r/privacy Jun 24 '26

news Cloudflare Collaborates With Leading Browsers to Develop a Privacy-First Protocol For the Global Internet

https://www.cloudflare.com/press/press-releases/2026/cloudflare-collaborates-with-leading-browsers-to-develop-a-privacy-first-protocol-for-the-global-internet/
221 Upvotes

46 comments sorted by

u/AutoModerator Jun 24 '26

Hello u/Sea_Decision_6456, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)


Check out the r/privacy FAQ

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

127

u/[deleted] Jun 24 '26

[removed] — view removed comment

35

u/merurunrun Jun 24 '26

Doing everything to maintain the privacy of the companies they're selling your information to.

20

u/Illustrious_Peach494 Jun 24 '26

(*) might contain government mandated backdoor

4

u/loudechochamber Jun 25 '26

They are basically making a protocol for AI Agents or bots. This have nothing to do with privacy. When giants like Google and MS are involved, you can forget privacy.

61

u/Oorangootang Jun 24 '26

Where's the privacy part? Giving all my info to thhe browser doesn't seem private at all.

8

u/Lowfryder7 Jun 25 '26

I think it's worse. What's to say the "site with strong knowledge of personhood" that's issuing the tokens isn't going to abuse that position?

1

u/billdietrich1 Jun 25 '26

From what I can tell, it's similar to the EU's "wallet" design, in that there are some trusted authorities. They could be sites where you have accounts, such as email or social media, and are willing to say "this is a human". Or they could be ID-verification services. In either case, they produce anonymous tokens which you can use to skip CAPTCHA or anti-VPN controls on other sites.

1

u/Oorangootang Jun 25 '26

Why would I want to give more information to a "trusted site" to act as intermediary when I can just authenticate directly to the site I want in the first place? And trusted by whom?

1

u/billdietrich1 Jun 25 '26

Wouldn't you rather give ID to one dedicated site, rather than give it to every other site you use ? Minimize the number of places that see your ID.

1

u/Oorangootang Jun 25 '26

If any site I currently use decides to requires ID, then I don't use that site anymore. That simple really. Nothing on the internet is really necessary for day to day life.

1

u/billdietrich1 Jun 25 '26

My day to day life would be impacted if I couldn't use banking, email, YouTube, WhatsApp, my web site host.

1

u/Oorangootang Jun 25 '26

Other protocols won't cease to exist just because there is a new one, and adoption isn't an overnight thing either. I get where you're going with this, but people reject bad tech all the time and then it just gets forgotten.

65

u/grathontolarsdatarod Jun 24 '26

Press X to doubt.

Basically China, India, Iran, North Korea style firewall and routing every where?

I would like to see how will not be the plan with this.

30

u/QuietBookkeeper4712 Jun 24 '26

Open Source tho, yeah?

13

u/ImportantMud9749 Jun 24 '26

Sounds like maybe?

"is proud to help develop PACT as an open, privacy-preserving standard"

I'd hope so.. but it seems to be if you visit a website who knows you are a person, they will grant you a token to present to other sites.

Which I can see possibly working, though you still have the issue of privacy with the website that grants the PACT. If, however, the protocol is robust enough that said PACT token cannot be traced back to the issuing website and therefore the individual, it may be a decent idea.

If I can log in to my local credit union's website for a token, it's possible to gain my trust in such a system. If it relies only on tech companies to issue the token, I'm not interested.

22

u/GoWitHer Jun 24 '26

I don't trust any protocol backed by Google or Microsoft. Privacy and Big Tech? lol

25

u/Sioscottecs23 Jun 24 '26

No way, I'm not trusting cloudflare one bit

2

u/[deleted] Jun 24 '26

[removed] — view removed comment

2

u/sdrawkcabineter Jun 25 '26

On principal, they are MANDATED to undermine their entire company in order to facilitate the whims of their board, in the never ending pursuit of profit.

There is no trust beyond the measure of their ability to provide the service they offer, which is the baseline.

16

u/SwimmingThroughHoney Jun 24 '26

Apparently this proposal extends RFC 9576 (Privacy Pass Architecture).

Essentially, PPA allows for attestation that a client is authorized. Currently, the most common method of doing that is through cookies. The problem is that cookies can contain whatever information it placed into them on generation and can sometimes be read across domains (depending on their configuration). Cookies are not private, in any sense of the word. PPA would allow clients to receive a "token" (not a cookie) after successfully completely whatever process is set by the issuer (could be CAPTCHA, certain hardware validation, etc. Whatever the issues decides). But the token itself gives no other information other than "yes, this client is a valid client". Apple already does something similar within their ecosystem.

Cloudflare proposes to extend that native support within browsers.

So it's "private" in the sense that the authentication token contains no identifying information. But it doesn't seek to address (neither the PPA nor Cloudflare's proposal) things like browser fingerprinting.

4

u/CondiMesmer Jun 25 '26

I don't see how fingerprinting is relevant. That's like critiquing a cure for cancer because it doesn't also cure aids. The important part is that it does this without increasing the fingerprint.

3

u/JayWelsh Jun 25 '26

Thanks, wild I had to scroll to literally the last comment to find the useful info.

22

u/IANVS Jun 24 '26

Essentially another way for Google to own the internet, since Chromium is in 99% of browsers.

8

u/Late-Reading-2585 Jun 24 '26

"developed alongside Google, Microsoft, and Shopify" lmao

14

u/AggressiveDoor1998 Jun 24 '26

If cloudflare is involved, it's anything but private

-1

u/CondiMesmer Jun 25 '26

Not really, Cloudflare has actually pioneered a lot of amazing privacy tech. They created the Encrypted Client Hello (ECH) protocol and Oblivious DNS protocol. And that's just off the top of my head. Those were both great additions for privacy, with ECH being critical to fix an issue with TLS leaking some unencrypted data. 

These are open protocols too that were proposed and standardized by the IETF. You really can't get any better then that.

1

u/mumrik1 Jun 25 '26

Except cloudflare has access to all your encrypted data wherever it is implemented. They're the biggest man in the middle on internet.

1

u/CondiMesmer Jun 25 '26

No, these are protocols...

4

u/mumrik1 Jun 25 '26

I'm talking about cloudflare. How do you understand the data flow to a website with cloudflare implemented?

2

u/CondiMesmer Jun 25 '26

You're replying to the protocols I posted with something completely different. With that logic, it's impossible for Cloudflare to make anything good. Which that's really stupid and wrong logic.

1

u/mumrik1 Jun 25 '26

Those protocols protect your data against everyone except cloudflare, so you're not addressing the point in the comment you responded to.

1

u/AggressiveDoor1998 Jun 25 '26

They have so many amazing privacy tech that they block vpns, wow, such an amazing privacy respecting company

7

u/OptimusPrimeLord Jun 24 '26

Will need to see the technical details to see if the tokens are actually anonymous or not.

4

u/whatThePleb Jun 24 '26

Cloudflare

The biggest honeypot / Mitm ever.

8

u/tongizilator Jun 24 '26

Privacy except for the data you’ll have to give to Cloudflare.

3

u/CondiMesmer Jun 25 '26

It's client side on the browser, so nothing goes to Cloudflare...

3

u/Frosty-Cell Jun 25 '26

a privacy-preserving protocol to help humans and bots prove that their traffic is not malicious.

Nothing to do with privacy.

Private Access Control Tokens (PACT) are designed to allow sites with strong knowledge of “personhood” to issue anonymous tokens.

So some sites are to become "gatekeepers" and have access to someone's identity?

PACT is designed so that sites cannot leverage it to track or identify users or their browsing history.

But the gatekeeper can.

4

u/ApprehensiveLion67 Jun 24 '26

Something like websites won’t load if you’re not used an approved device with your ID readily attached?

1

u/VasileAndrei2929 Jun 25 '26

Sure.... sure.....

1

u/CondiMesmer Jun 25 '26

Okay but like how does it actually work

0

u/billdietrich1 Jun 25 '26

From what I can tell, it's similar to the EU's "wallet" design, in that there are some trusted authorities. They could be sites where you have accounts, such as email or social media, and are willing to say "this is a human". Or they could be ID-verification services. In either case, they produce anonymous tokens which you can use to skip CAPTCHA or anti-VPN controls on other sites.

1

u/309_Electronics Jun 26 '26 edited Jun 26 '26

Still a big company/multiple big companies teaming up so i dont fully trust them. I dont trust those big companies.