Live data from Hacker News

Cloudflare Warp

1.1.1.1

171–180 of 196 posts

Re: Cloudflare Warp

#171
post #93

We use Cloudflare Warp at work. Honestly—and I say this as a Cloudflare fan in general—it doesn’t work well for me. I regularly have connection issues with it enabled. Video calls sometimes cut out for a couple seconds, and Tuple (which I use a lot) really struggles with it. It’s possible it’s my internet connection or something unrelated, but I don’t have any of these issues when Warp is disabled. YMMV and all that,…

I have the same sorts of issues on Android -- I frequently have to kill the 1.1.1.1 app because it no longer passes traffic, but it seems to work fine on other Linux systems that are not Android.

The Android issue is an issue, but a separate one. It seems to only happen on a few devices (including mine). What device do you use and on what version of Android?

Re: Cloudflare Warp

#172

We use Cloudflare Warp at work. Honestly—and I say this as a Cloudflare fan in general—it doesn’t work well for me. I regularly have connection issues with it enabled. Video calls sometimes cut out for a couple seconds, and Tuple (which I use a lot) really struggles with it. It’s possible it’s my internet connection or something unrelated, but I don’t have any of these issues when Warp is disabled. YMMV and all that,…

I believe the issues with your video calls and Tuple are due to a specific issue we've recently identified. What video call software do you use? Also, Tuple has a troubleshooting screen to see packet loss etc. Would you be willing to share the data from that screen with us? If so, you can reach out to me using my HN username at cloudflare.

Re: Cloudflare Warp

#173
post #92
post #61

Earlier quoted context omitted.

They know what IPs you are connecting to and when, which is valuable. If Cloudflare serves the site you are connecting to (which is increasingly more common) they have access to all of the data you are transmitting.

SNI reveals which domains.

ECH (encrypted client hello) is going to become mainstream pretty soon. But if you're doing something dodgy, hostname vs. IP is unlikely to make a difference anyway.

Re: Cloudflare Warp

#174

We use Cloudflare Warp at work. Honestly—and I say this as a Cloudflare fan in general—it doesn’t work well for me. I regularly have connection issues with it enabled. Video calls sometimes cut out for a couple seconds, and Tuple (which I use a lot) really struggles with it. It’s possible it’s my internet connection or something unrelated, but I don’t have any of these issues when Warp is disabled. YMMV and all that,…

I believe the issues with your video calls and Tuple are due to a specific issue we've recently identified. What video call software do you use? Also, Tuple has a troubleshooting screen to see packet loss etc. Would you be willing to share the data from that screen with us? If so, you can reach out to me using my HN username at cloudflare.

We use mostly Google Meet and Slack for calls. If/when I next experience issues, I’ll be sure to reach out!

Re: Cloudflare Warp

#175

Earlier quoted context omitted.

Which is not supported by 99.99% of the websites.

Far more than 0.01% of websites use cloudflare.

Yes, but it's not implemented yet on any website. And there is no software support except beta versions of Chrome/Edge and you have to manually toggle flags in dev options.

Re: Cloudflare Warp

#176
post #94

Earlier quoted context omitted.

Cloudflare recently hijacked the domain of one of their customers (RaidForums), then cloned the RaidForums login page, and ran a phishing campaign at the behest of the FBI for two weeks. I understand that you have to comply with law enforcement, but actively attacking the users of one of your customer's websites is super rude.

This is a pretty wild mischaracterization. "I can't believe they let the FBI tell them what to do" is an incredibly bad take.

When the FBI asked Apple to build tools to attack customers, Apple said no. Cloudflare could have just dropped RaidForums as a customer, but they went the extra mile and built tools to facilitate an attack of RF users.

Re: Cloudflare Warp

#177
post #94

Earlier quoted context omitted.

Cloudflare recently hijacked the domain of one of their customers (RaidForums), then cloned the RaidForums login page, and ran a phishing campaign at the behest of the FBI for two weeks. I understand that you have to comply with law enforcement, but actively attacking the users of one of your customer's websites is super rude.

Please, where can I read about that? I need it to back my point why putting too much trust into CF is not good.

It's all this: https://www.bleepingcomputer.com/news/security/raidforums-ha...

Also I feel like Raid Forums is a bit mis-characterized in the article. It was largely a forum for people who collect OSINT about breached websites, not really a market place, and in the years that I spent there, I never saw people selling actually carding details, like they claim in the article. I used it regularly for my day job.

Re: Cloudflare Warp

#178

What's that saying? "'If you're not paying for the product, you are the product'?" It comes to mind here.

you can literally pay for the product (e.g., an ISP services) and still have meta data you generate bundled and sold. the saying is overused and mostly misleading, unfortunately.

I believe it's simply a statement that you can't take the converse of. If something is free, then the company providing it must get some benefit from it. You can't flip that around in very many cases.

Re: Cloudflare Warp

#179

Earlier quoted context omitted.

Much easier to get a global view of Internet behaviour when there are only one or two DCs worth of ClickHouse clusters needing tapped Related question: given this obviously generates logs, what are CloudFlare doing to protect log data in transit within its own network from similar attacks to the Google-NSA episode? ( https://www.washingtonpost.com/world/national-security/nsa-i... )

What was to stop the NSA funding, creating, acquiring, or controlling CloudFlare so as to be useful for MITM surveillance?

I suspect the 5 eye countries don't have to pay a dime and have complete access to traffic and records on it. Hence everyone pushing encryption to at least make it a bit harder for them.

Re: Cloudflare Warp

#180
post #104

Most of the time the fastest way to any given site is to avoid unnecessary network hops. Now maybe CF have a more efficient route here or there but really I can’t believe that for most people it’ll be faster. As for security or privacy I can’t imagine they’re much safer than browsing most HTTPS sites directly. There’s nothing to say they’ll be able to resist a secret US government subpoena for records either.

The only real advantage I see is that it could be useful in coffee shops and hiding your connections from your computer->isp->cloudflare. isp can't see your traffic and headers other than that the encrypted pipe has been created between you and cloudflare "vpn"
Post reply on HN