I thought Cloudflare was just an HTTP forwarder, no?
When I connect to ProtonVPN via my OpenVPN client, it hits port 1194 (by default) on one of their worldwide servers. Itโs just a UDP connection, but I donโt think it passes through Cloudflare.
My HTTP request to a website then rides on top of that UDP connection. The website is hosted at Cloudflare, so Cloudflare will see the IP address of some Proton server in the Netherlands, letโs say, but how would Cloudflare be able pierce the veil and see my real IP in San Diego?
The bigger concern to me is that Proton sees the hostname of every site I visit since itโs the one part of the SSL (HTTPS) connection that isnโt encrypted.
They are far more than just http forwarding, it's data collection for DDoS primarily, but there are risks and issues. At the end of the day what does privacy even mean if a single provider sees so much. Regarding the IPs, here it's hitting them up on the initial client coordination, and then yes, it can tunnel direct without seeing CF. But there are risks of timing here.
Please see this article for in general the issues with CF:
https://simplifiedprivacy.com/why-and-what-is-arweb/arweave-website-creator.html
Thread collapsed