Proton uses Cloudflare

The VPN traffic, which sees your real home IP (and packet size and timing), flows through Cloudflare to Proton.

This is an undeniable conflict of interest, because the websites you're hiding from are also on Cloudflare.

In this epic meme slide show "article" with humor, we quickly present the critical facts you need to know,

https://simplifiedprivacy.com/proton-vpn-and-mail-use-cloudflare/outright-negligent-harm.html

If you care about freedom tech, please share my words. Because "giving a shit" is the only way things will ever change.

Reply to this note

Please Login to reply.

Discussion

Dammit..... I use Proton Suite.

I thought Cloudflare was just an HTTP forwarder, no?

When I connect to ProtonVPN via my OpenVPN client, it hits port 1194 (by default) on one of their worldwide servers. Itโ€™s just a UDP connection, but I donโ€™t think it passes through Cloudflare.

My HTTP request to a website then rides on top of that UDP connection. The website is hosted at Cloudflare, so Cloudflare will see the IP address of some Proton server in the Netherlands, letโ€™s say, but how would Cloudflare be able pierce the veil and see my real IP in San Diego?

The bigger concern to me is that Proton sees the hostname of every site I visit since itโ€™s the one part of the SSL (HTTPS) connection that isnโ€™t encrypted.

They are far more than just http forwarding, it's data collection for DDoS primarily, but there are risks and issues. At the end of the day what does privacy even mean if a single provider sees so much. Regarding the IPs, here it's hitting them up on the initial client coordination, and then yes, it can tunnel direct without seeing CF. But there are risks of timing here.

Please see this article for in general the issues with CF:

https://simplifiedprivacy.com/why-and-what-is-arweb/arweave-website-creator.html

It's no big deal. I use Proton VPN just for porn.

Stop using porn. It's bad for you.

#ireallybelievethis.

Itโ€™s amazing how easily triggered people are ๐Ÿ˜‚

I ran a couple IP address for US-based VPN servers (that you can use via wireguard) and they all came back with various ARIN-COGC Cogent Communications blocks. I hate Cloudflare as much as the next guy, but it doesn't appear that all of the US IP addresses they expose for wireguard connections are upstreamed by Cloudflare. Not that Cogent is likely any better but just wanted to point that out.

That's fair enough, thanks for your time, and each IP will vary. You definitely can go direct and avoid them. But you're connecting to them to get configs, logins, ect to setup these tunnels. Also added notes to the article to focus on email more.

Totally agreed. Just wanted to add some clarification to the details there, and that technically it's possible to connect directly is all.

This is despite the fact I use ControlD as my DNS of choice, and I'm already going through a VPN connection so Cloudflare doesn't see squat.

Proton, however, really should be using ControlD or Quad9, though.

I believe you have a fundamental misunderstanding of Cloudflare based on repeat comments I've seen. They are far beyond just DNS, but the websites themselves are pointed to them. Please review our educational materials, as it's not voluntary.

How A-record pointing works:

https://simplifiedprivacy.com/cloudflare/index.html

Fingerprinting:

https://simplifiedprivacy.com/browser-fingerprints/updated-every-5-minutes.html

In general on why CF is bad,

https://simplifiedprivacy.com/why-and-what-is-arweb/arweave-website-creator.html

@protonvpn, this true?

most people aren't aware that they're leaking traffic, even when using your own server/vpn. apple argument, "your clock wont work, if we route your entire traffic through your vpn". fucking joke.

Proton suck. Its a honey pot.

Is proton a honeypot? Has MLS encryption a backdoor?

I do not know if it's a honeypot. But I disagree with their decisions.

MLS can't say. has a lot of eyes on it tho

I kicked Proton to the curb after six years of being a paying customer because the froze my account for no apparent reason. Then they tried to bullshit me as to why it was done. Had they just said we fucked up and sorry, I would have been okay with that.

I'm now a tuta.com paying customer.

Hopefully, someday there will be a Nostr implementation supporting email.

Hopefully, someday Nostr will replace email

Yes I rather here the truth then some bullshit lie

the big issue is tuta doesn't do pgp. so self-host pgp to proton shares the network effect.

while proton to tuta is broken. ultimately self-host is the answer

I just gave up couple months ago and now use Cloudflare warp as my vpn

VPNs are mostly a scam, imo. They served a purpose, but mostly for corporations who actual network boundaries. Doesnโ€™t really work that way anymore.

I get into constant arguments with people in my fiat job about this. Theyโ€™ve been sold the maxim that VPN = secure for so long, they canโ€™t even reason about it in modern environments.

nostr:nevent1qqsr605swzpd669c8ds5jddu6zl5z825zr8t96dd62408w4jcfsyuggpndmhxue69uhkummn9ekx7mp0y5erqamnwvaz7tmwdaehgu3wd3skuep0y5erqffjxpshvct5v9ez2v3swaehxw309ahx7um5wgh8w6twv5hj2v3sy5erqctkv96xzu39xgc8wumn8ghj7ur4wfcxcetjv4kxz7fwvdhk6te9xgc8wumn8ghj7un9d3shjtnyv9kh2uewd9hj7ffjxpmhxue69uhhyetvv9ujuumwdae8gtnnda3kjctv9ugsclfc

GM๐Ÿ™‚๐Ÿค™

Does Proton use Cloudflare as their upstream provider?

If this is true, is Cloudflare able to associate the IP address of a Proton VPN user with the url that is accessed?๐Ÿง

๐ŸŽง๐Ÿซ–๐Ÿตโ˜บ๏ธ

The question was prompted by the following note:

nostr:nevent1qqsr605swzpd669c8ds5jddu6zl5z825zr8t96dd62408w4jcfsyuggpzamhxue69uhhyetvv9ujumn0wd68ytnzv9hxgtczyzkr76h7zavn7cvpq5fa4jdpu4zws7uuaydj05mm3rk937a2jq225qcyqqqqqqg966qhx

#FreedomTechFriday

No, nostr:npub1dd9znw7585wsam4d8p84ztdmtywwjsrayld6fzk4fvqdn5hpju4st5xe7p is literally a solution for this problem

Exactly!