Comment by fragmede

17 hours ago

So you don't know my IP (DDoS target), and because of NAT.

I think tonymet meant he didn't understand why cloudflare didn't allow using ssh -R instead of cloudflared to create the tunnel, not not using a tunnel at all.

  • cloudflared is a bit unique in that it makes multiple outbound connections to CF DCs to do the tunneling and fails over if a DC has an issue (or, more likely, when a DC is near-capacity and they need to divert lower-tier traffic away from it[0]). SSH would reintroduce a single point of failure to this.

    Also, the _main_ use case of `cloudflared` tunneling is using it as a long-term way to host production websites on your own hostname. the ability to create ad-hoc tunnels is more of a gimmick / advertising opportunity.

    0: https://github.com/judge2020/cloudflare-connectivity-test/wi...

any app will connect with an IP am I missing something . a socket is exactly (IP, port) (src, target) tuple

  • For me, it’s as much about ease of use as much as it is about minimizing attack surface area.

    Also the lifetime I need the connection open. For something quick, ssh tunnel. For something normies use, reverse proxy. Ain’t trying to teach my parents about IP addresses and port numbers.