Warp – Mobile VPN
blog.cloudflare.com
blog.cloudflare.com
Anywho, congratulations Cloudflare! I long held an opinion that the VPN market was ripe for disruption when I looked at privacy policy of some of the top players. Having analysed the market, I find that its defragmented with no clear run-away winner. I hope you're able to make a headway with all the interesting innovations that you plan to offer on top of it.
Here are some ideas that I had in mind for a Mobile VPN:
1. Ability to run a dns-blacklist, tag-based blacklist, and a ip-firewall at cloudflare's end (not on the end devices). May be you could add that as an option to your wrap+ product?
2. Auto change exit IPs underneath the covers.
3. Take over the dialer and route calls over IP whenever possible.
4. Provide ability to analyze traffic on a PC.
5. Track and warn mode per app, where the traffic is analysed for a particular app to generate a report on what its doing and how much.
Basically, bring enterprise-grade security to the end consumer.
The CloudFlare VPN is interesting to me because they’re a large, established company with a good reputation, so I trust them more than TunnelBear or ExpressVPN or PIA or whoever’s sponsoring YouTube this week.
If there was a way you could offer a product or service that provided a compelling case for why you won’t (or better yet can’t) snoop on my internet traffic, I’m all ears. Everything else is just gravy on top.
1. OpenSource vpn server and client, with ability to Cloud-SSH to the server and view what's running.
2. Hands-off, one-click, spin up VPN servers on a VPS of your choice under your control, Streistand/Algo style [0][1], but find a way to provide support (think AWS marketplace).
3. Make privacy-centric commitment legally binding as part of EULA/ToS (is this sufficient?).
4. Run client-side only VPN (like intra, blockada, netguard). The idea is you're still able to analyse traffic and add blacklists client-side, without having to pay for or run a VPN server.
Thoughts?
Our intention is to: Put the control of the mobile device back in the hands of the consumer and empower them with simple but powerful tools. Think keybase, Stripe, or pre-2014 WhatsApp in terms of UX.
Mobile VPN is key part of that vision, including building other apps around it.
A lot of things triggered this:
1. The prism/carrier-iq snafu from 7yrs back.
2. The uptick in government censorship prevelant in multiple nations (India, Turkey, Pakistan, Russia, etc).
3. Rise of app-economy and the relentless tracking behaviour that entails, esp from Facebook.
4. pi-hole and it's elegant solution to shut out trackers. Though I first saw this solution impl by Sam Hocevar (one of the VLC devs) in 2002 (?): http://sam.zoy.org/writings/internet/doubleclick.html
5. Not very many firms developing products like DuoSecurity did but for the end-consumer. There's a few I could find, like SecureMix (glasswire developer), Objective-See (LuLu Firewall), Jigsaw (primarily for journalists?), Purism, and KeepSafe.
For some reason, Outline is still mega-targeted at journalists and activists when it could be so much more — it’s been an absolute joy to use so far, and being powered by Shadowsocks certainly doesn’t hurt.
I hope to get something ready to show you guys here on news.yc in may be 3 to 6 months from now.
I'm not aware of any subpoenas directed at Cloudflare that was equally as useless.
are you insane?
CF's reputation is terrible[1]. They are trying to MiTM the entire internet, and frustrate attempts to access some of the most important information online( including but ont limited to evidence of the holocaust, sexual health information and climate change ). They are practically a threat to humanity itself at this point - you shouldn't trust them worth anything.
It could eliminate the client/server by activating the authentication and encryption with exchange of certificates by using a PKI.
It may provides a full p2p encryption in the network layer without logging your traffic somewhere or third parties. open-sourced would be awesome.
Wow. Sure, thanks.
Not sure if you can answer this question, but are the performance benefits still there in conjunction with utilizing the VPN google uses to encrypt traffic with google fi? This announcement mentions they have 2x the latency in comparison to WARP, but did not mention specifically which google VPN technology (not sure if they have multiple) but I assume something mobile related since this is a mobile application.
If I use the WARP app in conjunction with google fi, am I layering this VPN on top of the 2x latency of google fi, thus slowing down WARP VPN to gain then the other performance benefits of optimized network switching of google fi?
Neither project is open source (that I know of) so it is hard to understand how the implementations overlap or not with one another. I also am not an expert in VPNs so maybe this is not a good question, but I find myself reading Cloudflare's blogs alot and couldn't help but ask.
THAT'S HOW IT SHOULD BE!
That's how all of this should be.
Designing a reasonably secure and reliable mobile VPN has been a very difficult challenge to get right. If you look at existing mobile VPNs through a tool such as Charles Proxy or Burp, you will see that none of them really appear to be designed very well. There are many unsolved technical problems with managing and scaling such services, likely avoided by existing providers due to how easy the issues are to mask. That said, Cloudflare’s cautious approach with Warp gives me some confidenxe that they really are trying to do this right.
> Have you already started on this concept?
Initial stages where we have looked at OSS projects to fork for a quick prototype, with our focus being exclusively on Android, and not just limited to VPN.
> Designing a reasonably secure and reliable mobile VPN has been a very difficult challenge to get right.
Thanks for the heads-up. From usability point-of-view, I've seen my share of VPNs mess up and sink hole all traffic. On one ocassion, an app simply refused to get past its loading-screen unless I turned off VPN.
> It would be great to chat further, if you have interest in working on this concept.
Sure, thanks. I'd be sure to email you, Will.
This would be such a great feature. I hope someone makes such a VPN.
So basically Cloudflare created an app with Cloudflare branding and set up a Wireguard server for everyone. No bad, but just check out the original:
While I am not a big fan of VPNs in general, I have to admit, that Wireguard performs exceptionally well. I tested it a week ago and the added latency is pretty much just the network latency and the bandwidth loss is minimal (so small I couldn't even measure it reliably). What I found most interesting, was that there were some use-cases when the network with Wireguard performed even better than without it (probably related to congestion control).
When coupled with an DNS based ad blocker Wireguard can actually make your internet faster than when not using it.
More so on Android than iOS and more so on mobile than fixed, but still feels so much smoother.
you can even only forward the DNS requests and not the rest of the data so your home upload speed won't become your bottleneck.
https://www.ckn.io/blog/2017/11/14/wireguard-vpn-typical-set...
Then you'd just need to use the iOS app, I hope?
To make split tunneling work in WireGuard I changed AllowedIPs = 0.0.0.0/0 in the config file into: AllowedIPs = 92.13.14.15/32 10.192.122.0/24
where 10.192.122.0/24 is the subnet of my tunnel, and 92.13.14.15/32 is the ip address of my home computer
this works on iOS and macos for me
Confluence as in the Atlassian software? What do you use it for at home?
The only thing I was never able to get working was the IPv6 support. Oh well...
Disclosure. It is my day job
It could be the different routing.
Your ISP's routing might be sub-optimal to certain destinations. After all, it chooses routes based (at least in part) on cost, not performance.
There are commercial products that do this sort of tunneling (among other things) to lower routing latencies.
Just search through HN for any discussion of net neutrality.
In short, because they can and they're assholes.
https://www.stavros.io/posts/how-to-configure-wireguard/
It's actually very easy to set up, I don't know why the official docs make it seem super hard.
Not sure what you mean. Algo has no relationship to WireGuard; it's basically a customized StrongSwan setup under the hood, which utilizes IKEv2 (not WireGuard) as the transport.
Could be mistaken though .. not sure
Might have to set this up again!
Not just one -- servers in 175 (and growing) locations spread around the world, and the app will always use the closest one to you. That's arguably a lot more important that what protocol it uses, and is not something you could easily DIY.
I'd say that even the known unknown that ips and networks change routinely should make it a headache to maintain.
In this case, I agree that a single VPS is usually enough for most but never underestimate the market power of making things simpler and faster.
(Not implying anything, just providing a discussion point.)
Once you get your script to work, you’d have to wait minutes for the VPN to spin up in a new region.
Check out algo: https://github.com/trailofbits/algo
I think you could bake your configuration into a custom image, so it would be fast to get a VM started (about 30 secs on GCE, not sure about EC2).
If you use stopped instances, it's even faster.
(I work at GCP so know more about GCE than EC2)
Even if you change residences, you'll typically be in the same state. Even if you change states, you can just set it up again in, what, super conservatively, under an hour (you've already done it once so fewer missteps).
I was lucky to find small paid VPN provider, that doesn't do marketing, pay for referral and stuff, and I'm sticking to it.
I'd disagree. Many VPN protocols suck even if the gateway is in-house. I guess there's a reason they introduced that with Wireguard specifically.
You can go on the wait-list for WARP+ which sounds like it’ll route everything over the VPN.
However, I realize that the problems with mobile Internet performance and reliability are real. So when HTTP/3 is stable, I'll do what I can to help it spread.
As for HTTP/3... so will we. See: https://blog.cloudflare.com/http-3-from-root-to-tip/, https://blog.cloudflare.com/the-road-to-quic/ and https://blog.cloudflare.com/head-start-with-quic/.
I like and use 1.1.1.1 though.
I obviously don't know how many Cloudflared sites I visit that don't pop up the nag. And Cloudflare's nag is certainly nicer than Google's more pervasive help-us-build-a-T-800 or Akamai's "just get lost". But that mode seemingly activates on light browsing just because it's coming from a slightly-less-trackable VPS address (non-shared), and that is a problem.
This might have changed but in the past it made using Tor for anything beyond onion sites extremely annoying.
Yes there's the argument that TOR provides protection for those in apressive states, but given the pros/cons of blocking TOR altogether I can at least understand the reasoning.
However, Cloudflare has also adopted and promoted at least one standard that adds complexity for dubious benefit, specifically DNSSEC, which tptacek has repeatedly criticized (e.g. [1]).
Moreover, Cloudflare is encouraging both providers and consumers to bypass the public Internet as much as possible in favor of Cloudflare's network and proprietary protocol(s). For providers, this is done through Argo and especially Argo Tunnel. And now for consumers, Warp is replacing the standard TCP with a proprietary protocol built on UDP.
Now that Cloudflare has proprietary replacements for the standard Internet on both sides, it can start taking advantage of network effects to make its proprietary network attractive to still more providers and consumers. As Cloudflare's power grows, it becomes harder to escape any future abuses of that power, as well as honest mistakes on Cloudflare's part.
I realize the standard Internet sucks in some ways, and Cloudflare is doing something about that. But I think the right answer is to improve the standards-based Internet, not offer a proprietary replacement. I suppose that's not compatible with running a VC-backed business, though.
I think that applies almost anywhere. One could say "don't trust Google or Facebook with personal data" merely based on the fact that almost all of their money comes from advertising.
And thanks for the interesting exchange!
FWIW, tptacek's argument in that thread seems to be premised on certificate pinning being widely deployed[1], which it's not, and it seems at this point like it never will be[2].
[1]: https://news.ycombinator.com/item?id=10553608
[2]: https://groups.google.com/a/chromium.org/forum/#!msg/blink-d...
It hardly matters at this point, though. DNSSEC is a dead letter. It's over. Stick a fork in it. It'll be around indefinitely for performative nerds to performatively noodle with --- lots of dead IETF protocols are! --- but Cloud Flare is likely to be the largest company ever to use it (and they're the exception that proves the rule, since they sell DNSSEC services).
If upstream is doing something you don't like and refusing to work with you, sure.
When upstream actively petitions you to not fork, asks you politely to work together, and you refuse to work with them, that is far, far from a "tried and true open source software process". That creates a fissure in the community and it generally ends up poorly for everyone involved.
My comment is far from inflammatory, it's a statement of fact, and something cloudflare has refused to acknowledge or respond to. Which just further drives the point home that they aren't acting in good faith.
EDIT: eastdakota filled me in, thanks John.
https://blog.cloudflare.com/boringtun-userspace-wireguard-ru...
We communicated with Jason throughout the process and have a ton of respect for him and the entire WireGuard community. In the short term, we need the flexibility to quickly update BoringTun's code base to support the project we built it for. That's harder when you need to coordinate with people outside Cloudflare and when we need to move as fast as we plan to. However, we really believe in Open Source and want the WireGuard community to thrive. We licensed the code very openly (3-paragraph BSD) and WireGuard may choose to fork it. If they do, we'll support it and plan to contribute any improvements in our own fork back. Over the long term, I think we're very open to merging this back into the upstream project.
>I thought the invitation to put their engineers as the head of a WireGuard subproject was a cool invitation, but alas.
https://lists.zx2c4.com/pipermail/wireguard/2019-March/00404...
I mean no offense, but the response comes off as corporate approved PR. "We need to move fast" when you haven't actually even tried engaging with the parent project and have no idea whether or not it would prohibit "moving fast" is disingenuous IMO.
More importantly, without having already tried it, it’s hard to predict how much overhead there will be.
Since CloudFlare had a (self-imposed) deadline, working fast had to take priority over optics. After all, the project can always be folded into the WireGuard organization later.
Implementing a standard without regard for the beliefs of other implementors is an action that supports a standard. Refusing to work with others does not implicitly harm a standard.
You assert that refusing to cooperate with another implementor is guaranteed to harm a standard. It is not guaranteed at all.
DJB has not destroyed DNS. BoringSSL has not destroyed TLS. A thousand reimplementations of standards in Rust have not destroyed a thousand standards.
You clearly believe that Cloudflare is acting in bad faith, and are constructing a worldview out of assumptions that you declare instead are facts. While I respect your right to hold those views, I do not respect your declaration of future outcomes as fact.
DJB didn't fork Bind and then refuse to work with them.
>BoringSSL has not destroyed TLS
BoringSSL didn't fork OpenSSL and then refuse to work with them.
About the closest modern comparison would be OpenOffice vs. LibreOffice - which created a complete mess like I mentioned before.
Except even THAT is a bad comparison because LibreOffice only forked when they were FORCED to fork.
WireGuard is written as Kernel Module in C, with a GPL licence; BoringTun is a user space program written in Rust with an MIT licence.
So it’s not really even a fork.
So one could argue you are both pushing the latest standards and the latest nonsense. ;)
Hence the ;) face, it's meant as a friendly jab, not a critical accusation. jgrahamc is awesome.
If they cannot then it is not the internet. It's more akin to a 'web' only service.
CGNAT means that the same is true of "mobile" connections in general, so it's not like Warp is changing anything for the worse here. Though the Tor network does allow you to host a .onion-linked service over such a connection, but that - while quite handy - seems more like a special case to me.
[1]: https://en.wikipedia.org/wiki/Embrace,_extend_and_extinguish
[2]: But then, sorry how this sounds, but pessimists tend to think, EEE perpetrators wouldn't publicly admit to it either...
Pretty much most if not all of Cloudflare's services and work suggest the complete opposite to me.
Like other commenters, Cloudflare for me is probably one of the only companies I truly trust. I'm not saying that because I'm a big user of there services in fact 1.1.1.1 is the only service I actively use.
Yes. Agreed. But if not Cloudflare as a pushback alternative to those trying to own the internet, then who?
It seems to me the "standard internet" is getting smaller and smaller. What other options do we have?
If anything, I've kinda been hoping Cloudflare would realize self-hosting and decentralization is what they should be supporting and pushing, as it's when using their CDN makes the most sense. And obviously, Amazon and Google and Microsoft all have their own CDN capabilities, so the less people using their cloud services, the better for Cloudflare.
Having worked in an ISP, only one thing mattered to costumers, and only one thing: YouTube.
Mind you, I'm still skeptical. I probably won't use Warp on my phone, or Cloudflare on my personal site. But I should have been more careful about how I expressed that skepticism in public. None of us want a world where we all assume the worst in each other without strong evidence. So again, I'm sorry.
I've been using Tor as a privacy-friendly VPN, so Cloudflare getting into this business will make it feel a bit different, every time I see an error Web page that says Cloudflare is blocking a Tor exit node from viewing a page that Cloudflare hosts.
Perhaps Cloudflare could figure out how to block competitor Tor less (even if there's abuse coming in through Tor)? That might be difficult, but an excellent show of good faith.
they are: https://blog.cloudflare.com/cloudflare-onion-service/
Routing VPNs through Tor is a great way to avoid site discrimination against Tor users. But there are two key problems. One is that you degrade Tor anonymity, because Tor can't switch circuits (normally at ~10 minute interval). And also because you typically must pay for VPN services.
The other problem is that Tor only routes TCP traffic. So when you use TCP-based VPNs routed through Tor, and are using HTTPS or some other TCP flavor, you get the TCP-in-TCP horrors. There's too much error correction.
So yes, Cloudflare would need to allow Warp via Tor. Or maybe even better, Warp via Tor via Warp. And also it would need to protect Tor anonymity.
Cool idea, though :)
Warp would see all your incoming packets and all your outgoing packets, so why bother with Tor?
But still, if it were done right, that's not necessarily true. I mean, I can have two accounts with some VPN service. I connect to server1.vpn.com using one account. Then I connect to the Tor network via that VPN tunnel. And then I connect to server2.vpn.com via Tor, using the other account. Even better, I connect to server2.onion, using the other account.
Even then, Cloudflare could easily do traffic correlation. But as it is now, the NSA can easily do traffic correlation. So hey.
then setup a computer at various data centers/locations around the world that you can route your traffic through (its a VPN now)
and then either
1) run a Virtual Machine in that which connects through VPN
2) run a remote machine which connects to the outside through VPN
Amusingly, this is actually not true. TCP was originally developed to run on an inter-network over two networks: the ARPANET which has the reliability characteristics of a "traditional" network, and an extremely mobile network with lots of packet loss: ship-to-ship packet radio.
TCP today seems very poorly suited for the mobile environment, but it was in fact originally designed for mobile.
Which is to say, it still feels largely experimental.
I just mentioned it as it's a cool project and in time will help address some of the limitations you mention.
This is one part of a tug-of-war that's going on in recent years between Internet network operators and cloud providers, with the cloud providers slowly but surely winning.
For better or worse, we are moving away from a distributed Internet composed of many autonomous networks into a future in which the only job of the ISPs is to connect homes and offices to the local POPs (Points Of Presence) of the large cloud providers.
Why do you need connectivity to other networks when you can get Google (w/ Youtube & GCE) and Facebook from a local POP? Add to that all the sites and services that reside on Amazon, Azure, Cloud Flare, Akamai, and maybe a few more large clouds/CDNs, and you don't need a public Internet anymore. Imagine the security and performance benefits of that!
Centralization is far easier to manage. A single entity has the ability to control all routes and all the pieces of the network. The structure can become faster, mesh-networks are notoriously slow. By using a VPN + Argo cloudflare has control over how your data is routed, and can make sure it skips slow network segments, is peered well, etc.
Decentralization doesn't require trust if implemented correctly. This is it's biggest selling point IMO. If implemented correctly (which is hard to do) it can have better uptime, as we aren't relying on any single entity. But, with meshnetworks as an example, a specific route could be slower then the others, and there's often not much you can do about it. Decentralization if not implemented correctly is a nightmare on so many levels. There's nobody to appeal to if an issue occurs. If trust isn't implemented correctly (current state of ISPs) then we have multiple parties who can spy/modify your communications.
You statement is the exact opposite of reality.
These are companies that respond to market pressures. Routing around the network operators (both figuratively and literally) makes a lot of sense for large cloud providers. Especially so if there are no network neutrality rules in place to enforce free access to consumers (as opposed to consumer ISPs demanding payment for pushing content to their subscribers).
Also, the content from Google, Facebook and a couple other cloud providers is what consumers actually want. I've seen internal numbers from a European mobile provider that show that >80% of consumer traffic is to/from either Facebook or Youtube. So are the consumers villains?
If you measured that by doing a count() and group by on the domains of a traffic log, it would be easy to draw a conclusion that doesn't meaningfully reflect real user activity.
What content from Google and Facebook? If you are referring to YouTube and Instagram - that's one part of the total internet content consumed. Hard to totally ignore the news sites, blogs and streaming services.
The centralization of the internet and death of the “end to end” ethos is very real unfortunately.
They aren't a villain, they're an illustration of market forces currently favoring centralization. Like CenturyLink and Comcast, for that matter.
While not in itself neutral, it seems like it should help to preserve the competition that network neutrality is supposed to enable, since it's easy for small organizations to hook up with Cloudflare and they do encryption where they can.
I'm reminded of Galbraith's theory of countervailing power, which seems like a more realistic approach than always thinking in terms of centralization versus decentralization:
https://en.m.wikipedia.org/wiki/Countervailing_power
Also, consider how companies try to commoditize their complements, which having competition at different layers tends to do:
I have been supporting FSF, ACLU, etc. for years, but the practical considerations that prompted me to be a bit more trusting are Cloud Search in GSuite, Cloudflare offering HTTPS to help get the web more secure, and a deep appreciation for having Firefox available (containers are so easy to use and make me feel more secure in my use of the web).
I don't trust cloudflare to not make mistakes (like Cloudbleed). I don't trust myself to not make mistakes. I don't think there is anyone I trust not to make mistakes. It's just not a reasonable criteria.
I'm in a position where I do appreciate Google's software, Chrome/V8 and resulting node and electron as downstream projects. However, my trust of Google is waning in light of their incredibly divisive culture all around and a lot of their practices, cover ups and just poor form in the sun-setting of "don't be evil."
Personally I find the performance of PIA fine. I just ran a test through fast.com and got 42 mbps on 4g through PIA mobile VPN in NYC. (Weirdly, when I turn off the VPN and test I'm only getting around 2 Mbps.) Latency is a bit higher than direct, but not enough for me to agree with their blanket statement that all VPNs suck.
I look forward to testing with Warp once it's released, but I don't see how it could be much better than the status quo. PIA has lots of servers all over the place, cloudflare might have a bigger network but the delta should be negligible.
I am a bit surprised that fast would get throttled though.
Then again, I don't always notice even on a larger screen from a better 720p stream and a poorer (relatively) 1080p stream. I often notice the difference from 1080p to 4K though, which is a slightly bigger bump on a much larger screen.
Fast.com runs its tests against the actual servers that stream Netflix to you. It uses the same selection algorithms as actual Netflix. The whole point of it was so that you use Fast.com and then call your ISP and say you did a speed test and aren't getting anything close to the speed that they advertised.
On the back end they can't tell the difference between a Fast.com speed test and actually playing Netflix, and that was the point. So if they are going to throttle one they have to throttle both.
But this only sends DNS over the VPN so it won’t use much power at all. 99% of your traffic does not route via the VPN with this app.
> Any unencrypted connections are encrypted automatically and by default.
> Unfortunately, a lot of the Internet is still unencrypted. For that, Warp automatically adds encryption from your device to the edge of Cloudflare’s network
It reads to me like all your traffic goes through your service, not just DNS.
The blog led me to their "1.1.1.1 app", which I installed and found created a VPN on my iOS device that only tunneled DNS traffic.
This "warp" thing, which is not released you can only go on a waiting list for, will apparently tunnel all traffic.
My apologies for the error.
Every free product comes with a catch. When this catch is not clearly explained by the company, I always feel it's because the reason is too "shady" to acknowledge publicly (like Gmail and Facebook gathering data for advertisers). I'm probably naive to believe the reason here is vastly different, but the tone and style of this article puts Cloudflare closer to Apple than to Google privacy-wise in my eyes.
While it's true that if Cloudflare was evil, they could fairly likely identify you from metadata, that's a lot more complex and a lot more error-prone than having you sign in.
I am curious though if this will extend to their premium Warp+ offering though, as presumably they need to identify a paying customer. Perhaps if they're entirely built off of IAP on whatever platforms their clients are on, they can avoid this problem entirely?
Yup... a rare beast these days. My niece is a gifted writer - one of less than a half dozen that I personally know.
She graduated recently and had her pick of several positions due to her portfolio of work.
Just curious, do you hire copywriters?
Aside from previous job experience, what sort of things are in a portfolio like this?
Nobody does it quite like him, though @jgrahamc is great too, and I try to encourage my team to follow the lead here as much as possible.
> on “April Fools” a handful of elite tech companies decide to waste the time of literally billions of people with juvenile jokes that only they find funny.
Bah Humbug much?
I'd say the backlash is due to unaccountability, privacy erosion, and income inequality.
April Fools gimmicks are barely a blip on the radar compared to the above. At best they provide a target to focus the above ire on, but that's confusing the issue.
> a handful of elite tech companies decide to waste the time of literally billions of people with juvenile jokes that only they find funny.
I sort of agree, but it's not nice, and not necessary. It also isn't particularly classy to then go on to say "and we're so much better, because we do useful things".
(I do happen to find Cloudflare, as a company, so much better, and awesome things like 1.1.1.1 and warp make me really want to push my employer to use Cloudflare for all the things).
It's the fast path to replacing the decentralized internet with a few proprietary CDNs. I'm much more excited about those projects that actually try to fix the raised issues:
Unencrypted connections -> TLS / Letsencrypt
TCP sucks on mobile/roaming devices -> QUIC & HTTP/3
I'm not saying Cloudflare isn't doing good things for the Internet but it's a bit disingenuous to equate the 2 efforts. Cloudflare could have done LetsEncrypt, but as a CDN that would make no business sense - which is why we need LetsEncrypt, so they can continue to do the things that don't make good business sense for Cloudflare.
I believe CF is working on LetsEncrypt certificates, at least based on letsencrypt.org being included in the 'automatic' CAA records[1].
0: https://community.letsencrypt.org/t/issuance-criteria-for-ir...
1: https://support.cloudflare.com/hc/en-us/articles/11500031083...
Which, incidentally, allows you freer access to the open Internet.
A good add on though might be a way for people to run their own service on a Cloudflare worker that gets hit with each request to 1^4, which would allow them to run their own ad blocker.
Making it a plugin that you could plug another app into might be cool, though?
Alternatively, I have a Xperia XA1 running a June 5, 2017 security patch. It's been my intent for a long time now to figure out how to get root without unlocking the boot loader the sony approved way (which makes the camera less functional). Anyone have any pointers on easy to exploit privilege escalations that should exist on my phone?
Could also approach from usb/wifi/bluetooth/etc instead of local userspace.
The problem specifically is that unlocking the bootloader the official way deletes drm keys stored in a "TA" partition, and that makes the camera less functional. It would be sufficient to find a vulnerability that let me back up the DRM keys - but that seems unlikely without gaining root access and I'd have more confidence that I backed up the right thing with root access.
Unfortunately AFAIK all community run mods for Android require bootloader to be unlocked.
In all honesty it's pretty rare that I use anything not browser based that might have ads, but on principle I'd like to keep it around.
Otherwise, you are out of luck. You cannot run the 1.1.1.1 app and run another VPN app like blockada, netguard, no-root-firewall side by side on Android (at least not supported till the latest release, Android 10).
https://www.ckn.io/blog/2017/11/14/wireguard-vpn-typical-set...
So what happens when people start using Warp to hide their IP so they can hack, scan, scrape, upload malware, etc? Is Cloudflare going to show captchas to Warp users and slow down their experience? What is the plan to mitigate abuse on a free VPN that doesn't log?
On my phone my web traffic is being sent direct using this, looks like only DNS queries are sent over the VPN tunnel?
Is WARP+ the full VPN ?
Will warp be available on desktop machines at some point?
If you wish to block or otherwise take action on, e.g., malicious traffic from the IP being used to connect to Warp, you'll be able to do so.
See https://support.cloudflare.com/hc/en-us/articles/200170986-H... for details.
1- https://blog.cloudflare.com/mmproxy-creative-way-of-preservi...
Are Cloudflare going to be able to decrypt the TLS sessions running over their VPN between me and end-sites, so they can insert this additional HTTP header?
Doesn’t sound feasible.
Therefore Warp will be open-source and its distribution will be free from the control of commercial third parties via "app stores".
Those who do not wish to use an "app store" may compile Warp themselves or download binaries from their preferred repository for sideloading, e.g., F-Droid.
April Fools
Sounds interesting though!
I'd imagine they'd test the performance with say 100 users, then another 900 to make it a round 1000, then if they see the 1000 users only use 1% CPU, they could just go up to 10000 to see if it uses 10% CPU or just 5%...
And after they figure out how many servers/how much bandwidth they need, they could just bring in e.g. 100K users online at once.
Just does it over and over.
1. Is there a public endpoint for boringtun/noise? For playing with
2. Any chance the client (desktop) will be open source? Would love to help if possible.
3. Any interest in a WebRTC (and webRequestBlocking) based chrome extension/client?
That would probably not need anything special installed on desktops and would be awesomeAlso, this post is relevant: https://blog.cloudflare.com/boringtun-userspace-wireguard-ru...
1- https://github.com/cloudflare/boringtun
Switched the account so it wouldn't be confusing who was commenting.
Also I wonder how do you work with censors? For example Russia censors internet and requires that all VPN services cooperate and censor internet for Russian customers as well (probably they will ban services that won't comply). Will you cooperate or will you accept that Russian users won't be able to reach your service? I guess, that some other countries use or will use similar techniques. For example I'm from Kazakhstan, there are many banned websites and they seem to ban popular VPN and proxy services as well (I'm using my own server with OpenVPN, but obviously I'm just a small fish to bother).
It would be amazing if it could be made to work from standard wireguard, but I suppose there's a chance that if desktop versions arrive, you'll be able to extract the keys.
The only thing stopping that would be if Cloudflare broke the protocol.
It's okay to just say, "Hey, we are running a free VPN. We're making some privacy guarantees and are trying to log as little as possible. That exposes us to being abused, which means that we have to put some limits in-place on the client."
There's nothing unreasonable about that at all.
Would you ever make the code of the 1.1.1.1 app with Warp open source?
On the open source thing: maybe? It's hard to say. In general, we like to open source libraries and stand alone applications. And we think pretty carefully about the cost of supporting an open source community as well. Which is, I think, a thing people overlook.
Embrace, extend, extinguish!
It would be nice to know the policy there. For those of us that do know what a VPN is, and are okay not having access to support, getting things to work without a desktop app would be nice.
It's important to appreciate that we have literally millions of users for the 1.1.1.1 App and we are rolling out a free VPN for them. That is a huge support and network burden that we have to deal with to make that experience work well. Yes, we use WireGuard under the hood (and have open sourced our Rust code), but the additional cost of supporting people connecting from their WireGuard clients means that we don't want to support that _today_. Please bear with us while we get through a massive roll out.
[1]https://lists.zx2c4.com/pipermail/wireguard/2019-March/00404...
From what I understand, Jason was willing to make your guys head of a sub-project. I'm failing to see how this would hinder your development, considering you've probably got your own build and deployment systems anyway. The way you've done it feels like a 'chuck the code over the fence' style of interaction, which again - I can't see any rationale, from a project perspective (imho)
I don't think anyone on Linux setting up and tweaking WireGuard to integrate with CloudFlare's free network expects to be able to call up support and be like "hey, I need help debugging my custom client." :-) As far as network burden, you're just concerned that we'll be using too much traffic?
It's Cloudflare's service, and of course entirely Cloudflare's decision how it is permitted used. I just hope that, in the future, it will be allowed (but not necessarily *supported) to use stock clients rather than desktop apps (which many of us Linux people would dislike). :)
Good luck with the massive deployment!
1. VPN from mobile device to the nearest Cloudflare PoP.
2. Use Cloudflare backbone to connect to the nearest exit PoP to destination.
3. Between entry and exit PoPs, do all sorts of optimisations that are possible, like:
3a. Jumbo frames, custom/advanced form of TCP congestion control, multipath, fast-open.
3b. Custom transport protocol (quic, sctp, etc).
3c. Custom compression and error correction schemes.
4. Reverse CDN: Proxy HTTP/S requests and serve content from cache.
5. Peer CDN: serve content from nearby devices?
Something like AWS Silk [0] or Google Chrome FlyWheel [1] but on steroids.
Easier said than done, I guess.
[1] https://blog.apnic.net/2018/04/02/apnic-labs-enters-into-a-r...
People willingly pay $5-10/mo for a VPN that is nowhere near this level.
NOTE: I doubt this won't survive longer than 3 days in China mainland (inside GFW).
“2. We will never sell your browsing data or use it in any way to target you with advertising data;”
Does this mean they have the right to sell browsing data for other purposes than “to target you with advertising data”?
Even without any personal data, the data generated when using their DNS-service, such as statistics on domain names, can be of great value for e.g. Hedge Funds and SEO-companies wanting to know how big a domain name is based on DNS-request statistics.
My question is therefore: Do they have the right to sell non-personal DNS-request statistics to third parties?
https://www.cloudflare.com/public-resolver-mobile-privacy/
In paragraph 2 Cloudflare says "We do not receive your phone number, device ID, IP address or any other information that could identify you when you install or use the Mobile Application."
But in paragraph 4 it says "These Service Providers may only process personal information pursuant to our instructions".
So which is it - do they collect personal info or not?
This Sounds Too Good To Be True
That’s exactly what I thought when I read about the
launch of Gmail exactly 15 years ago today.
Is this supposed to make me less suspicious?Maybe they are using one tunnel interface per single customer then always assign the same address to everybody and use policy routing to handle this (EDIT: just realized there might not be using the network stack at all for this and do something alike in their userspace implementation). This would not solve key exchange though. But maybe it is possible to accept any key (if the public key is transmitted this should be easy). Otherwise connecting probably requires requesting an IP address for your key prior to connecting via WireGuard to allow the endpoint to setup required configuration.
This is really something WireGuard did not quite expect to be needed apparently. It is also hard to do dynamic routing with WireGuard which could also possibly allow fully meshed networks directly on top of WireGuard but i have not tried really hard yet. It would also be very useful to me to be able to have a CA so i do not have to update configuration everywhere. Last but not least its not possible to bridge the WireGuard interface at all. I have an experimental setup where i would like to use WireGuard as a sole network interface for a virtual machine, somewhat like advertised for containers where it works beautifully. However, its not possible because its not an Ethernet interface in Linux. Instead i have setup a VLAN on my switch and route traffic through WireGuard using my gateway. I would like to terminate the tunnels at the hypervisor a lot more, but don't want to route traffic there.
I think all of this boils down to the usage of their cryptographic routing and trickery around it to make it work as intended. I would probably abandon WireGuard if a fork would allow my use cases as i am otherwise a really happy user.
Maybe next you can do a better security for our WiFi? But this might require releasing a better hardware not just software.
Edit: It's fixed and I'm on the waitlist.
Happened to me as well, and that’s why I came looking for the canonical post on this topic to see what’s happening. I switched networks and tried, but got no waitlist number. There’s just a message saying I’m on the waitlist and the button to join the waitlist is still visible and enabled.
Now that I see people from Cloudflare have responded, I’ll just wait and see.
> 2. We will never sell your browsing data or use it in any way to target you with advertising data;
Is it just me or are these terms super-specific? They can easily be circumvented to achieve real logging, especially at Cloudflare's scale. While I trust Cloudflare as a company, I feel like they're being a bit disingenuous here.
[1] https://blog.cloudflare.com/boringtun-userspace-wireguard-ru...
2. They're onboarding people slowly. You can't use it yet without an invitation.
https://github.com/cloudflare/boringtun/issues?q=is%3Aissue+...
That's great... but you do log user-identifiable info? How I read that is "we log things that can identify you but just keep it in memory for X amount of time".
Myself and other privacy-minded folks would like to know more details there, especially as this is a freemium service.
I don't think their target audience includes those people (privacy minded folks.)
The short answer is we really don't want to have data. We store bits of it for aggregate analysis and debugging, but the goal is to not be able to map traffic to individual people as quickly as possible.
I like both companies so maybe I'll just keep supporting Mullvad and recommend 1.1.1.1 to friends and family once Warp is in general availability (those "people who don't know what a VPN is").
Warp+ looks to be a solid business use case which I think fits well with Argo and their other offerings. Either way, it's good to have another proper VPN option outside of (self)hosted WireGuard.
Many thanks for democratizing this service, as is always the case with Cloudflare.
1. When you use WireGuard as a VPN your device is connecting to wherever you happen to have hosted your server. Cloudflare's PoPs are located in 165 different Internet exchanges and ISPs, giving you a pretty good chance to be closer to you wherever you are in the world.
2. We (Cloudflare) have tech through our Mobile SDK product which can optimize the actual way the Internet TCP traffic is mapped into UDP.
3. We also have Argo, a technology for optimizing the routing of packets through the Internet which will be released as Warp+.
So geo-specific things will break... BBC.com should load though since its for out-of-UK people
I'm not having any trouble with bbc.co.uk on 1.1.1.1, maybe it was a temporary hiccup.
(Disclosure: I work for Cloudflare but not on this product.)
I am getting more than 300ms difference to google.com
curl -v cloudflare.com 2>&1 | grep -i CF-Ray
The letters should correspond to an airport code nearby the CF server you landed on. Let me know what it says. CF-RAY: 4c0c98839feb5ff3-MRS
Its hitting the Marseille, France POP.I posted the issue (bad route) on the community forum a few months ago.
https://community.cloudflare.com/t/high-ping-sri-lanka/15276...
I'll try it again for awhile and see if I have any issues now.
Cloudflare do not use the EDNS Client Subnet extension:
https://tools.ietf.org/html/rfc7871
You are right to say that can potentially affect geo-located services. But that is not to say that 1.1.1.1 doesn’t support EDNS:
Use case: I want to be able to say, "only use VPN when on WiFi networks (not cellular), and if so, only activate on public WiFi networks (not my home WiFi).
https://www.purevpn.com/download/router-vpn https://www.expressvpn.com/vpn-software/vpn-router
By doing the least work possible: creating a proxy. They haven't actually fixed the internet at all, they just made a new middle box.
https://askubuntu.com/questions/1001241/can-netplan-configur...
I would say "anonymity" is a fairly strong term for what's being offered here. It's going to hide your source IP, and if you don't mind CF seeing your unencrypted content (and the fact it's unencrypted kinda means that from a technical perspective, you already don't care), it may improve the amount of the connection to unencrypted content that is encrypted (and thereby block the "coffee shop" attack fairly well), but that's all. They're not going to actively strip the bajillions of other active tracking techniques being used nowadays. Your phone will still track location. Facebook will still track you on your phone every bit as much as they did before. etc.
This is part of a complicated set of measures you may be able to take to attain anonymity, but not even remotely the full package.
Again, this is a technical posting to ensure that people understand what this is and is not. This is not a criticism of the service for not being something it isn't or anything like that.
Less technically and more value-judgy (though still not much), note the title: "Introducing Warp: Fixing Mobile Internet Performance and Security" Performance was highlighted first, security second. This seems to me to be a reasonable and accurate reflection of the nature of the service.
It's worth thinking about...we had this situation before with AOL. That is, a pretty large number of people in diverse geographic areas, all coming from a small number of IP addresses.
People do use that "relative" anonymity for lots of things, not all of them good. Also, it may create some issues for things like geolocation, regional content restrictions, credit card fraud detection, SMTP blacklisting, rate limiting, and so forth. Because your offering is free, and CF is well known, I'm guessing it will grow fast. Not suggesting anything change about it, just that it may create something that site owners need to react to.
Interesting to see competition heat up at the VPN level.
This is especially true for certain privacy and security focused applications. For example, Signal release their code, have quite a lot of users, and don't report an unmanageable overhead due to having released their source code.
It's not just a matter of trusting their intentions, it's a matter of knowing that their code matches their intentions. I trust OpenSSL (mostly, these days) and I always trusted the intentions of the developers, but if their code was not open it would not be half as secure today.
As far as their bottom line, I guess this helps them sell services by having a documented number of people suckling the internet straight from the CF teat?
When I read something like that I feel protected and cared about. Now, can someone explain me why this should be in any form different from the WhatsApp case?
The Department of Homeland Security offered to buy the data from Project Honeypot (run by Matthew Prince and Lee Holloway), and they sold it to them for $20,000. Michele Zatlyn (a classmate of Prince) said "if they'll pay for it, other people will pay for it."
"And so the idea for Cloudflare was born, with Ms Zatlyn as its third co-founder." [with Prince and Holloway]
If CloudFlare is bought by Comcast and they start doing Bad Guy Things™, then your exposed surface area is rather low.
and which you were probably saving for April 1ˢᵗ
Forgive me they were delicious so sweet and
IRONIC
I started using 1.1.1.1 last April from the start. Later I decided I want a firewall on my Android phone as well and installed NetGuard. Unfortunately both apps can not run at the same time, because they are both "VPN".
Really hope there are plans for a firewall built into 1.1.1.1 in the future.
Google photos didn't want to sync when using the CloudFlare 1.1.1.1 app. I think I had problems with podcast apps in the past too.
But looking good so far.
Is this by design or there is possibly something wrong with my router's DNS setup?
Even moreso once this Warp VPN functionality is live.
How do they make money?
So, the price plan and extras from Business, Professional and Enterprise CDN is enough to cover all the cost of running the network + free tier CDN + Domain Registration Operation + DNS + Free tier VPN?
There is a reason why I am using Apple. Their interest is in me using iPhone or Apple devices with a very decent profits margin, and hopefully up sell me into any convenience services like iCloud and in the future Apple Cards. They are simple and easy to understand Business Model. Even iWork, Map, and all other Services are deducted from each Apple devices sold and now accounted into Services.
So how do Cloudflare make money with free VPN?
> Warp+ premium service
> enterprise VPN space
> So the more people who install Warp, the more valuable Cloudflare’s core services become.
The last one being the key: they acknowledge they will run it even if it's not profitable. See my other comment.
[1] Since you are all about speed!
They don't make money, they just want to gain market leverage. This will make their network more interesting because of crowd effect. Akin to fb letting people create profiles/chat, google giving free search results/emails/file hosting, etc. Just finished reading a book about this, see [1] for a review.
[1] https://blogs.lse.ac.uk/lsereviewofbooks/2017/06/05/book-rev...
Facebook's business modem is simple, Ads. And its business model only works once you reach a certain level of user and usage.
Tried VPNs at some point. It was a slower and more error prone Internet experience. For doubtful privacy gains.
It would awesome to have static IPs as well.
I'm really hoping it works out, and Cloudflare can continue to contribute their expertise working with WG. At the end of the day, this benefits everyone since OpenVPN whilst it's reliable in my experience, is just too burdensome.
I also am intrigued by the price, and features that will differ between free/pro. I suspect many VPN services over the next few years will feel the effects of this (is that why they're all rushing to add 3 year plans?)
Warp+ will use Argo (our "Waze" of the Internet) to improve routing. It significantly improves reliability and performance. Pricing for Warp+ will vary by region/country to ensure it's appropriately affordable everywhere.
I'm referring to the routing logic and optimisation algos.
Asked already several times in the past. I'm very curious as I've worked a lot on those specific issues. Thanks.
- Certificate[1] info:
- subject `CN=Google Internet Authority G3,O=Google Trust Services,C=US', issuer `CN=GlobalSign,O=GlobalSign,OU=GlobalSign Root CA - R2', serial 0x01e3a9301cfc7206383f9a531d, RSA key 2048 bits, signed using RSA-SHA256, activated `2017-06-15 00:00:42 UTC', expires `2021-12-15 00:00:42 UTC', pin-sha256="f8NnEFZxQ4ExFOhSN7EiFWtiudZQVD2oY60uauV/n78="
- Status: The certificate is trusted.Now the apps will be upgraded with Warp, an option to set up a full data VPN over WireGuard, terminating at any worldwide PoP.
This should give you super low latency to your VPN server, and also open up the possibility of local caching smarts on the device.
Basic service is free, premium service coming that’ll put you on the CF backbone for all your traffic, should take you off the public internet and speed things up.
Desktop versions coming as well.
Will Cloudflare push all of the users in a given country to an exit point in their country? Can they realistically do that? Will it guarantee that, or will it vary with load? Will they detect VPNs coming into the service, or will it be a good way of laundering the VPN? Will it do anything at all as an anti censorship service?
Tl:dr, I'd expect an awful lot of sites that currently block VPNs entirely (and that practice is increasing) to keep doing it here.
1. What will the exit IPs be? Will I get to stay with-in my region and access region specific content, or can I bypass censors, both government (porn, "glory of Islam", etc), and private (Netflix region-specific content, GDPR non-compliant websites that accidentally block my region).
2. Can I select my own exit region?
3. How do they handle abuse? Can I spam and get their IP blacklisted? (I'm curious, not actually nefarious)
2. No
3. Exactly what an actually nefarious person WOULD say!
> Exactly what an actually nefarious person WOULD say!
It's hard to distinguish between curious and nefarious people after a point, I suppose ;) but that's still not an answer :)
No matter what words they use, the model is a dangerous one and we should be just as wary of it coming from cloudflare as we would if it were coming from google.
Service Scope User Data
DNS 1.1.1.1 users Browsing history
CDN/Proxy CF protected websites SSL decrypted user forms, passwords, emails
Warp VPN Warp users Device data, browsing history, apps traffic
Most sensitive is raw, SSL decrypted web traffic, and users using two or more services at the same time. CF promise they don't use data, but legalese have loopholes, like do they store/use aggregated (not raw) data?I'm using native iOS/MacOS IKEv2 client with selected few VPN providers, and pretty happy with not having 3rd party app on my mobiles/desktops.
OK. TFA says "We built Warp around WireGuard". That kills native client support.
It'd be interesting to see a response from Cloudflare (unless there is one an I've missed it)
Well, there's at least two coming out this year. I can understand them wanting to handle the 99% of use cases first, but as I understand it they won't allow normal Wiregaurd clients to connect which is sad but entirely their call.
Did the same with Nord and a dozen other vpn-of-the-week services. no-logs means no-accountability which means malicious traffic which means you don't get to talk to our stuff.
>TCP, the foundational protocol of the Internet, was never designed for a mobile environment.
Packet loss due this is mentioned, but I don't see a relevance to the new VPN service; especially when the next section talks about wrap using UDP.
> We’ve built Warp around a UDP-based protocol
Other VPN providers do offer an option of choosing TCP/UDP as per usage i.e. better reliability vs faster speed.
I'm glad that it uses Wireguard, but it's likely other major VPN providers are working on a Wireguard version for their clients & so in the end it would come down to speed/price/privacy which hopefully cloudflare can compete with.
I don't think TCP-based VPNs are offered for increased reliability. They might be offered so you can run your VPN traffic in restricted scenarios, e.g. I run a VPN-ish service that uses TCP/443 by default and all connections are only outbound, so you can still use your VPN in restrictive scenarios.
Outside that, encapsulating TCP inside TCP is nothing short of a headache as you have two congestion control algorithms kicking in and one doesn't know about the other.
One day when away from the office, I pinned my wifi DNS settings to 8.8.8.8 just to try it out & compare it to the DNS I normally use at home, but then I forgot to undo it. When I got back to the office, the office Intranet was unsurprisingly inaccessible, and I removed the pinned DNS settings. I knew how to solve the problem, but less savvy folks trying out the Cloudflare product might not, which could create some confusion for IT helpdesks.
Cloudflare is concerned with the user experience of people who don't know what a VPN is, and that's why I mentioned it. Normally I would have just tried it & reported the edge case I it exists, but the app isn't usable yet, so I posed the question instead. Judging by the downvotes, I should have mentioned that in my comment above :)