11 ms·
Cloudflare Calls
- teddyh 4y agoAnother “Let’s make Cloudflare the central server of the Internet” service, from what I can see.
- deleted 4y ago[deleted]
- dewey 4y agoI'm really getting tired of this kind of take. You never really see that if AWS adds a product, or GCP adds a product or any other products from bigger CDNs. What do you suggest? Cloudflare should stop releasing products? Regulation that you are only allowed to handle x% of the total internet traffic?
- danwee 4y ago> What do you suggest? Cloudflare should stop releasing products? Regulation that you are only allowed to handle x% of the total internet traffic? Regulation sounds about right. Monopolies are regulated in the real world, so why don't we do the same in the virtual one?
- endisneigh 4y agoYou do see plenty of complaining about Amazon and Google, and yes, [some] people on here are very much pro regulation.
- teddyh 4y ago> You never really see that if AWS adds a product, or GCP adds a product or any other products from bigger CDNs. Accusations of hypocrisy is not an argument. Instead of accusing me (and all other detractors) of not criticizing others enough, please elaborate why this isn’t what I described. Cloudflare (and others) keep releasing products which makes their central role more central and less vulnerable to competition. They ought not to do that, and I would argue for laws which prevent them from doing that if necessary. Regarding the problem, this kind of problem should not be solved by one central actor. Instead, these problems should be solved by new network and protocol designs.
- onion2k 4y agoplease elaborate why this isn’t what I described Approximately 1/3 of the most popular websites use Cloudflare[1]. That's not really an argument against the fact that Cloudflare might want to be 'the central server of the internet', but it's a suggestion that they have some way to go yet. I'd bet that Google Tag Manager and some AWS services are integrated into more than 1/3. [1] From https://backlinko.com/cloudflare-users https://backlinko.com/cloudflare-users
- teddyh 4y agoWhat, “They’re not an empire, they only rule ⅓ of the Earth’s surface!”? Or “Cloudflare cannot possibly be taking advantage of their market share, since they have competition!”?
- jraph 4y agoGoogle Tag Manager can be down without affecting websites uptime and as a visitor I can block them. I do block them, by the way. So, it's quite central, but at least not really a point of failure. AWS and Cloudflare, on the contrary… (and also Google products like fonts.googleapi.com, or probably anything under googleapi.com)
- gautamdivgi 4y agoThat’s too much government control for my liking. Just being honest. Laws that prevent free enterprise never end well. There should be laws that prevent companies from selling a product at a “loss” to gain market share. But to prevent companies from releasing products is completely different level of control which is undesirable.
- jnwatson 4y agoFrom that line of argument, we should really get folks off Linux. And nginx.
- teddyh 4y agoIs Linux a central actor? No, it’s not; any people could continue development at any time if the current people stop developing it. Also, the comparison is flawed, since neither Linux nor Nginx are network services.
- corytheboyd 4y agoI agree, this rhetoric is getting old. So we're supposed to go use one of thousands of other tiny cloud platform providers? Okay let's entertain that idea. The first bare minimum items on your vendor approval checklist are things like "can I trust this business to exist in 10 years" , "do they have enough resources to support me when shit hits the fan", and "are they mature enough to deliver on the shiny bullet points on their homepage and in their sales pitch". Isn't this process going to naturally select a small handful of providers? What am I missing here?
- endisneigh 4y ago> Isn't this process going to naturally select a small handful of providers? What am I missing here? No. It's possible to not do a lot and still last a very long time. Consider zippers, YKK has existed for almost a century and they only manufacture zippers.
- corytheboyd 4y agoI know you know this but there is quite the difference between a multi-faceted cloud compute offering and the thing that holds my hoodie together.
- endisneigh 4y agoThe point is that it's possible for a company to focus on one thing for a long time. Do you dispute this?
- corytheboyd 4y agoI am, surprisingly, capable of understanding that companies can exist for long periods of time. Time to walk away lol
- endisneigh 4y agoIf you understand that then I don't know why you posted your original comment. It isn't true in theory nor in practice. cya, lol
- larvaetron 4y ago> I'm really getting tired of this kind of take. I'm really getting tired of this kind of hand-wavey response.
- viraptor 4y agoThey're a bit different from AWS. First, they have less competition. Like, competition exists, but they really dominate the market and are the only ones onboarding serious traffic for free loss leader accounts. Second, for all their "we're neutral" talk, they regulate a lot of online traffic in a way that AWS never did. AWS cloudfront shield will not cut you off from majority of the popular internet without recourse just because you accidentally tripped some rule. So yeah, not being able to handle more than x% of the internet traffic (unless they're running a real dumb pipe with only IP routing logic) sounds great. I'd welcome anther Bell systems breakup.
- bogomipz 4y ago>"I'm really getting tired of this kind of take." Which take is that? An opinion or outlook that differs from your own? >"You never really see that if AWS adds a product, or GCP adds a product or any other products from bigger CDNs." Sure, you do. When AWS released it's DocumentDB(MongoDB competitor) and "Open Distro for Elasticsearch" there was plenty of uproar, both form the companies behind these products as well as the community. Those concerns were also registered on HN.
- snarf21 4y agoUnlike Google or Amazon? What happens when there is an outage on either of those? I think it is great that there is more competition in the space writ large.
- teddyh 4y agoNo, not unlike, but exactly like Google and Amazon. I don’t actually think there should be competition in the space of “being a central point of everything” – there should be no such thing as the central company for everything.
- corytheboyd 4y agoThis sounds badass to be honest. Having written some WebRTC browser applications from scratch, that architecture turns into a complicated mess real fast, I can only imagine the nightmare that becomes at less than well equipped tech startups. This sounds like the right way to actually solve the problem.
- jgrahamc 4y agoDammit. We should have made the internal code name for this BADA55.
- corytheboyd 4y agoHaha you can keep that one in your back pocket :)
- jgrahamc 4y agoThank you. D2BA DA55.
- tommoor 4y agoI suppose this would be mostly a direct competitor to Twilio's solution that's a few years old now: https://www.twilio.com/webrtc https://www.twilio.com/webrtc
- kwindla 4y agoOther long-standing direct competitors include Vonage, who acquired the original WebRTC platform-as-a-service, OpenTok; AWS Chime Video; and Daily (YC W16). https://www.vonage.com/communications-apis/video/ https://www.vonage.com/communications-apis/video/ https://aws.amazon.com/chime/chime-sdk/ https://aws.amazon.com/chime/chime-sdk/ https://www.daily.co/ https://www.daily.co/
- rixthefox 4y agoThey really do want to be the center of everything it seems. I wish they would stop trying to be the Cisco of Networking in the sense of trying to convince a lot of people to let them handle critical network functions for a ton of networks. All it will take is one major outage for everyone to see this is a bad idea. Why trust a cloud provider who could go down and take half the Internet with it? Why centralize it that much where that is even possible?
- seeekr 4y agoThey just keep building on top of the things they've already built that are working really well, expanding into related services. Doesn't seem that different from what AWS is doing, just with a different focus and in a different place in everyone's (or the Internet's) stack.
- yamtaddle 4y agoThe focus on a different place in the stack is really, really key, though. It's what's letting them make the kind of "the whole Internet's middle-man" play that they are.
- hn_go_brrrrr 4y agoAWS is going for "the internet's backend". I don't see how that's any different. A SPOF is still a problem, no matter where in your stack it lives.
- yamtaddle 4y agoThey're positioned to have much wider reach than even AWS. You probably wouldn't put AWS in front of GCP or Azure. You might put CloudFlare in front of any of those. And once you've done that, well, they offer these other services that compete with the backend you're already using.... Their position in the stack has a great deal of market relevance, which translates to risk if they realize that potential, because they could well end up being a critical part of more of the Internet than AWS is.
- Xeoncross 4y ago> "With a traditional WebRTC implementation, both the patient and therapist’s devices would talk directly with each other, leading to exposure of potentially sensitive data such as the IP address... When using Calls, you are still using WebRTC, but the individual participants are connecting to the Cloudflare network. If four people are on a video call powered by Cloudflare Calls, each of the four participants' devices will be talking only with the Cloudflare network. To your end users, the experience will feel just like a peer-to-peer call, only with added security and privacy upside. Can someone clarify this? WebRTC is encrypted generally even if you leak metadata like IP address. Is Cloudflare stating they will be the middleman and therefore have access to the decrypted video stream?
- lnsp 4y agoAs far as I understood it: the premise of added security is based on the fact that the other WebRTC peers only see Cloudflare's IP instead of your own. Also nobody knows who you are exactly talking to except Cloudflare. I would still expect that the media channels itself still remain encrypted when even when multiplexed by Cloudflare's network. edit, yes it's encrypted: > Finally, all video and audio traffic that passes through Cloudflare Calls is encrypted by default. Calls leverages existing Cloudflare products including Argo to route the video and audio content in a secure and efficient manner.
- treis 4y agoIt doesn't say that Cloudflare can't or doesn't access the encrypted data. It seems to be written in a way that everyone would assume they can't but AFAICT it doesn't explicitly say it. Which makes me think they phrased it like this for a reason but I definitely could be wrong.
- nine_k 4y ago"If you don't trust each other, trust us": a very understandable value proposition. Also very understandable trade-offs.
- ranger_danger 4y ago
- endisneigh 4y agoHow much will this cost after the beta?
- gizmo 4y agoThis basically turns phone/video chat into a feature. If this actually works with 10.000 people in a room as advertised Zoom is in a lot of trouble.
- intrasight 4y agoZoom is an app. This is an API for building apps.
- yencabulator 4y ago... that makes creating Zoom competitors much easier.
- mjreacher 4y agoI for one think this could be a very useful idea for my use case (education) and am looking forward to see how it turns out.
- throwaway99797 4y agoGoogle missed their opportunity to do this: they've had Google Meet / Hangouts / ... for years. They have the same backend infrastructure that can scale to thousands and low latency to everywhere. Meet already does this with a custom Google protocol in the browser. If Google had just opened their APIs, they could have provided this to everyone...
- mcpeepants 4y agoDon't forget about Google Fi (which, it seems sometimes, that _Google_ has forgotten about) which ties it all together with traditional carrier services too. Well it did until they sunset Hangouts, I suppose.
- brightball 4y agoI've been wondering when CF was going to build this for years. It only made sense given the moving parts in WebRTC.
- mwcampbell 4y agoWas hoping they'd release a stand-alone TURN service first. The WebRTC-based product I've been working on for months now (finally wrapping up v1) is one-to-one by nature, and I actually want the connection to be peer-to-peer when possible. But access to a TURN server in every Cloudflare datacenter would be nice.
- barake 4y agoTalk to your account rep, think they can help you out with that
- leihca 4y agoWe did! [1] It's currently in beta, if you're interested feel free to drop me a line at achiel [at] cloudflare.com [1] https://blog.cloudflare.com/announcing-our-real-time-communications-platform/ https://blog.cloudflare.com/announcing-our-real-time-communi...
- pwpwp 4y agoDoes this support RTC data channels, too, or just A/V?
- shiomiru 4y agoI'm having trouble understanding how giving this metadata to a centralized entity makes the transaction more "private". In the example, now instead of sharing my IP with a therapist, (who I presumably trust enough to... not ddos me?), I'm sharing the fact that I was talking to a therapist with a company I possibly didn't even know existed. Better yet, I suppose I can now be barred from accessing webrtc services if said company decides I'm a "threat" based on all the metadata they've been collecting through their other services.
- ghhgfghfghfhf 4y agoThis comment asks all the right questions! This allows CF to construct a person graph, which is the only power Facebook have in the advertising business. ;) This will also allow CF to police WebRTC and block people out, like they already do for the rest of the internet. Get ready to answer webRTC captcha(TM) on every call if you use linux or such.
- bryfb 4y agoI'm so tired of this FUD cloudflare throws around. So far, I don't see a single cloudflare product that solves the purported problem without introducing three others that they conveniently don't talk about. And when the inevitable curation / editorial / policing challenge of running half the internet does knock on their doorstep, they go "well we're not the ones who are supposed to be policing it, but what are you gonna do?!"
- skybrian 4y agoThis infrastructure isn’t needed for two person conversations. What you’ve missing is that in a group situation, you’re not just trusting the group leader, but everyone in the call. The larger the group and the lower the barriers to entry, the worse it is. That said, I’m not sure that leaking an IP address is a big deal for most people. (It might be important in Ukraine, though.)
- gnfargbl 4y agoI wonder if there's a way to integrate this with https://snowflake.torproject.org/ https://snowflake.torproject.org/, such that blocking Tor would require also blocking all of Cloudflare?
- dannyw 4y agoWhy did Cloudflare say "encryption" but not "end-to-end encryption"? Should we be reading deeper into this?
- kwindla 4y agoShort answer: it's not currently possible to do true end-to-end encryption through media servers with a key that is inaccessible from user space. Longer answer... WebRTC was designed as a fundamentally peer-to-peer protocol. The spec defines (and basically mandates) the use of end-to-end encryption. Which is great! Among other things, this means that browsers can implement e2e in a standardized and provably secure way. On top of WebRTC's fundamental peer-to-peer-ishness, you can build an architecture to forward or process media and data streams through media servers. This is what Cloudflare has done, and what every major WebRTC platform/project does in order to scale up participant counts, improve performance by moving routing closer to the network edge, and implement things like recording. But there's no support (yet) in the WebRTC spec for encrypting media streams so that they can be handled and routed by a media server without decrypting them. There's ongoing work on this. Here's a nice blog post covering how the early working group effort was being organized: callstats.io/blog/2018/06/01/examining-srtp-double-encryption-procedures-for-selective-forwarding-perc
- computerfriend 4y agoThank you for this long answer. Actually, I have always wondered why it isn't possible to treat the stream as arbitrary data, so it can be encrypted and decrypted in "userspace". Something like how Firefox Send works, with a key as a URL fragment. E2EE with intermediate forwarding peers unable to decrypt the contents.
- rasz 4y agoOther than giving cf your encryption keys to https traffic, your eSIM Ki and now your unencrypted voice calls? Noooo.
- rasz 4y agoTLDR: Remember how Skype allowed you to talk directly with one another without pesky servers and middle men positioned to intercept calls and metadata? Remember CALEA (Communications Assistance for Law Enforcement Act to allow wiretapping on digital phone networks)? Remember how Microsoft scrambled to dismantle peer-to-peer infrastructure and switch Skype to a typical server model while simultaneously joining PRISM program? Wouldnt you want to do the same with WebRTC? Why trust your doctor when you can trust Us instead! >"With a traditional WebRTC implementation, both the patient and therapist’s devices would talk directly with each other, leading to exposure of potentially sensitive data such as the IP address... When using Calls, you are still using WebRTC, but the individual participants are connecting to the Cloudflare network
- tschellenbach 4y agoThis is the same approach that getstream.io (disclaimer, my startup) and agora.io take for video calling. A global edge network with support for SFU cascading is optimal for the call quality.
- kwindla 4y agoThe Cloudflare Calls launch post is really well written! But I agree that it perhaps somewhat overstates the uniqueness of their approach, given that Agora, Jitsi-as-a-Service, Stream, and Daily all offer WebRTC platforms with a mesh/cascading SFU architecture. Relatedly, I didn't know that Stream had launched SFU cascading. That's awesome! I'd love to compare notes sometime if you're up for it. (I'm a co-founder of Daily.)
- tschellenbach 4y agoThat sounds fun, @tschellenbach on twitter or the email in my profile
- kwindla 4y agoI'd love to know more about > Calls uses anycast for every connection, so every packet is always routed to the closest Cloudflare location. Is this true for the UDP media (and data channels) traffic, or just for the initial signaling and connection setup? If the UDP traffic is all anycast, that's truly impressive engineering work. Bravo!
- mmastrac 4y agoIs anycast "just" (!) broadcasting different routes for different parts of the internet for the same IP address? I cannot imagine this is trivial to get right at all.
- kwindla 4y agoDefinitely non-trivial! Deep BGP expertise is required to operate anycast at any significant scale. And RTP/WebRTC media traffic is perhaps particularly tricky, because UDP is so stateless but media servers need to maintain a relatively large amount of state for each "connection."
- davidz 4y agoSpeculating here, but I would read this as "anycast" as a concept, where each user is connected to the closest location. versus anycast as in the IP protocol. The complexity far outweighs benefits with routing each UDP packet to different servers within the same session.
- yencabulator 4y agoCloudflare uses Anycast for the TCP connections they terminate. See e.g. https://blog.cloudflare.com/magic-transit-network-functions/ https://blog.cloudflare.com/magic-transit-network-functions/ or ponder DNS-over-HTTPS to 1.1.1.1 I don't think they've talked much about what happens if the connections gets routed to a different PoP mid-stream.
- dincer 4y agoI work on the team that works on Calls. Thank you for the kind words. It is true, both media and signaling is over anycast and advertised from every Cloudflare location. We manage things like ICE and DTLS state in a distributed way. Super happy to be part of the super talented team that made this happen!
- throwaway787544 4y ago
- lminiero 4y agoAs the main author of Janus, I didn't appreciate at all them proactively suggesting Calls as a replacement for existing deployments based on Janus and mediasoup. I'd understand them aggressively marketing against other RTC cloud providers like Agora, Twilio, and others: trying to "steal" users from open source projects (who share everything and so often live on consulting) really feels like a d*ck move, instead, and basically stealing candy from kids.
- deeblering4 4y ago> Remote 'fireside chats' where one or multiple people can have a video call with an audience of 10,000+ people in real time (<100ms delay) I keep hearing this term 'fireside chat' used like this, and ever time there's no actual fire and it's not intimate (10k viewers?). What is it supposed to mean?
- transientbug 4y agoI believe it's a reference to President Roosevelt's ["Fireside chats"](https://en.wikipedia.org/wiki/Fireside_chats https://en.wikipedia.org/wiki/Fireside_chats) radio addresses during the 30's-40's
- yencabulator 4y agoIt's just a hipsterism for "interview of a CxO".