smaller and smaller. What other options do we have?

Re: Warp – Mobile VPN

#152
post #101

Earlier quoted context omitted.

This is precisely my setup, and I couldn't be happier. I have a lot of internal infrastructure including pi-hole, confluence and a number of self-hosted services. WireGuard lets me go anywhere on my laptop and its like I never left home, and I just keep two configurations for when I want to forward only internal IP addresses, or all my traffic.

Any pointers on setup instructions for WireGuard split tunneling on iOS?

not for wireguard. but for openvpn here's a howto https://ba.net/adblock/vpn/doc/howto.html

Re: Warp – Mobile VPN

#154

I'd wager that the Super Secret Plan is geared towards further centralizing the Internet. Preferably on Cloud Flare's infrastructure. This is one part of a tug-of-war that's going on in recent years between Internet network operators and cloud providers, with the cloud providers slowly but surely winning. For better or worse, we are moving away from a distributed Internet composed of many autonomous networks into a f…

I don’t think this would fly for a number of reasons, but CloudFlare isn’t exactly a world leader or even a household name. They’re a newcomer in this space and for once they’re actually open with their community (us). If CloudFlare is the villain, then are CenturyLink & Comcast the heroes? By my estimation, we’re more likely to see any kind of doomsday scenario like that executed by cable companies and telcos — which already have a natural monopoly in most localities. I don’t see CloudFlare as having anywhere close to that reach.

Re: Warp – Mobile VPN

#155

I'd wager that the Super Secret Plan is geared towards further centralizing the Internet. Preferably on Cloud Flare's infrastructure. This is one part of a tug-of-war that's going on in recent years between Internet network operators and cloud providers, with the cloud providers slowly but surely winning. For better or worse, we are moving away from a distributed Internet composed of many autonomous networks into a f…

Here's the issue that everything fights when talking about Centralization vs Decentralization. Centralization is far easier to manage. A single entity has the ability to control all routes and all the pieces of the network. The structure can become faster, mesh-networks are notoriously slow. By using a VPN + Argo cloudflare has control over how your data is routed, and can make sure it skips slow network segments, is…

Of course centralization is easier. The problem is that it's centralized.

Re: Warp – Mobile VPN

#156
post #134

Earlier quoted context omitted.

It does I think - Certificate[1] info: - subject `CN=Google Internet Authority G3,O=Google Trust Services,C=US', issuer `CN=GlobalSign,O=GlobalSign,OU=GlobalSign Root CA - R2', serial 0x01e3a9301cfc7206383f9a531d, RSA key 2048 bits, signed using RSA-SHA256, activated `2017-06-15 00:00:42 UTC', expires `2021-12-15 00:00:42 UTC', pin-sha256="f8NnEFZxQ4ExFOhSN7EiFWtiudZQVD2oY60uauV/n78=" - Status: The certificate is tru…

> Firefox does not trust this site because it uses a certificate that is not valid for 8.8.8.8. The certificate is only valid for the following names: .c.docs.google.com, .a1.googlevideo.com, .c.2mdn.net, .c.audiobooks.play.google.com, .c.bigcache.googleapis.com, .c.chat.google.com, .c.doc-0-0-sj.sj.googleusercontent.com, .c.drive.google.com, .c.googlesyndication.com, .c.googlevideo.com, .c.inbox.google.com, .c.lh3-d…

Thanks! That's what I meant - 8.8.8.8 has a real cert, just not a valid one for its IP address (which does appear on other domains, oddly enough).

Re: Warp – Mobile VPN

#157

Earlier quoted context omitted.

I think my answer was pretty clear. We do not currently plan to allow stock WireGuard clients to use Warp. I say, currently, because things can always change. It's important to appreciate that we have literally millions of users for the 1.1.1.1 App and we are rolling out a free VPN for them. That is a huge support and network burden that we have to deal with to make that experience work well. Yes, we use WireGuard un…

What's the reasoning behind this[1]? It strikes of ulterior motives and turns me off, as a potential user. Any official response from Cloudflare? [1] https://lists.zx2c4.com/pipermail/wireguard/2019-March/00404...

We're really happy to work with the WireGuard. We communicated with Jason throughout the process and have a ton of respect for him and the entire WireGuard community. In the short term, we need the flexibility to quickly update our code base to support the project we built it for. That's harder when you need to coordinate with people outside Cloudflare and when we need to move as fast as we plan to. However, we really believe in open source and want the WireGuard community to thrive. We licensed the code very openly (3-clause BSD) and WireGuard may choose to fork it. If they do, we'll support it and plan to contribute any improvements in our own fork back. Over the long term, we're very open to merging this back into the upstream project.

Re: Warp – Mobile VPN

#158

There’s a lot of claims about how mobile internet sucks and this makes it not suck. But then it’s revealed it’s a WireGuard based VPN. What I don’t understand is how my internet will be so much faster than any other use of WireGuard?

There are a few reasons:

1. When you use WireGuard as a VPN your device is connecting to wherever you happen to have hosted your server. Cloudflare's PoPs are located in 165 different Internet exchanges and ISPs, giving you a pretty good chance to be closer to you wherever you are in the world.

2. We (Cloudflare) have tech through our Mobile SDK product which can optimize the actual way the Internet TCP traffic is mapped into UDP.

3. We also have Argo, a technology for optimizing the routing of packets through the Internet which will be released as Warp+.

Re: Warp – Mobile VPN

#159
I wonder if when accessing a Cloudflare website if they'll be presenting the website owner with the original origin IP, or passing along the 1.1.1.1 endpoint IP addressed when staying within their network.

Re: Warp – Mobile VPN

#160
post #136

Congrats! Just a few days ago you said BoringTun is “not ready to be used in mission critical tasks” [1] — has this changed? [1] https://blog.cloudflare.com/boringtun-userspace-wireguard-ru...

It looks like you can follow the security review work on the github repository.

https://github.com/cloudflare/boringtun/issues?q=is%3Aissue+...

Post reply on HN