Cloudflare OHTTP gateway
Article URL: https://blog.cloudflare.com/announcing-cloudflare-ohttp-gateway/ Comments URL: https://news.ycombinator.com/item?id=49941091 Points: 183 # Comments: 89
Today, end users bear the brunt of the responsibility for online privacy. To circumvent tracking or targeted advertisements, users are advised to employ VPNs, disable cookies, or install adblockers. However, certain app developers acquire excessive knowledge about their users. A conventional client-server interaction generates a trail of user data, such as the client's IP address or TLS fingerprint.
This level of exposure can be burdensome. Thus, Cloudflare develops infrastructure to help developers embed privacy into their applications. Oblivious HTTP (OHTTP) is an IETF standard enabling app backends to receive HTTP requests without detecting user IP addresses. This autumn, Cloudflare will introduce the Cloudflare OHTTP Gateway.
Users can activate the new OHTTP Gateway as a paid add-on to their zone and begin receiving OHTTP traffic with minimal effort. To join the waitlist, submit a registration through our form. Delve deeper to discover more. OHTTP comprises two independent hops: a relay and a gateway. An OHTTP relay transmits encrypted requests unaltered to conceal client identifiers from app servers.
An OHTTP gateway executes the cryptographic tasks of decapsulating encrypted requests and encapsulating responses, allowing app servers to process OHTTP requests as if they were standard HTTP. The division of trust between relay and gateway is crucial: it guarantees that no single entity perceives both client identifiers and request contents.
In 2022, Cloudflare launched an OHTTP relay product, Privacy Gateway. Privacy Gateway empowers customers to offer heightened privacy-preserving experiences to their users. For instance, Flo Health utilizes OHTTP for their app's Anonymous Mode, and Apple's Private Cloud Compute employs OHTTP to dissociate AI inference requests from user identities.
Nonetheless, customers who already safeguard their servers via Cloudflare cannot simultaneously utilize a Cloudflare-operated relay — they require an OHTTP gateway instead. Having operated OHTTP relays, Cloudflare has observed the intricacy of constructing and managing a secure, high-performing OHTTP gateway at scale. Presently, they are launching the closed beta for the self-service Cloudflare OHTTP Gateway.
They are also renaming their "Privacy Gateway" to "Cloudflare OHTTP Relay" to differentiate the two products. Now, customers seeking an OHTTP architecture with the requisite trust separation have two alternatives: Cloudflare is striving to elevate privacy standards across the Internet, and they believe that protocols like OHTTP can facilitate this if they are user-friendly enough.
Since launching their OHTTP Relay product, Cloudflare has noted several observations. Firstly, there is a rising demand among developers for accessible, functional privacy infrastructure. Developers of privacy-focused apps desire to embed network privacy into their applications by default, yet doing so remains more challenging than it should be.
Secondly, they have realized that constructing and operating an OHTTP gateway can be challenging for customers. Any proxying architecture introduces latency due to requests traversing additional hops around the globe. Factor in the expense to decrypt requests and encrypt responses, and the latency penalty for a homemade OHTTP setup can be substantial.
Cloudflare is well-equipped to address this issue: the foundational elements that enable them to deliver swift, reliable privacy infrastructure for products like 1.1.1.1 and iCloud Private Relay position them well to provide an OHTTP gateway. Due to Cloudflare's anycast strategy, their OHTTP Gateway will operate on every server across Cloudflare's global edge network, reducing latency in relay-to-gateway hops.
If you utilize their CDN, user requests can be decrypted by the Gateway and resolved by your app servers on the same Cloudflare hardware, minimizing gateway-to-origin latency. Lastly, recall that OHTTP's privacy model necessitates that the relay and app server be operated by separate, non-cooperating parties. Cloudflare aims to provide customers with the optimal range of options for their privacy infrastructure.
Previously, developers who protected their app servers behind Cloudflare could not employ Cloudflare's OHTTP Relay, as Cloudflare would see both client metadata and the decrypted request contents, violating OHTTP's privacy model. Now, developers can determine whether a Cloudflare OHTTP Relay or Gateway is more suitable for their architecture.
Written by urgent.news from Hacker News Best's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Cloudflare Ohttp Gateway blog.cloudflare.com