1- https://github.com/cloudflare/boringtun
Also I wonder how do you work with censors? For example Russia censors internet and requires that all VPN services cooperate and censor internet for Russian customers as well (probably they will ban services that won't comply). Will you cooperate or will you accept that Russian users won't be able to reach your service? I guess, that some other countries use or will use similar techniques. For example I'm from Kazakhstan, there are many banned websites and they seem to ban popular VPN and proxy services as well (I'm using my own server with OpenVPN, but obviously I'm just a small fish to bother).
It would be nice to know the policy there. For those of us that do know what a VPN is, and are okay not having access to support, getting things to work without a desktop app would be nice.
It's important to appreciate that we have literally millions of users for the 1.1.1.1 App and we are rolling out a free VPN for them. That is a huge support and network burden that we have to deal with to make that experience work well. Yes, we use WireGuard under the hood (and have open sourced our Rust code), but the additional cost of supporting people connecting from their WireGuard clients means that we don't want to support that _today_. Please bear with us while we get through a massive roll out.
[1]https://lists.zx2c4.com/pipermail/wireguard/2019-March/00404...
From what I understand, Jason was willing to make your guys head of a sub-project. I'm failing to see how this would hinder your development, considering you've probably got your own build and deployment systems anyway. The way you've done it feels like a 'chuck the code over the fence' style of interaction, which again - I can't see any rationale, from a project perspective (imho)
It's Cloudflare's service, and of course entirely Cloudflare's decision how it is permitted used. I just hope that, in the future, it will be allowed (but not necessarily *supported) to use stock clients rather than desktop apps (which many of us Linux people would dislike). :)
Good luck with the massive deployment!
I don't think anyone on Linux setting up and tweaking WireGuard to integrate with CloudFlare's free network expects to be able to call up support and be like "hey, I need help debugging my custom client." :-) As far as network burden, you're just concerned that we'll be using too much traffic?
Would you ever make the code of the 1.1.1.1 app with Warp open source?
On the open source thing: maybe? It's hard to say. In general, we like to open source libraries and stand alone applications. And we think pretty carefully about the cost of supporting an open source community as well. Which is, I think, a thing people overlook.
Embrace, extend, extinguish!
It would be amazing if it could be made to work from standard wireguard, but I suppose there's a chance that if desktop versions arrive, you'll be able to extract the keys.
The only thing stopping that would be if Cloudflare broke the protocol.
It's okay to just say, "Hey, we are running a free VPN. We're making some privacy guarantees and are trying to log as little as possible. That exposes us to being abused, which means that we have to put some limits in-place on the client."
There's nothing unreasonable about that at all.
Switched the account so it wouldn't be confusing who was commenting.
Also, this post is relevant: https://blog.cloudflare.com/boringtun-userspace-wireguard-ru...
1. VPN from mobile device to the nearest Cloudflare PoP.
2. Use Cloudflare backbone to connect to the nearest exit PoP to destination.
3. Between entry and exit PoPs, do all sorts of optimisations that are possible, like:
3a. Jumbo frames, custom/advanced form of TCP congestion control, multipath, fast-open.
3b. Custom transport protocol (quic, sctp, etc).
3c. Custom compression and error correction schemes.
4. Reverse CDN: Proxy HTTP/S requests and serve content from cache.
5. Peer CDN: serve content from nearby devices?
Something like AWS Silk [0] or Google Chrome FlyWheel [1] but on steroids.
Easier said than done, I guess.