Cloudflare OHTTP gateway (blog.cloudflare.com)
simondotau 13 hours ago
Joker_vD 13 hours ago
9dev 9 hours ago
groomlake 9 hours ago
NSA's mission, as outlined in Executive Order 12333 in 1981, is to collect information that constitutes "foreign intelligence or counterintelligence" while not "acquiring information concerning the domestic activities of United States persons".
– WikipediaWhether they abide by that is another matter.
michaelt 8 hours ago
Joker_vD 7 hours ago
gigatexal 8 hours ago
arcanemachiner 4 hours ago
Also the NSA is a "signals intelligence" agency... Wouldn't the FBI be the local analog to the CIA? Or maybe the DHS?
bladeacidic 4 hours ago
Yaqub_W 10 hours ago
Another thing is the motivation to send people to work for CF. And another thing is the question of preparation vs hope.
Are you, by chance, an operative, sir? :)
simondotau 10 hours ago
nullbio 8 hours ago
simondotau 7 hours ago
brookst 8 hours ago
How is anyone worse off using their OHTTP gateway than not using it? Is the idea that CF is this spectacular conspiracy, but nobody thought of capturing traffic from backbones?
burdock 2 hours ago
When you capture traffic at internet backbones, which the NSA does (Room 641A), you don't get to middle-man the encrypted traffic. Cloudflare gets access to unencrypted traffic, because they act as the TLS termination.
Most companies take this trade-off because "we can trust cloudflare", or "the data isn't that important, and besides it's encrypted the rest of the way anyway."
phatfish 9 hours ago
ThatMedicIsASpy 8 hours ago
evulhotdog 7 hours ago
1a527dd5 6 hours ago
Five years later Mr Prince was doing a Master of Business Administration (MBA) at Harvard Business School, and the project was far from his mind, when he got an unexpected phone call from the US Department of Homeland Security asking him about the information he had gathered on attacks.
Mr Prince recalls: "They said 'do you have any idea how valuable the data you have is? Is there any way you would sell us that data?'.
Source: https://www.bbc.co.uk/news/business-37348016palata 5 hours ago
How is that exactly what you would expert from a covert government operation?
Do we agree that the design goes through two hops, only one of which is controlled by Cloudflare? And that it is the whole point of the design?
gruez 4 hours ago
Yeah I'm not sure what everyone's complaining about. The lack of criticism of anything specific about OHTTP makes me think it's just kneejerk "cloudflare = bad".
palata 25 minutes ago
I mean, sure. There is that against BigTech all the time, and I understand where it comes from.
What I don't get is that... I don't know, I feel like it should be possible to be against the fact that there are monopolies and criticise them on the one hand, and on the other hand to actually have technical discussions about technical solutions. Here it feels like many comments denigrate Cloudflare without even understanding what the OHTTP gateway does.
For example:
- "Google sucks, they just optimise for profit like all BigTech and that makes it worse for everybody" -> criticises a monopolist entity, all good. No need to be constructive here, it's just sharing a feeling.
- "Android's security model is soooo bad because Android is developed by Google, you should use Linux on mobile it's a lot more secure" -> criticises a technical solution (Android's security model) in a completely uninformed manner, not good.
In other words, BigTech companies "suck" by being BigTech companies, but they do hire brilliant engineers and develop nice stuff (when they don't develop technology to screw us, that is), and I think it would be worth acknowledging that. Cloudflare does contribute a lot of cool stuff open source. One doesn't have to like that Cloudflare is as big as it is, but that's not a reason to say that what they open source is bad software.
0x073 12 hours ago
But maybe I get privacy wrong.
someonebaggy 9 hours ago
ThatMedicIsASpy 7 hours ago
I have a feeling that privacy is easier to protect if you just mix what you want to hide with a lot of garbage.
krzyk 7 hours ago
jbverschoor 6 hours ago
johnhess 6 hours ago
You can imagine a lot of threat models where who you talk to isn't sensitive, nor is "someone talked to them about X" but knowing both facts is a risk.
thayne 4 hours ago
Although, that is still better than them having the source ip and the content.
charcircuit 2 hours ago
coldstartops 5 hours ago
nirui 12 hours ago
Wouldn't that be better if you design an oblivious encryption method so the encryption and decryption is handled by the origin server (a.k.a Target Resource in the RFC) and the Client? Instead of letting anyone in the middle to handle that data?
Their current design looked not that different than if you just connect to a public anonymous SOCKS5 server (which don't decrypt TLS traffic) and uses it to connect to a website hosted behind Cloudflare. It would probably work the same way too, since someone has to host a "OHTTP Relay" the same way they host a anonymous SOCKS5 server.
kccqzy 7 hours ago
scosman 8 hours ago
There’s also room for a privacy-centric analytics offering
ricardobeat 10 hours ago
AtNightWeCode 3 hours ago
Joker_vD 13 hours ago
someonebaggy 9 hours ago
lgeek 9 hours ago
CF seems to end up in the business of making problems worse, and selling the fix way too often. Before this, I had someone try to DDoS a webapp by setting up their own domain to proxy to my backend and running their attack traffic through CF. But that was easy, I could just block CF's IP range entirely as I don't use their reverse proxies.
jasomill 6 hours ago
esseph 24 minutes ago
If you work for an ISP you'll see it all the time. It's a constant fight to keep your subnet reputations high, which is hard when the subscribers don't care unless you shut off their service, but then your IP block still has a reputation issue to clean.
Joker_vD 8 hours ago
someonebaggy 7 hours ago
yencabulator 5 hours ago
arisudesu 2 hours ago
ZiiS 12 hours ago
palata 6 hours ago
shieldagent 7 hours ago
freedomben 7 hours ago
I love to see privacy improvement in tech. However I do wonder at this. Cloudflare is obviously a business and can't do everything for free, but charging extra for websites to add privacy Seems like a poor incentive if the goal is to improve privacy generally
tclancy 6 hours ago
jt2190 9 hours ago
Can someone expand on “burden” here? Scenarios that come to mind for me are something like: “I now need to ensure my log files are stored securely but that’s a PITA.” This doesn’t feel like the best example of why I’d use this though. (Edit: Secure messaging servers for a service like Signal?)
stogot 9 hours ago
9dev 9 hours ago
If your view on data protection or privacy is "I don't care about it, my users can go to hell as long as they pay"--then sure, this whole discussion probably seems pointless to you. But otherwise, storing and handling as little data as you can probably resonates with you as a good solution to many problems.
carlosjobim 8 hours ago
The above is also a good reason why you wouldn't want to get any of their data. Users who are not consumers are of no interest, and users who become customers will give the necessary data to make a purchase without any need to spy on them.
dokyun 15 hours ago
cpa 13 hours ago
You can google the sentence directly to find it.
BatchJob 2 hours ago
palata 18 minutes ago
The "privacy" it adds is that it separates your IP from your request, so no one actor on the way knows "X requested Y". A server knows "X requested something", another one knows "someone requested Y".
Maybe you don't need it, but I don't see how this is slightly creepy.
robertlagrant 9 hours ago
But that aside - surely this won't help for websites with Google tracking code embedded, which are the sorts of sites that track you anyway?
deknos 6 hours ago
palata 5 hours ago
maayank 4 hours ago
blantonl 8 hours ago
I respect customer privacy. But I also need to know who is abusing my platforms as well. The balance here is very difficult to manage, now that we have entire agentic platforms capable of deploying highly technical capable "abuse" platforms.
singpolyma3 11 hours ago
BiteCode_dev 2 hours ago
indeyets 15 hours ago
arshxyz 14 hours ago
Does Cloudflare's WAF (which relies on TLS Fingerprinting) stop working if OHTTP is enabled? If not, does this imply the client metadata is read and processed by Cloudflare but not passed on to the application server?
42droids 18 hours ago
chairmansteve 17 hours ago
- King Lear
pbhjpbhj 11 hours ago
LoganDark 10 hours ago
Like, bots are a huuuge problem but I am a huge believer in the case-by-case basis, and identity verification isn't a good default!
nc0 10 hours ago
wferrell 16 hours ago
dzink 18 hours ago
adlotsof 17 hours ago
therein 17 hours ago
roozbeh18 16 hours ago
est 15 hours ago
Same applies to Apple's Private Cloud Compute. A service provider has to join the program to avoid reading visitor's source IP.
It will handicap service provider's capability if I am not mistaken.