Live data from Hacker News

Warp – Mobile VPN

blog.cloudflare.com

281–290 of 500 posts

Re: Warp – Mobile VPN

#281
post #27

I currently use DNS66 for ad blocking on android without root. Is there a way to do something similar while using this app? Alternatively, I have a Xperia XA1 running a June 5, 2017 security patch. It's been my intent for a long time now to figure out how to get root without unlocking the boot loader the sony approved way (which makes the camera less functional). Anyone have any pointers on easy to exploit privilege…

Are you Android 9 or later? If so, set up private DNS to dns.adguard.com [0]

Otherwise, you are out of luck. You cannot run the 1.1.1.1 app and run another VPN app like blockada, netguard, no-root-firewall side by side on Android (at least not supported till the latest release, Android 10).

[0] https://news.ycombinator.com/item?id=18788410

Re: Warp – Mobile VPN

#282
post #142

Earlier quoted context omitted.

> Forking an upstream project to implement decisions without upstream’s consent is a tried and true open source software process, implemented by thousands of projects over the years. Claiming that they don’t support standards, solely because they don’t support another implementation of those standards, is incorrect and inflammatory. If upstream is doing something you don't like and refusing to work with you, sure. Wh…

While the fissure you describe as a guaranteed outcome is certainly likely in many such scenarios, you're missing the point: Implementing a standard without regard for the beliefs of other implementors is an action that supports a standard. Refusing to work with others does not implicitly harm a standard. You assert that refusing to cooperate with another implementor is guaranteed to harm a standard. It is not guaran…

>DJB has not destroyed DNS.

DJB didn't fork Bind and then refuse to work with them.

>BoringSSL has not destroyed TLS

BoringSSL didn't fork OpenSSL and then refuse to work with them.

About the closest modern comparison would be OpenOffice vs. LibreOffice - which created a complete mess like I mentioned before.

Except even THAT is a bad comparison because LibreOffice only forked when they were FORCED to fork.

Re: Warp – Mobile VPN

#283
post #253

Earlier quoted context omitted.

We'll be presenting the original IP. If you wish to block or otherwise take action on, e.g., malicious traffic from the IP being used to connect to Warp, you'll be able to do so.

Is this in X-Forwarded-For?

CF-Connecting-IP is what we recommend using.

See https://support.cloudflare.com/hc/en-us/articles/200170986-H... for details.

Re: Warp – Mobile VPN

#284
>TCP, the foundational protocol of the Internet, was never designed for a mobile environment.

Amusingly, this is actually not true. TCP was originally developed to run on an inter-network over two networks: the ARPANET which has the reliability characteristics of a "traditional" network, and an extremely mobile network with lots of packet loss: ship-to-ship packet radio.

TCP today seems very poorly suited for the mobile environment, but it was in fact originally designed for mobile.

Re: Warp – Mobile VPN

#285
post #149

> We built Warp around WireGuard So basically Cloudflare created an app with Cloudflare branding and set up a Wireguard server for everyone. No bad, but just check out the original: https://www.wireguard.com While I am not a big fan of VPNs in general, I have to admit, that Wireguard performs exceptionally well. I tested it a week ago and the added latency is pretty much just the network latency and the bandwidth los…

I consider myself fairly competent, and I couldn’t understand the wireguard documentation enough to setup my own install without resorting to algo [0]. There’s real value in wrapping a system like WireGuard into a product, because it democratizes technology rather than making it available only to those knowledgable enough to understand how to set it up. I think Warp is great in that regard. [0]: https://github.com/tr…

I am still trying to figure it out how to setup a Wireguard server on Kubernetes/GKE to personal use. Outline and OpenVPN clients have some problems that's why I want to try Wireguard.

Re: Warp – Mobile VPN

#286

There goes me and my co-founder's plan of disrupting the Mobile VPN market. Or may be, we still have a chance? Anywho, congratulations Cloudflare! I long held an opinion that the VPN market was ripe for disruption when I looked at privacy policy of some of the top players. Having analysed the market, I find that its defragmented with no clear run-away winner. I hope you're able to make a headway with all the interest…

My biggest concern with any VPN is: do I trust you? I’ve been reluctant to sign up with any of these VPN services that seem to be advertising everywhere nowadays because I don’t know what they’ll do with my internet traffic.

The CloudFlare VPN is interesting to me because they’re a large, established company with a good reputation, so I trust them more than TunnelBear or ExpressVPN or PIA or whoever’s sponsoring YouTube this week.

If there was a way you could offer a product or service that provided a compelling case for why you won’t (or better yet can’t) snoop on my internet traffic, I’m all ears. Everything else is just gravy on top.

Re: Warp – Mobile VPN

#287
post #17

Is there a better summary of what's being offered here?

Cloudflare already has an app on mobile devices - but so far it only served your DNS queries. Now the app behaves as a VPN for all your mobile traffic - all data is routed within Cloudflare's network from the moment it leaves your device, which is faster than going through the public internet.

I think it is important to notice that the traffic is first routed to Cloudflare over the public internet, so technically it is not the moment it leaves your device when it starts to get routed inside CloudFlares network and the public internet again soon after in most cases. Being faster crucially relies on having nearby access to their network from your device and from their network to the destination. Otherwise you ultimately just add some additional hops in between, making it likely to be slower in terms of latency instead. I also would not expect much of a difference performance wise if you access services already using CloudFlare as the endpoints network is likely the same there. However, this is only relevant for your argument of it supposedly being faster. Of course the packets leaving your device are encapsulated and unreadable to third party observers. After being decapsulated its not about routing your VPN traffic anymore but the packets inside which is probably what you were referring to on its own.

Re: Warp – Mobile VPN

#288
post #241

193 Comments and No one has asked yet. How do they make money? So, the price plan and extras from Business, Professional and Enterprise CDN is enough to cover all the cost of running the network + free tier CDN + Domain Registration Operation + DNS + Free tier VPN? There is a reason why I am using Apple. Their interest is in me using iPhone or Apple devices with a very decent profits margin, and hopefully up sell me…

194 comments, and someone didn't read the article
Post reply on HN