Project ideas from Hacker News discussions.

Cloudflare OHTTP gateway

📝 Discussion Summary (Click to expand)

Three prevalent themes in the discussion


1. Privacy guarantees vs. MITM concerns

Many commenters focus on what OHTTP actually hides and what it still reveals.

  • “Cloudflare (or any OHTTP gateway) sees who talks to who, but can't see the content. The service sees the content but not who you are/your IP.” – johnhess
  • “Does Cloudflare's WAF (which relies on TLS Fingerprinting) stop working if OHTTP is enabled? If not, does this imply the client metadata is read and processed by Cloudflare but not passed on to the application server?” – arshxyz
  • “At my previous job we routinely gave out IP-based bans, and it worked pretty well; the most insistent guys gave up after their third or fourth IP banned at most.” – Joker_vD

These excerpts show the split‑trust model (gateway sees metadata, origin sees payload) and the tension between privacy gains and the loss of traditional abuse‑fighting tools like IP‑based bans.


2. Distrust of Cloudflare’s motives (government ties, business model)

A recurring skeptical strand questions whether Cloudflare’s privacy tools serve ulterior interests.

  • “I have absolutely no reason to think Cloudflare is a covert CIA operation. In fact, I’m sure there are plenty of good reasons to think it isn’t. But if it were, pretty much everything it does is exactly what you'd expect from one.” – simondotau
  • “NSA's mission… is to collect information that constitutes 'foreign intelligence or counterintelligence' while not 'acquiring information concerning the domestic activities of United States persons'.” – groomlake (quoting Wikipedia)
  • “Customers will be able to enable our new OHTTP Gateway as a paid add-on to their zone and start receiving OHTTP traffic with just a few clicks.” – freedomben (highlighting the monetisation angle)

These quotes reflect worries that Cloudflare may be acting as a middleman for intelligence agencies or profiting from privacy‑as‑a‑service.


3. Practical effectiveness and operational trade‑offs

Commenters also discuss how OHTTP works in the real world—abuse mitigation, usability, and alternatives.

  • “I have a public facing website that is blocking about 500 obviously botted requests per second. About half are from residential proxies.” – someonebaggy
  • “Why not both? When browsing Microsoft, give your IP to Cloudflare. When browsing Pouet, give your IP to Pouet.” – someonebaggy (suggesting selective trust)
  • “Self Service Relay https://oblivious.network/” – wferrell (pointing to decentralized options)

These remarks underline the debate over whether OHTTP meaningfully reduces tracking while still allowing site operators to combat bots and abuse.


🚀 Project Ideas

ObliviousProxy: Self‑Hosted OHTTP Relay & Gateway Suite

Summary

  • Provides Docker/Kubernetes‑deployable OHTTP relay and gateway components so anyone can run their own privacy infrastructure without relying on Cloudflare.
  • Core value proposition: full control over who sees metadata vs. content, eliminating third‑party trust and reducing centralization concerns.

Details

Key Value
Target Audience Developers, site operators, privacy enthusiasts who want to run private OHTTP relays/gateways for themselves or their community
Core Feature One‑click deployment of an OHTTP relay (receives client‑encrypted requests) and gateway (decapsulates for the origin server) with TLS termination, optional mTLS, and basic metrics
Tech Stack Go (OHTTP implementation), Docker, Kubernetes Helm chart, Prometheus/Grafana for monitoring, optionally Envoy as sidecar for traffic shaping
Difficulty Medium
Monetization Hobby

Notes

  • HN commenters asked “how can i run this for my friends and me selfhosted? is there a ohttp server?” showing a clear demand for DIY OHTTP infrastructure.
  • Enables community‑run relays that alleviate worries about Cloudflare’s MITM role while giving small sites a free way to offer OHTTP privacy.

OHTTP‑AbuseGuard: Privacy‑Preserving Bot & Abuse Mitigation for OHTTP Gateways

Summary

  • Adds plug‑in based rate limiting, proof‑of‑work challenges, and revocable anonymous tokens to OHTTP gateways, letting operators block abusive traffic without learning real IP addresses.
  • Core value proposition: lets site owners defend against bots and abuse while preserving the IP‑oblivious privacy guarantees of OHTTP.

Details

Key Value
Target Audience Operators of OHTTP relays/gateways (including self‑hosted suite users) who need to stop bots, credential stuffing, or DDoS while keeping client IPs hidden
Core Feature Middleware that issues short‑lived anonymous tokens (Privacy Pass style) or requires PoW/CAPTCHA per request, tracks token usage, and can revoke tokens for abusive clients; integrates via Envoy filter or custom handler
Tech Stack Go/Rust plugin, libp2p or Redis for token state, integrates with existing OHTTP gateway codebase; uses HPKE for token encryption
Difficulty Medium‑High
Monetization Revenue‑ready: tiered SaaS pricing based on monthly request volume; open‑core with paid support/SLAs

Notes

  • Users expressed frustration: “How would you add 'banning abusers by IP' functionality?” and noted residential proxies make IP bans ineffective.
  • Provides a privacy‑friendly abuse‑control mechanism that satisfies both privacy advocates (no IP leakage) and site owners needing security, directly addressing the quoted concern.

ObliviousFox: Browser Extension for User‑Controlled OHTTP Traffic

Summary

  • A WebExtension that transparently wraps outgoing HTTP(S) requests in OHTTP using user‑selected relays, giving end users IP privacy without relying on Cloudflare’s default relay.
  • Core value proposition: puts the choice of relay (self‑hosted, community, or trusted third‑party) in the user’s hands, with per‑site policy controls and fallback to direct connections when needed.

Details

Key Value
Target Audience Privacy‑conscious end users who want to hide their IP from websites while maintaining normal browsing usability
Core Feature Intercepts requests, performs OHTTP encryption via a chosen relay, forwards to the gateway; UI for managing relay whitelist, viewing metadata leaks, and setting per‑site exceptions (e.g., banking sites)
Tech Stack WebExtension (JavaScript/TypeScript), Web Crypto API for HPKE, optional native messaging host for relay communication, React‑based popup UI
Difficulty Medium
Monetization Hobby (donation‑supported) – could evolve into a premium relay subscription service if desired

Notes

  • Commenters noted iCloud Private Relay already uses OHTTP and voiced interest in similar user‑controlled solutions; others worried about Cloudflare acting as a MITM.
  • Empowers users to pick their own relays, mitigating centralization trust issues and providing a practical everyday tool for IP obfuscation.

Read Later