Cloudflare is now powering Microsoft Edge Secure Network
blog.cloudflare.com
blog.cloudflare.com
There is already precedent for this happening in Russia; in that incident every VPN pulled out of the country. However if everyone enforces it, it's gonna be hard.
--
From a purely technical perspective this seems to equivalent to Apple Private Relay _iff_ the operator for the ingress and egress are two different endpoints, which it is not clear from the presentation.
In the case of APR Apple has their own servers (mask-h2.icloud.com) that accepts connections and obscures the IP <-> website mapping for their exit relay providers, who are Cloudflare, Akamai and Fastly at the moment.
If they are the same operator, because of the ClientHello permutation in Chromium based browsers[1] such as Edge, Cloudflare gets a high-entropy identifier + IP address, which, along with SNI header inspection, could be theoretically used to identify individual users.
[1] https://www.fastly.com/blog/a-first-look-at-chromes-tls-clie...
This doesn't necessarily require Cloudflare's cooperation. Remember when the NSA tapped Google's internal network without their knowledge? SSL added and removed here :-)
It did raise a fascinating question about where the physical tap was and how the take was routed back.
You do the tap at a hub, and you have the egress connectivity, but you're one unexpected employee away from discovery.
You do the tap in the middle of nowhere, and how do you get the data stream back?
I'd guess they went rural and just leased physically adjacent dark fiber to route out on.
> From a purely technical perspective this seems to be a slightly worse version of Apple Private Relay.
Private Relay is a well thought out design. Microsoft Edge Secure Network is merely a proxy because it is built for a different threat model: https://archive.is/pNnW5
> DPI at ISPs or Cloudflare isn't really what I'm concerned about
Well, ~50% content of the comment I replied to comprised of these "non-concerns".
As per your own source, a different permutation is used per connection, so it's unclear how it would help to "identify individual users".
Iff they're the same operator, I assume there'd be a TLS connection between Microsoft Edge Secure and the Edge browser, and that'd be a long-lived session because of the nature of proxying traffic, which means there's a static identifier. Even if it wasn't, IP addresses may themselves be considered as sensitive enough for such identification.
On the bright side, maybe they'll protect it with their "One more step...please wait while we verify your browser" system, which has such a high false positive rate (in my experience) that few people could actually access it.
Not only that, ISPs now close all connections which look like VPN traffic. I used to have my own OpenVPN server as a window to the free world and now it doesn't work... I wish there was some kind of open standard which doesn't leave a very obvious signature which is easy to detect by ISPs. I don't know if HTTP CONNECT can be hidden from ISPs? I guess I'm going to try Edge after all.
It's also been a while I've read about these topics, so I'm not sure if Russia also does entropy analysis and fingerprinting differences to block these protocols either.
You may like reading about the new TSPU system in Russia [1], and discussing your issues on [2].
[1] https://censoredplanet.org/tspu
[2] http://ntc.party
You can also co-exist OpenVPN on 443/tcp with a "real" web server. The usual use case for that is getting more value out of a single IP address. Put your pony fan club website up or an Ubuntu default webpage.
Another possibility is to use port knocking to open ports before the OVPN connects.
PPTP is generally believed to be broken so it might be "allowed" because it will be assumed that grabbing and storing the stream will be sufficient for later analysis. Then you put a OpenVPN inside the PPTP tunnel with proper, modern encryption.
... 53/tcp or udp might be worth trying too. 123/udp - ntp, 25/tcp - email! Basically try being weird - it may well work!
https://www.scientificamerican.com/article/russia-is-trying-...
https://www.cloudflare.com/application-services/products/chi...
Many CDNs set up a China specific network which customers can use it subject to presenting their recordal; that’s what Cloudflare China is.
Not blocking cloudflare China?
I'm not saying your concern isn't valid, it's a great point. Only that if anyone was going to run a company like Cloudflare, we're lucky it's Matthew, he's not a dumbass.
> In 2008, the Department of Homeland Security (DHS) contacted Unspam Technologies, asking, "Do you have any idea how valuable the data you have is?" The DHS' email served as the impetus for Cloudflare, a technology company Prince co-founded with Holloway and fellow Harvard Business School graduate Michelle Zatlyn the following year.
Which sounds like the opposite of what we would want. Cloudflare being started because a three letter agency told him that harvesting internet data is valuable. Unless his take away was “they do that too? Better try to stop it!”
Is there something else you’re referring to?
This may be totally true, but it's extremely important to understand that it does not matter.
As a US-based company Cloudflare is subject to NSLs (https://en.wikipedia.org/wiki/National_security_letter) which will force them to reveal all traffic and never talk about it. There's nothing they can do to resist that, regardless of founder personality.
Combine this with the fact that Cloudflare terminates TLS traffic, so it's all in the clear within their infrastructure. It would be difficult to think of a more juicy target for intelligence agencies waving NSLs.
It'll all be classified so we'll never know (unless some future Snowden tell us). But it is logical and wise to assume all traffic passing through Cloudflare is siphoned off in cleartext to the TLAs.
Egyptian ISPs used to hijack DNS for all reasons (and some are scary of course). They would ban port 443 to prevent people from using DoH if they could without technically cut Egypt out of internet.
So yes normally this is not something most of people here are not going to like. But as usual reminder, the world is much bigger than US and the western Europe.
Neat. On the other hand… I have to hand it to Cloudflare, they’ve done a great job turning themselves into the internet’s second backbone. (AWS might as well be the third backbone.)
It seems that decentralized systems always centralize over time when it comes to mindshare, and really don’t like decentralizing. Like, once the network effects begin even slightly, it becomes irreversible quickly. Linux is still not beating Windows and Mac. Mastodon’s numbers are still tiny compared to Twitter. Bitcoin hasn’t really hurt banks. The internet started out fairly decentralized, look at it now.
I’ve come to the conclusion that people just do not like decentralized anything, period. Which is unfortunate.
Yeah, you're absolutely right. Companies grow, and people talk about them, and get other people to try them, and they grow more, and more, until it becomes the "default" option that everyone knows, and they become entrenched by sheer power of their mindshare.
Especially in a global world where these brands become larger than life. There are brands with more global recognition and soft power than most countries out there.
Most people go with the defaults. That goes for software as much as companies. It doesn't matter how many decentralised options you have, because mindshare is what matters. Being the default in people's minds is what matters.
You need hosting? AWS. CDN? CloudFlare. Git? GitHub. Video? YouTube. And so on. There -are- options. But people aren't going to bother, when they can just... go with the default.
It's not about people not liking decentralisation, it's just much more mental effort to research and explore options when you can just go with the default.
It's only 5GB for free. Microsoft doesn't have a paid option yet so we'll have to wait and see what that costs.
I wish I had a lawyer friend that can advise in this. Do I just need to get a bunch if people to submit similar complaints somehow to FTC? Sue them directly? Email the DoJ? It's an active hostility I can't avoid, what are my options?
This seems strictly inferior to what Apple is doing with Private Relay where there are two separated hops, and given that I wonder what the Privacy Pass token is actually doing here.