> Your Internet service provider can see every site and app you use—even if they’re encrypted. Some providers even sell this data, or use it to target you with ads. > We believe privacy is a right. We won't sell your data, ever. "We, the people who make up this company now, but not in the future, PROMISE." I notice they didn't say "we don't keep the data." According to the comments, this is just wireguard. I deployed…
I’m confused by the first claim. Is it really true? I thought TLS prevented anyone from inspecting my traffic. Am I completely off base?
Cloudflare Warp
91–100 of 196 posts
Re: Cloudflare Warp
#92Earlier quoted context omitted.
I’m confused by the first claim. Is it really true? I thought TLS prevented anyone from inspecting my traffic. Am I completely off base?
They know what IPs you are connecting to and when, which is valuable. If Cloudflare serves the site you are connecting to (which is increasingly more common) they have access to all of the data you are transmitting.
Re: Cloudflare Warp
#93We use Cloudflare Warp at work. Honestly—and I say this as a Cloudflare fan in general—it doesn’t work well for me. I regularly have connection issues with it enabled. Video calls sometimes cut out for a couple seconds, and Tuple (which I use a lot) really struggles with it. It’s possible it’s my internet connection or something unrelated, but I don’t have any of these issues when Warp is disabled. YMMV and all that,…
Re: Cloudflare Warp
#94Kinda uneasy about how Cloudflare is positioning themselves to have insight into a huge chunk of the Internet's traffic (very much like Google has). Even though there's no visible abuse right now, you know, Google's motto also used to be "don't be evil".
I understand that you have to comply with law enforcement, but actively attacking the users of one of your customer's websites is super rude.
Re: Cloudflare Warp
#95Earlier quoted context omitted.
Yup. A bit less catchy than “Don’t be evil” but it’s the same. Cloudflare is what Google was 20 years ago. The cycle can only break by decentralized protocols.
Which isn't ever going to happen as the benefits of centralization are too great, as it has been empirically observed time and time again.
Re: Cloudflare Warp
#96> Your Internet service provider can see every site and app you use—even if they’re encrypted. Some providers even sell this data, or use it to target you with ads. > We believe privacy is a right. We won't sell your data, ever. "We, the people who make up this company now, but not in the future, PROMISE." I notice they didn't say "we don't keep the data." According to the comments, this is just wireguard. I deployed…
Yup. A bit less catchy than “Don’t be evil” but it’s the same. Cloudflare is what Google was 20 years ago. The cycle can only break by decentralized protocols.
Cloudflare is already much worse. It's relentlessly centralizing the whole Internet.
Re: Cloudflare Warp
#97I’ve been a Warp+ user for some time now and I’m mostly happy. My online privacy is important to me. I use ad blockers too in addition to cloudflare. A couple of things I’ve noticed along the way… 1. Switching off my wi-fi network and then rejoining later used to be an issue but seems to have resolved some time ago (mobile) 2. It seems on macOS that almost every time I login I need to update the client. 3. Usually si…
Cloudflare Warp is not meant for anonymity. If you're using the free tier (and maybe the plus tier too?), websites behind Cloudflare are able to see your origin IP.
Re: Cloudflare Warp
#98Kinda uneasy about how Cloudflare is positioning themselves to have insight into a huge chunk of the Internet's traffic (very much like Google has). Even though there's no visible abuse right now, you know, Google's motto also used to be "don't be evil".
"Your ISP looks at which websites your browsing, oh the horror! Instead trust us, as an internet behemoth bigger than any ISP in the world with that data!" I also don‘t really get their argument here?
Cloudflare can collect your traffic history, but can only connect that history to your originating IP + timestamp. Their official client may be able to collect more info though. But, warp is just wireguard, so you do not need to run their official client there are shell/python scripts floating around to get the keys / endpoint IPs setup for Warp to use with std. in-kernel wireguard.
Further, all the telcos in the US are known to have colluded in illegal NSA spying on Americans. Cloudflare has not been caught at this yet. So, you can look at it as a choice of exposing your browsing history to an entity that may be not be lying and actually is not snooping vs. telcos that are known to have lied and definitely have and are likely still snooping.
Re: Cloudflare Warp
#99Kinda uneasy about how Cloudflare is positioning themselves to have insight into a huge chunk of the Internet's traffic (very much like Google has). Even though there's no visible abuse right now, you know, Google's motto also used to be "don't be evil".
"Your ISP looks at which websites your browsing, oh the horror! Instead trust us, as an internet behemoth bigger than any ISP in the world with that data!" I also don‘t really get their argument here?
Re: Cloudflare Warp
#100Earlier quoted context omitted.
"Your ISP looks at which websites your browsing, oh the horror! Instead trust us, as an internet behemoth bigger than any ISP in the world with that data!" I also don‘t really get their argument here?
Your ISP can collect your traffic history AND trivially connect that history to your identity, and sell/provide data to brokers, TLAs, police etc. Cloudflare can collect your traffic history, but can only connect that history to your originating IP + timestamp. Their official client may be able to collect more info though. But, warp is just wireguard, so you do not need to run their official client there are shell/py…
That's exaggerating quite a bit. Maybe in 2005 they had that sort of insight, but with HTTPS everywhere things are different. Your ISP can only see which IPs you're connecting to, possibly which hosts you're looking up depending on your setup but DNS-over-TLS and the like will put a wet blanket on that.
Cloudflare (even without warp) has a much clearer picture of your browsing habits. Not only do they see which webpages you are requesting since they're situated as a MITM between you and a significant chunk of the servers online, they do quite a lot of browser fingerprinting and tracking for bot mitigation that could, theoretically, be used to identify humans as well.