693 points jcbhmr 18 hours ago 275 comments
user3939382 17 hours ago | parent
dangoodmanUT 17 hours ago | parent
ThrowawayTestr 17 hours ago | parent
cuu508 17 hours ago | parent
monster_truck 16 hours ago | parent
johng 16 hours ago | parent
cuu508 15 hours ago | parent
- find my approximate physical location
- regularly scan ports on my IP and wait for me to accidentally expose a service I didn't mean to
- track me in any access logs they have access to
mitxela 8 hours ago | parent
kincl 17 hours ago | parent
edit: yeah, it says no account creation, neat!
alasano 16 hours ago | parent
Tepix 16 hours ago | parent
athrowaway3z 14 hours ago | parent
spwa4 14 hours ago | parent
So cloudflare sees your plaintext. Btw: tailscale does not (but ssl errors and warnings are unavoidable)
ZeroCool2u 17 hours ago | parent
aniviacat 17 hours ago | parent
bakugo 17 hours ago | parent
roncesvalles 17 hours ago | parent
berofeev 16 hours ago | parent
My initial thought was desktops generally run 24/7, with laptops running when in use. At least for the customer at the market intersection for this type of product.
JavierFlores09 16 hours ago | parent
seabrookmx 13 hours ago | parent
roncesvalles 16 hours ago | parent
SoftTalker 15 hours ago | parent
sophacles 16 hours ago | parent
cmacleod4 14 hours ago | parent
danserfaty 16 hours ago | parent
aliasxneo 17 hours ago | parent
afzalive 16 hours ago | parent
simonw 16 hours ago | parent
I bet these new tunnels end up being a fraction of a percentage point of their network traffic.
aliasxneo 16 hours ago | parent
simonw 15 hours ago | parent
swozey 15 hours ago | parent
I've migrated many companies off of cloudflare, usually because they end up pissing off companies when a contract renewal comes up and they slam them with massively increased bills and almost useless support if you aren't very high paying enterprise. I don't know how many CF support tickets I've just given up on over the last 15 years, usually related to their admin page, workers or some weird thing their system does that wasn't documented and I just stop getting responses and definitely don't get fixes.
If you ever worked in webhosting the Cloudflare wordpress/etc extensions are everywhere and back when I did work in hosting tons of support tickets were made because of CF. Could be way better now, I don't go near that industry these days.
The casual CF user sticking it in front of a blog they rarely look at and the business forced CF user has a very different experience. I cringe and seriously consider if I'm interviewing for an infra role and they use cloudflare. Usually it's startups that grew into larger businesses.
eli 16 hours ago | parent
bix6 16 hours ago | parent
robertlagrant 11 hours ago | parent
mitxela 9 hours ago | parent
ceejayoz 16 hours ago | parent
Tepix 16 hours ago | parent
insanitybit 16 hours ago | parent
pstoll 16 hours ago | parent
They can monitor extreme outliers. It’s not an issue for them.
ijustlovemath 16 hours ago | parent
aliasxneo 16 hours ago | parent
pstoll 7 hours ago | parent
But again my point applies - the chances they get enough people using it that it becomes a meaningfully worse security target than lots of other existing things seems … super low.
It’s a big world, people make many choices I can’t understand (nix? Haskell? Php? <flame wars to /dev/null>). Even if this product nailed it - the number of people who can use it is minuscule - yes even as we add Claude-enabled PMs to the software dev ranks.
Alt view with the old saying - “put all your eggs in one basket … and watch that basket!”
inopinatus 16 hours ago | parent
mitxela 9 hours ago | parent
Perz1val 15 hours ago | parent
t_mahmood 15 hours ago | parent
I'm not trusting any of these corporates any more
done_lurking 14 hours ago | parent
ozozozd 11 hours ago | parent
“The substrate itself consists of a few systems…”
I doubt that this is how wordy your communication is.
“It consists of a few systems” would be adequate. And if we had prior context about what else exists that surrounds “the substrate” the “substrate itself” distinction would be meaningful, but it’s not, because you are referring to one object, which is the system you built, and I doubt any enzymes act on it, so it’s likely not a substrate.
whizzter 17 hours ago | parent
Imustaskforhelp 17 hours ago | parent
mitxela 9 hours ago | parent
axus 17 hours ago | parent
srichard16 15 hours ago | parent
noname120 10 hours ago | parent
uxjw 15 hours ago | parent
JV00 17 hours ago | parent
daemonologist 17 hours ago | parent
raahelb 16 hours ago | parent
[1]: https://developers.cloudflare.com/cloudflare-one/networks/co...
Narciss 17 hours ago | parent
Thought it was very cool
smalltorch 17 hours ago | parent
It does the exact same thing, except supported by a global network of volunteers around the world.
Sure, you get some latency, but this is actually ideal for testing. You should know how your service operates in non optimal lightning fast conditions.
thenewnewguy 16 hours ago | parent
The obvious difference (and thus massive advantage) of the cloudfare product is that it is accessible over the normal internet without needing to install a tor client.
I'm sure that works for some subset of the population where all potential users are already comfortable using Tor; but imagine trying to share your PoC website with the designer/client and you are asking them to install Tor browser.
smalltorch 16 hours ago | parent
Is different than sharing your work with a client.
I personally wouldnt make it SOP to utilize a complely free service like this to share my work. I'm not saying it's not convient, it definitely is.
But you shouldn't subject a clients product to terms they probably aren't aware of.
himata4113 16 hours ago | parent
booi 16 hours ago | parent
cute_boi 16 hours ago | parent
usewik 15 hours ago | parent
cub-creature 15 hours ago | parent
xeornet 16 hours ago | parent
rozab 16 hours ago | parent
maipen 14 hours ago | parent
tombert 16 hours ago | parent
I think that rule is more of a "we reserve the right to..." rule, but it makes me sad because I'd rather not open up ports on my router to expose my Jellyfin to my parents.
TonyStr 16 hours ago | parent
tombert 16 hours ago | parent
madeforhnyo 16 hours ago | parent
guluarte 15 hours ago | parent
tamimio 16 hours ago | parent
bityard 16 hours ago | parent
tombert 16 hours ago | parent
mitxela 8 hours ago | parent
rplnt 16 hours ago | parent
reaperducer 16 hours ago | parent
We live in an age of monkey-see-monkey-do management.
When Microsoft axed its QA team, it gave permission for everyone else to make the same stupid mistake.
rvz 13 hours ago | parent
lkbm 16 hours ago | parent
rplnt 16 hours ago | parent
brazukadev 13 hours ago | parent
Gigachad 10 hours ago | parent
I've never seen someone fail a static page like this. And from a huge company like Cloudflare too..
075326899532 16 hours ago | parent
israrkhan 16 hours ago | parent
https://github.com/anderspitman/awesome-tunneling
I have played around with frp, bore and ngrok.
drdexebtjl 16 hours ago | parent
damsta 16 hours ago | parent
ggg011012 16 hours ago | parent
pstoll 16 hours ago | parent
rinconrex 15 hours ago | parent
kelvinjps10 16 hours ago | parent
raahelb 16 hours ago | parent
> Free tunnels are meant to be used for testing and development, not for deploying a production website.
[0: https://developers.cloudflare.com/cloudflare-one/networks/co...
awwaiid 13 hours ago | parent
opengrass 10 hours ago | parent
singpolyma3 16 hours ago | parent
AtNightWeCode 16 hours ago | parent
nullbyte 16 hours ago | parent
I used to use a service called ngrok for this, but it's nice that Cloudflare is offering one now.
usewik 15 hours ago | parent
frankcostanza 15 hours ago | parent
_pdp_ 15 hours ago | parent
yodon 15 hours ago | parent
srichard16 15 hours ago | parent
cmacleod4 14 hours ago | parent
One caveat - there is an option to inject Javascript into your pages for traffic measurement which is ON BY DEFAULT, you have to go to "Web Analytics" and turn this off if you don't want it!
TIPSIO 15 hours ago | parent
Anything from baby stuff, groceries, shopping, planning, wine tracker app, simple/fun/useful data things, etc…
We have Tailscale on our phones and can instantly and privately see without deployment or anything crazy via our secure VPN.
Think shared Claude Artifacts that don’t live @ Anthropic.
Tried to first do this with Cloudflare Tunnels (because I love Cloudflare), but between the broken dashboard side of Zero Trust and nightmare of Warp… it was basically impossible to setup. I guess that’s all super enterprise, which seems to be very anti-Cloudflare philosophically to not be able to self do things.
Will check out Quick Tunnels but I think it’s missing the bigger integration offerings Tailscale has/does still.
noir_lord 15 hours ago | parent
Getting it to do what I wanted with a traefik front router with cloudflared talking to arbitrary subdomain that is spun up and broadcast from the other project side was very painful in a "this could be more friendly" way.
It has been truly bulletproof though since then so that's almost enough to make me go reread all the docs.
nemosaltat 15 hours ago | parent
DaSHacka 11 hours ago | parent
_blk 15 hours ago | parent
cbsks 15 hours ago | parent
> Anything from baby stuff, groceries, shopping, planning, wine tracker app, simple/fun/useful data things, etc…
Can you elaborate on this? Sounds really cool!
SwamyM 15 hours ago | parent
U4E4 14 hours ago | parent
The core is chat+audio/video call server running locally on my m3 Mac Studio. Centrifugo has handled the chat concerns very well. LiveKit was a really nice foundation for video and audio calls. There are a few different options for local STT if you want that.
I used RN via expo for the client and have my friends and family on TestFlight as beta testers. Utility over polish.
With messages and call transcripts on my own box, I can prompt Claude code or Codex to operate on any message or transcript content. And follow up in chat with a message. I do most of that from Claude or ChatGPT mobile apps via remote control to my sessions running in the box.
From there, if I give enough of a specc, anything that happens in chat or call transcripts can become an additional custom workspace in the main app. I think GP calls these mini apps. But they’re essentially rich clients under the main app umbrella. There’s other details, but yeah it’s a strange new world. Check my profile and reach out directly if you want.
dizzard 13 hours ago | parent
rambleraptor 13 hours ago | parent
ilusion 4 hours ago | parent
FridayCuriousit 15 hours ago | parent
U4E4 13 hours ago | parent
theturtletalks 15 hours ago | parent
You can also use Tailscale serve to get a HTTPS url like Cloudflared but it's only visible to your tailnet. Be careful using Cloudflare tunnels because they are public and bots start poking around immediately.
SparkyMcUnicorn 14 hours ago | parent
For public access, similar to these cloudflare tunnels, there's Tailscale Funnel.
nacs 14 hours ago | parent
MattCruikshank 13 hours ago | parent
The CLI doesn't let you do as much as the go library does.
bakkoting 13 hours ago | parent
Here's `tailscale funnel status` on my machine:
$ tailscale funnel status
# Funnel on:
# - https://my-machine.tailXXXX.ts.net
https://my-machine.tailXXXX.ts.net (Funnel on)
|-- / proxy http://localhost:3000
|-- /foo proxy http://localhost:3001
|-- /bar proxy http://localhost:3002
|-- /baz proxy http://localhost:4004justinc8687 4 hours ago | parent
havnagiggle 3 hours ago | parent
0x1ch 14 hours ago | parent
garettmd 14 hours ago | parent
0x1ch 12 hours ago | parent
drcongo 12 hours ago | parent
0x1ch 12 hours ago | parent
allthetime 5 hours ago | parent
drakenot 6 hours ago | parent
Is this primarily for multi-user scenarios or complex setups?
usagisushi 3 hours ago | parent
Beyond that, compared to a typical hub-and-spoke WireGuard setup, the main advantage is peer-to-peer connectivity. Clients connect directly to each other when possible, which lowers latency by bypassing a central relay.
AFAIK, they also have different origins:
Pangolin started as an internet-facing reverse proxy (Traefik) combined with a WireGuard server for backend nodes. It has gradually added VPN-like features, including client device access and an internal HTTPS proxy similar to Tailscale Serve.
NetBird is a self-hostable Tailscale alternative that started as a mesh VPN focused on P2P traffic. It recently added its own reverse proxy features (Traefik-based, coincidentally), also similar to Tailscale Serve.
Pangolin is centered on endpoint and ingress management, while NetBird focuses on mesh networking, though their feature sets are increasingly converging.
_user_account 13 hours ago | parent
herpdyderp 13 hours ago | parent
titularcomment 13 hours ago | parent
matthewmacleod 13 hours ago | parent
pocksuppet 12 hours ago | parent
dlopes7 12 hours ago | parent
girvo 10 hours ago | parent
tenuousemphasis 8 hours ago | parent
eloisius 8 hours ago | parent
devilbunny 6 hours ago | parent
The only always-on TS service on my phone is Immich for photo backup, and I don't take enough photos for that to matter much.
aborsy 6 hours ago | parent
devilbunny 3 hours ago | parent
My endpoint is a pretty stable (though technically dynamic) IPv4 on one end, but the other might be a cell phone with CGNAT, some random WiFi, blah blah etc. TS does that. If you don't want to use it, cool. Don't. I'm willing to make the tradeoffs to use TS for now. That could change in the future.
prtmnth 7 hours ago | parent
roberttod 13 hours ago | parent
parthdesai 13 hours ago | parent
wildzzz 11 hours ago | parent
threecheese 13 hours ago | parent
EDIT you don't mean running on your actual phone lol, you mean in the web browser at Claude.ai. Anyway, if you use mcp-proxy for a stdio mcp, or if it's an http mcp alone, then you would need a public endpoint for Claude.ai to connect to. Tailscale will only help you if you use Funnel, but this cloudflare thing is exactly what you need (w/o Tailscale).
dalberto 11 hours ago | parent
https://github.com/dalberto/mcp-ferry
I also use CF managed auth to make auth easier.
gopalv 13 hours ago | parent
Until I had tailscale serve generating valid certs, I had a good reason to use Cloudflare tunnels.
But in general I don't want to put everything on the internet side of things.
Mostly, I don't want something open, but more like a "share with" for people who are in the same office (virtually over tailnet, not physically on the same LAN).
This still works great for a demo instead of a product pitch, to send an link out to see something.
I'd still use a real host over a laptop for those.
unixhero 12 hours ago | parent
nijave 9 hours ago | parent
Terraform has worked decently well especially since there's a few random settings here and there that aren't exposed anywhere in the UI (facepalm)
ramoz 7 hours ago | parent
Shameless plug, I've built a self-hosted capability here with things like live collaboration for humans and agents. There is a native cloudflare deplyoment and integration with Cloudflare Artifacts. PR for tunnel would be appreciated.
gibs0ns 6 hours ago | parent
For the few services I host that require SSL (eg; WebUSB), I serve the dark service via a standard domain (example.com) so I can still get a LetsEncrypt cert, but public access to that domain resolves to a static page; "Plz connect to OpenZiti & try again". This allows me to have SSL on required dark services without requiring to install a private CA for each client.
allthetime 5 hours ago | parent
pruneau 5 hours ago | parent
ezst 3 hours ago | parent
pbreit 3 hours ago | parent
epolanski 1 hour ago | parent
dbmikus 15 hours ago | parent
afisxisto 15 hours ago | parent
ssh -p 443 -R0:localhost:9051 free.pinggy.io
(Free for 1h each session)
scosman 15 hours ago | parent
corvad 15 hours ago | parent
smetannik 15 hours ago | parent
adamfeldman 15 hours ago | parent
keeganpoppen 14 hours ago | parent
robertlagrant 14 hours ago | parent
st3fan 13 hours ago | parent
lysace 11 hours ago | parent
judge2020 9 hours ago | parent
lysace 6 hours ago | parent
The product is falsely advertised as is:
"Cloudflare Quick Tunnels"
This is on one (or two) particular domain(s) where setting up wildcard DNS should be relatively trivial, if they actually cared enough about the UX of this product to make a special case in their code.
I don't understand how people can launch stuff like this.
rock_artist 15 hours ago | parent
While testing it locally Codex by itself suggests using CF Tunnels but what's more interesting it actually used the Quick Tunnels.
Coming from days where I get warnings of vibe-coded generated code using deprecated code or older APIs, I must say using something so fresh is quite impressive.
awwaiid 13 hours ago | parent
everybodyknows 15 hours ago | parent
> Free, secure tunnel for everything you are building.
> Preview and ship ideas globally in seconds with Quick Tunnels. Deploy your local application to the Internet with a single command.
Clicking through Explore Cloudflare Tunnel leads us to:
> Looking to expose public applications? This documentation covers Cloudflare Tunnel use cases for private networking and Zero Trust, like VPN replacement and private network access. For publishing public web applications, APIs, and services to the Internet through Cloudflare refer to ...
rinconrex 15 hours ago | parent
spprashant 15 hours ago | parent
superkuh 15 hours ago | parent
bilater 15 hours ago | parent
bitlad 15 hours ago | parent
skhameneh 15 hours ago | parent
Edit: Well, they just re-vibed it. Went from the most generic Claude 4.6 era to today’s models, quality wise. I wish I had saved a copy of the original, because it would have taken me actual solid effort to make a page that generic out of an LLM.
PufPufPuf 15 hours ago | parent
vlyan 15 hours ago | parent
(idk if it's really declining or I simply haven't noticed it in a while)
infogulch 15 hours ago | parent
The vps runs a custom image that is 2.54 Megabytes. It has a custom kernel with almost everything but networking and wireguard disabled, a fixed-size fs with pre-allocated blocks and inodes to hold the vps wireguard key, and a single pid 1 binary that calls the kernel directly to set up the routing rules, generate a new wireguard key on first boot and save it to the fs, print out the wireguard public key to the console, and loops reap. Updating involves building and uploading a new image, assigning the vps to use it, reboot, wait for the public key in the console then set it on the nas so they can talk.
RedCinnabar 13 hours ago | parent
infogulch 8 hours ago | parent
cyberamirul 1 hour ago | parent
maipen 14 hours ago | parent
This type of quality downgrade is scary, and it's everywhere now.
rkovashikawa 14 hours ago | parent
mgw 14 hours ago | parent
6thbit 14 hours ago | parent
existing (slow) tunnels you can create once you've set up your own domain for cloudflare to manage its DNS, installing cloudflare software, logging in to your account, and running a similar command.
edit: my bad, quick ones aren't new at all
mmoustafa 13 hours ago | parent
rcarmo 14 hours ago | parent
partloyaldemon 14 hours ago | parent
ghoshbishakh 14 hours ago | parent
ssh -p 443 -R0:localhost:443 tcp@free.pinggy.io
Disclosure: Co-founder of pinggy.io here.
Edit: I meant TCP tunnels, UDP tunnels, or also TLS tunnels for end-to-end encryption.
tonymet 14 hours ago | parent
fragmede 13 hours ago | parent
tonymet 13 hours ago | parent
c0wb0yc0d3r 13 hours ago | parent
Also the lifetime I need the connection open. For something quick, ssh tunnel. For something normies use, reverse proxy. Ain’t trying to teach my parents about IP addresses and port numbers.
tonymet 11 hours ago | parent
tredre3 12 hours ago | parent
tonymet 11 hours ago | parent
judge2020 9 hours ago | parent
Also, the _main_ use case of `cloudflared` tunneling is using it as a long-term way to host production websites on your own hostname. the ability to create ad-hoc tunnels is more of a gimmick / advertising opportunity.
0: https://github.com/judge2020/cloudflare-connectivity-test/wi...
caymanjim 13 hours ago | parent
yuchi 14 hours ago | parent
It’s interesting that 10 (more?) years later the product has not evolved and, apparently, hasn’t found a way to finance itself without removing the pure free tunneling option.
sparc24 13 hours ago | parent
something like - "We help you put localhost on the Internet."
What could possibly go wrong?
m00x 13 hours ago | parent
hashstring 13 hours ago | parent
Also, the “0 ports opened” marketing is misleading. It still binds to a port and then also lets people access your resources over it.
I dislike that Cloudflare Engineering has become more… marketingy as of late. Also with their Cloudflare OS misnomer. Their products used to make more sense, what happened?
mitxela 9 hours ago | parent
_user_account 13 hours ago | parent
The other use case for webhooks is ok, but is exactly what ngrok already does since forever with a pretty high free quota.
rvz 13 hours ago | parent
nickgray 13 hours ago | parent
emadabdulrahim 13 hours ago | parent
Can someone chime in here?
blocke 13 hours ago | parent
Hmm, Tailscale is too convenient and that traffic is going dark from Cloudflare's all seeing eye.
pocksuppet 12 hours ago | parent
Mullvad themselves already turned off port forwarding because people were using it to host child pornography. This is like Mullvad's port forwarding, but free.
inconshreveable 12 hours ago | parent
we removed anonymous usage of our product many years ago because it was far and away the largest source of abuse on our entire platform.
i believe at this point that that anonymous, account-less tunneling services like this are net negative for the security of the internet
happy to answer any questions from the community
jeremyjh 11 hours ago | parent
Gigachad 10 hours ago | parent
opengrass 10 hours ago | parent
mitxela 9 hours ago | parent
tobih 11 hours ago | parent
opengrass 11 hours ago | parent
Don't pass -d, your tunnel URL prints in the console and you can download dirs as tarball.
saejox 11 hours ago | parent
dzonga 11 hours ago | parent
then just use Cloudflare tunnels to connect to the laptop.
cryptolobster 11 hours ago | parent
girvo 10 hours ago | parent
It was pretty easy to setup… but I cheated, and use Dokploy which handled most of it AFAICT
JeremyJaydan 10 hours ago | parent
narmiouh 10 hours ago | parent
vibe coded app with may be no security and now available from the internet for anyone to RCE into my laptop?
dools 10 hours ago | parent
noname120 9 hours ago | parent
Is a new vibe-coded landing page for a 5-year old product really worthy of being on the front page nowadays? There should at least be a [2021] in the title.
malfist 9 hours ago | parent
nijave 9 hours ago | parent
Yeah, I just checked the page >can connect their server to the Internet with Argo Tunnel for free
greyhound1 9 hours ago | parent
nojvek 7 hours ago | parent
nyxtom 7 hours ago | parent
mintflow 7 hours ago | parent
I also think it seems cloudflare enter into a stage keep adding products and make the portal looks like a maze to get more advanced features configured
Do you still remember cloudflare mesh and use and stick to it?
reddec 5 hours ago | parent
Originally didn't want to share but here it is https://github.com/reddec/tunnel-me
UI: fully LLM assisted (not vibe coded, but guided with a lot of iterations). Backend: hand written, but before release polished via LLM. Docs: me - input, LLM - output.
The things I am proud:
- it very reliable
- its single binary with reasonable defaults and low memory usage
- SSO out of the box (cause I am using pocketid in my homelab)
- very simple backend
Nevin1901 5 hours ago | parent
geroge_kyaw 3 hours ago | parent
shmde 3 hours ago | parent
cliftonc 3 hours ago | parent
itvision 1 hour ago | parent