logoalt Hacker News

Cloudflare OHTTP gateway

182 points • by est • today at 3:15 AM • 86 comments • view on HN

Comments

simondotau • today at 9:11 AM

I have absolutely no reason to think Cloudflare is a covert CIA operation. In fact, I’m sure there are plenty of good reasons to think it isn’t. But if it were, pretty much everything it does is exactly what you'd expect from one.

➕ show 4 replies
0x073 • today at 9:56 AM

As cloudflare is the gateway for half the Internet and the other half is meta Google and Microsoft, I would prefer to share my IP with the website I visit instead some big tech companies.

But maybe I get privacy wrong.

➕ show 2 replies
coldstartops • today at 4:46 PM

I was at Thibault's talk when he explained the OHTTP this summer, for those interested: https://passthesalt.ubicast.tv/videos/2026-oblivious-http-wh...

nirui • today at 9:56 AM

> such that only the client and app server can see plaintext, and the relay sees only a jumble of ciphertext. A “gateway” sits between the relay and app server to handle all of this cryptography — decapsulating requests, encapsulating responses — and the app server handles only plain HTTP

Wouldn't that be better if you design an oblivious encryption method so the encryption and decryption is handled by the origin server (a.k.a Target Resource in the RFC) and the Client? Instead of letting anyone in the middle to handle that data?

Their current design looked not that different than if you just connect to a public anonymous SOCKS5 server (which don't decrypt TLS traffic) and uses it to connect to a website hosted behind Cloudflare. It would probably work the same way too, since someone has to host a "OHTTP Relay" the same way they host a anonymous SOCKS5 server.

scosman • today at 2:11 PM

I’ve wanted this for a while. I make private desktop software for transcribing meetings. It’s essentially offline, but things like checking for updates require the network. I looked at ohttp but it was still private, and ended up pinging GitHub releases directly.

There’s also room for a privacy-centric analytics offering

https://github.com/scosman/Biscotti

ricardobeat • today at 12:27 PM

So.. they continue having access to private identifiers, while you willingly give it up to "protect privacy"? Piping all of that data into a massive central database instead of your nginx logs? How is this supposed to be better?

Joker_vD • today at 9:07 AM

Hm. Interesting. I wonder how you would add "banning abusers by IP" functionality to it though — you first need to identify the abuse somehow and then link it to the originating IP (or any other kind of identifier)...

➕ show 2 replies
GalaxyNova • today at 10:04 PM

Cloudflare is like the systemd of the internet

ZiiS • today at 10:00 AM

If I want to preserve the privacy of my users I will avoid using massive behavior capturing networks like Cloudflare. The is no world where giving them the tracking is better then just ensuring I anonymize my logs. If my users don't trust me; and are informed enough to understand what this service dose and doesn't cover they are just going to assume I can fingerprint them in some other way.

arisudesu • today at 8:05 PM

Lots of words about how site owners can enable this "thing". But is it true that they can toggle it off at any moment? How as a visitor can I know in advance, whether OHTTP is enabled for my request and prevent making it, if OHTTP is not available?

shieldagent • today at 2:53 PM

OHTTP is a neat split: the relay learns who you are, the gateway learns what you ask, and neither gets both.

freedomben • today at 2:52 PM

> Customers will be able to enable our new OHTTP Gateway as a paid add-on to their zone and start receiving OHTTP traffic with just a few clicks.

I love to see privacy improvement in tech. However I do wonder at this. Cloudflare is obviously a business and can't do everything for free, but charging extra for websites to add privacy Seems like a poor incentive if the goal is to improve privacy generally

jt2190 • today at 12:53 PM

> Meanwhile, some app developers end up knowing more about their users than they’d care to: a typical client-server exchange creates a trail of user data, like the client’s IP address or TLS fingerprint. This level of visibility can be a burden.

Can someone expand on “burden” here? Scenarios that come to mind for me are something like: “I now need to ensure my log files are stored securely but that’s a PITA.” This doesn’t feel like the best example of why I’d use this though. (Edit: Secure messaging servers for a service like Signal?)

➕ show 2 replies
dokyun • today at 7:08 AM

SSL added and removed here :-)

➕ show 1 reply
robertlagrant • today at 1:03 PM

This is slightly worse than Cloudflare's usual excellent writing.

But that aside - surely this won't help for websites with Google tracking code embedded, which are the sorts of sites that track you anyway?

BatchJob • today at 8:00 PM

Im at a loss as to what I or anyone else would actually use this for. But it is slightly creepy. Ill give it that.

➕ show 1 reply
deknos • today at 4:18 PM

how can i run this for my friends and me selfhosted? is there a ohttp server?

➕ show 2 replies
blantonl • today at 2:08 PM

I'm seeing more and more organizations that I neither can identify nor pin down now using more and more cloudflare privacy offerings to "hide" their intentions.

I respect customer privacy. But I also need to know who is abusing my platforms as well. The balance here is very difficult to manage, now that we have entire agentic platforms capable of deploying highly technical capable "abuse" platforms.

singpolyma3 • today at 11:26 AM

If sharing your IP address with a website is a privacy concern we need to fix that problem, not hide the IP addresses

➕ show 1 reply
BiteCode_dev • today at 7:57 PM

Bots are going to love this.

indeyets • today at 7:27 AM

Has strong TOR (Onion Routing) feeling

arshxyz • today at 7:41 AM

> a typical client-server exchange creates a trail of user data, like the client’s IP address or TLS fingerprint. This level of visibility can be a burden.

Does Cloudflare's WAF (which relies on TLS Fingerprinting) stop working if OHTTP is enabled? If not, does this imply the client metadata is read and processed by Cloudflare but not passed on to the application server?

42droids • today at 4:27 AM

Next step: ClInternet: the World Wide Web by Cloudflare. :)

➕ show 2 replies
wferrell • today at 5:37 AM

Self Service Relay https://oblivious.network/

nc0 • today at 12:16 PM

Well played, CIA!

dzink • today at 4:28 AM

The irony is that the majority of people that need this don’t have the cognitive time or skill to process and set it up for themselves. But the agents and bad actors like North Korean hackers would absolutely have the time and ability to implement and use it. Then you have the market for lemons problem - if requests coming from here are malicious most requests coming from here will be seen as malicious. Aka dark alleys earn their reputation over time.

➕ show 4 replies
mococa • today at 1:43 PM

They really want to be MITM

ranger_danger • today at 5:30 AM

Does any current proxy/tunnel/VPN software support OHTTP as a transport method?

What about browsers making general website requests to services that support it?

➕ show 1 reply
Naru41 • today at 5:04 AM

Pathetically, people probably won't even erase cookie, let alone JavaScript. To begin with, any websites are not designed to be viewable without js. There are countless ways to find fingerprints. It is impossible to prevent tracking anyway in current the internet.

➕ show 1 reply
theclaireellis • today at 11:27 AM

[flagged]