103 pointsby est9 hours ago18 comments
  • simondotau3 hours ago
    I have absolutely no reason to think Cloudflare is a covert CIA operation. In fact, I’m sure there are plenty of good reasons to think it isn’t. But if it were, pretty much everything it does is exactly what you'd expect from one.
    • Joker_vD3 hours ago
      Of course it's not a CIA operation — that agency is foreign intelligence agency. The domestic intelligence agency is called NSA.
    • Yaqub_Wan hour ago
      The more people join in and become dependent on CF, the more incentive there is to subvert CF. Or am I being dumb?

      Another thing is the motivation to send people to work for CF. And another thing is the question of preparation vs hope.

      Are you, by chance, an operative, sir? :)

      • simondotau7 minutes ago
        I dare say that Cloudflare would represent excellent value for money to the intelligence agencies.
  • ricardobeat7 minutes ago
    So.. Cloudflare gets to keep access to private identifiers, while you willingly give it up to "protect privacy"? Piping all of that data into a massive central database instead of your nginx logs? How is this supposed to be better?
  • 0x0733 hours ago
    As cloudflare is the gateway for half the Internet and the other half is meta Google and Microsoft, I would prefer to share my IP with the website I visit instead some big tech companies.

    But maybe I get privacy wrong.

  • nirui3 hours ago
    > such that only the client and app server can see plaintext, and the relay sees only a jumble of ciphertext. A “gateway” sits between the relay and app server to handle all of this cryptography — decapsulating requests, encapsulating responses — and the app server handles only plain HTTP

    Wouldn't that be better if you design an oblivious encryption method so the encryption and decryption is handled by the origin server (a.k.a Target Resource in the RFC) and the Client? Instead of letting anyone in the middle to handle that data?

    Their current design looked not that different than if you just connect to a public anonymous SOCKS5 server (which don't decrypt TLS traffic) and uses it to connect to a website hosted behind Cloudflare. It would probably work the same way too, since someone has to host a "OHTTP Relay" the same way they host a anonymous SOCKS5 server.

  • ZiiS3 hours ago
    If I want to preserve the privacy of my users I will avoid using massive behavior capturing networks like Cloudflare. The is no world where giving them the tracking is better then just ensuring I anonymize my logs. If my users don't trust me; and are informed enough to understand what this service dose and doesn't cover they are just going to assume I can fingerprint them in some other way.
  • Joker_vD3 hours ago
    Hm. Interesting. I wonder how you would add "banning abusers by IP" functionality to it though — you first need to identify the abuse somehow and then link it to the originating IP (or any other kind of identifier)...
    • ricardobeat2 minutes ago
      Don't worry, they will handle that for you. They will also be kind enough to hold onto your keys and decrypt the incoming data, to make your life easier!
  • singpolyma3an hour ago
    If sharing your IP address with a website is a privacy concern we need to fix that problem, not hide the IP addresses
  • nc018 minutes ago
    Well played, CIA!
  • dokyun5 hours ago
    SSL added and removed here :-)
    • cpa4 hours ago
      To those missing it, it’s a reference to an internal NSA presentation that shown this sentence with an arrow at the boundary of google network and the internet.

      You can google the sentence directly to find it.

  • 6 hours ago
    undefined
  • arshxyz5 hours ago
    > a typical client-server exchange creates a trail of user data, like the client’s IP address or TLS fingerprint. This level of visibility can be a burden.

    Does Cloudflare's WAF (which relies on TLS Fingerprinting) stop working if OHTTP is enabled? If not, does this imply the client metadata is read and processed by Cloudflare but not passed on to the application server?

  • indeyets5 hours ago
    Has strong TOR (Onion Routing) feeling
  • 42droids8 hours ago
    Next step: ClInternet: the World Wide Web by Cloudflare. :)
    • LoganDark4 minutes ago
      They're already sort of inventing this by making the choice for everyone to block non-registered bots by default. (calling them "AI Training bots")

      Like, bots are a huuuge problem but I am a huge believer in the case-by-case basis, and identity verification isn't a good default!

    • chairmansteve7 hours ago
      "Jesters do oft prove prophets".

      - King Lear

      • pbhjpbhjan hour ago
        "Ful ofte in game a sooth I have herd saye!" (Chaucer, The Cook's Tale)
  • dzink8 hours ago
    The irony is that the majority of people that need this don’t have the cognitive time or skill to process and set it up for themselves. But the agents and bad actors like North Korean hackers would absolutely have the time and ability to implement and use it. Then you have the market for lemons problem - if requests coming from here are malicious most requests coming from here will be seen as malicious. Aka dark alleys earn their reputation over time.
    • adlotsof8 hours ago
      Not sure how north korean hackers benefit from not knowing who is accessing their servers?
    • roozbeh187 hours ago
      We have Cloudflare Tunnels to thank for this. I wish Cloudflare did more to stop malicious use of Cloudflare Tunnels.
    • est6 hours ago
      I thought ohttp is opt-in. You have to participate their beta to enable the relay/gateway.

      Same applies to Apple's Private Cloud Compute. A service provider has to join the program to avoid reading visitor's source IP.

      It will handicap service provider's capability if I am not mistaken.

    • therein7 hours ago
      I think you misunderstand. This is for inbound traffic, not outbound.
  • ranger_danger7 hours ago
    Does any current proxy/tunnel/VPN software support OHTTP as a transport method?

    What about browsers making general website requests to services that support it?

    • jon-wood4 hours ago
      iCloud Private Relay (available on every macOS and iOS device in recent years) uses OHTTP to obscure your identity from sites you visit.
  • Naru417 hours ago
    Pathetically, people probably won't even erase cookie, let alone JavaScript. To begin with, any websites are not designed to be viewable without js. There are countless ways to find fingerprints. It is impossible to prevent tracking anyway in current the internet.
    • jon-wood4 hours ago
      It’s entirely possible if the application developers have made the choice to intentionally avoid tracking and tying personal data to user identity, which is exactly who this product is aimed at.
  • theclaireellisan hour ago
    [flagged]
  • wferrell7 hours ago
    Self Service Relay https://oblivious.network/