Three prevalent themes in the discussion
1. Privacy guarantees vs. MITM concerns
Many commenters focus on what OHTTP actually hides and what it still reveals.
- “Cloudflare (or any OHTTP gateway) sees who talks to who, but can't see the content. The service sees the content but not who you are/your IP.” – johnhess
- “Does Cloudflare's WAF (which relies on TLS Fingerprinting) stop working if OHTTP is enabled? If not, does this imply the client metadata is read and processed by Cloudflare but not passed on to the application server?” – arshxyz
- “At my previous job we routinely gave out IP-based bans, and it worked pretty well; the most insistent guys gave up after their third or fourth IP banned at most.” – Joker_vD
These excerpts show the split‑trust model (gateway sees metadata, origin sees payload) and the tension between privacy gains and the loss of traditional abuse‑fighting tools like IP‑based bans.
2. Distrust of Cloudflare’s motives (government ties, business model)
A recurring skeptical strand questions whether Cloudflare’s privacy tools serve ulterior interests.
- “I have absolutely no reason to think Cloudflare is a covert CIA operation. In fact, I’m sure there are plenty of good reasons to think it isn’t. But if it were, pretty much everything it does is exactly what you'd expect from one.” – simondotau
- “NSA's mission… is to collect information that constitutes 'foreign intelligence or counterintelligence' while not 'acquiring information concerning the domestic activities of United States persons'.” – groomlake (quoting Wikipedia)
- “Customers will be able to enable our new OHTTP Gateway as a paid add-on to their zone and start receiving OHTTP traffic with just a few clicks.” – freedomben (highlighting the monetisation angle)
These quotes reflect worries that Cloudflare may be acting as a middleman for intelligence agencies or profiting from privacy‑as‑a‑service.
3. Practical effectiveness and operational trade‑offs
Commenters also discuss how OHTTP works in the real world—abuse mitigation, usability, and alternatives.
- “I have a public facing website that is blocking about 500 obviously botted requests per second. About half are from residential proxies.” – someonebaggy
- “Why not both? When browsing Microsoft, give your IP to Cloudflare. When browsing Pouet, give your IP to Pouet.” – someonebaggy (suggesting selective trust)
- “Self Service Relay https://oblivious.network/” – wferrell (pointing to decentralized options)
These remarks underline the debate over whether OHTTP meaningfully reduces tracking while still allowing site operators to combat bots and abuse.