Cloudflare: Warp for Linux and Proxy Mode
blog.cloudflare.com
blog.cloudflare.com
Cloudflare has the ability, and has used the ability to speed gate most of the internet with no transparency. Can cloudflare please provide notice on when domains start getting speedgated? Until then I'm not sure it's a good idea to move any sort of remote access capabilities (e.g. Warp for teams) onto Cloudflare's infrastructure. Not until they get a better support team and are more transparent when your account starts getting limited. I've spent hours trying to debug this problem and it ended up being the proxy.
The one massively annoying thing is their split tunnel config does not let you ONLY route your enterprise IP ranges through cloudflare for teams. Ie, you want users to have access to 10.15.XXX.XXX but the rest of their traffic is unmolested.
You can only EXCLUDE some items from the routing, not just route some ranges. Weird isn't it?
Most users at home want netflix, local printing etc to continue to work as it did before their employer has them stick cloudflare on machine. Routing all their private traffic through cloudflare seems like a big miss.
Info here: https://developers.cloudflare.com/cloudflare-one/connections...
And yes, the junky folks have this solved - you drop the endpoint on client, set a split tunnel and just pick up your enterprise route.
A basic split tunnel (normal style) or one that picked up accessible ranges based on the individual user permissions both would work fine. So if you had a single app on 10.15.54.120 and user had access to that app, split tunnel would put that into route. Key is to leave everything else out - so your computer can see your phone can see your lights etc etc on local network and netflix and friends work normally.
I started using it a few weeks ago while travelling and I've found it reliable and painless.
One thing I miss with 1.1.1.1 and WARP is DNS based ad blocking and filtering. NextDNS has handled that part quite well, allowing multiple profiles (so you can have different rules for different devices) to be setup in a single account. One can choose different filter lists and manage custom allow/deny lists too. The simpler filter lists are what one would choose with something like uBlock Origin. The NextDNS app on iOS is also just a DoH DNS provider and not a “VPN” app. This allows using another VPN app (or VPN service) while simultaneously relying on NextDNS for DNS.
I understand that Cloudflare wants users to use WARP+ for routing traffic too, but it would be useful to add more flexible DNS filtering capabilities (similar to NextDNS) and also provide for a non-VPN setup on iOS. As I understand it, the Cloudflare DNS service has a malware blocking/family mode and another (default) one that’s not.
Isn't that a lot less useful today anyway, given the new trend of serving ads through the same domain as the content you want to see? Why not just go all in on uBlock Origin?
I agree its effectiveness is wearing down as ads are served via the first party domain, but it still does make a difference.
An app that requires me to use sudo to send feedback doesn't seem like the kind of app I want to be running with sudo.
But, from the docs, if you run
> ~$ sudo warp-diag
(without the "feedback" argument), you can see the logs that are created and attached to the support ticket if you use "feedback" [1].
[1] https://developers.cloudflare.com/warp-client/setting-up/lin...
I can see the use case here for when connecting to the local Starbucks wifi to thwart potential bad actors sniffing your data on the wire, but your traffic can still be seen by Cloudflare. Using this is just shifting your network data to Cloudflare who play the 'good guy' (I hope)
Reminder: sending your traffic to Cloudflare means entrusting your privacy to them, the US government, the government of the countries where their datacenters are, the datacenter ISPs.
Is it better than your local ISP? Difficult to tell.
But creating a monopoly that controls most websites, DNS and VPNs is very dangerous for the world.
If you care about privacy and freedom of information for everybody, please support Tor instead.
tor for info.
i2p + tor is a great combo.
Also I'd love docker version just for socks proxy. I made one myself using RHEL UBI8 image, but official one would be perfect.
E.g., with:
In retrospect, I guess it's obvious that when nerdy but extremely popular tech mogul globally popularizes a pun on tunneling and boring that we'd see it pop up other places.
Still though, ugh.
after being bitten several times by questionably packaged third-party repositories I now refuse to use any third-party repos
Hacking, CSAM, Piracy, etc. will all be routed through Cloudflare's massive network -- and all for free.
And, I don't think they keep serious logs on traffic. So, DMCA holders are going to throw a fit if this gets popular, which seems to be the aim?