Rendered at 20:04:45 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
eddythompson80 2 days ago [-]
It seems that cloudflare is trying to create an internet-wide agent identity platform in general. I have seem few attempts at “agent identity” but they were all intrinsically limited to a particular system. An identity AWS IAM assigns to an agent isn’t gonna work on rottentomatos.com or techcrunch.com.
This was always a vaguely desired thing, but the implementation details was always a form of OIDC federation which is mind-numbingly complex and not worth the hassle. Just shove an api key or a shared secret of some sort and move on. Only accounts that are very high value targets for attacks (cloud infra accounts, CIs infra, billing, and things they interact with implement OIDC federation. But that awesome Thai recipe blog has no chance of implementing something like that.
With Agents driving internet traffic, there is a desire to have identities for them. And since it’s inherently easy for them to leak these identities (look at the million sandbox solutions that all share the same dumb goal of “protect the API Key or password”), having short lived tokens for everything (AWS IAM or Azure Managed Identity like) simplifies the entire process. Agreeing on the single IdP was the problem, there are like 40 (Google, Apple, Microsoft, Facebook, Twitter, even GitHub, and Amazon have SSO not to mention all the regional specific ones)
There is a legitimate need for that, and it looks like cloudflare figured if they are that “internet agent identity provider”, then there is a lot of power and control over the internet and AI use in general.
merek 2 days ago [-]
Someone has already reserved my very unique company name and a bunch of variants.
Without domain validation, what is this user's intention other than fraud/impersonation?
I've already got an active impersonator running a website under my brand name and confusing my customers.
zuzululu 2 days ago [-]
nothing
Ycros 2 days ago [-]
It feels like Cloudflare keeps inserting itself in between everything, everywhere it can. So convenient you'll middleman yourself. I do not like this.
nater5000 1 days ago [-]
"This company keeps creating products in the space that they operate in, where there is clear demand, and that people want to use. What's their angle?"
927373912092 9 hours ago [-]
Are you paid or just a fanboy of a monopolist whose business is being a mitm attacker?
You swallow the corporate propagana hook, line and sinker if you think there's a demand for all of CF's vibeslopped crap and their unsolicited rentseeking.
hendler 2 days ago [-]
Cloudflare is certainly making a full court press to provide infra for the agentic web. My own ability to see whats coming also believes we need wallets, agent protocols, cloud services for agents, etc. So, maybe this is the way.
At the same time, something tells me what is coming isn't going to be as recognizable as these products build for.
eddythompson80 2 days ago [-]
What are some examples of what you see coming that requires agent wallets or agent protocols (I’m not 100% sure what that means tbh) or agent cloud services (what makes these different from regular cloud services?)
The only thing I see that’s unique for “agents” when it comes to cloud services is finally paying attention to provisioning speed and developer iterations.
Last year, for the first time in my career, I heard c-suite exec concerned about projects with multi-hour long CI or deployments that take hours because “agents can’t be successful” as they need to iterate way more.
threatofrain 2 days ago [-]
Their bets are naturally hedged because a lot of their infra is just nice AWS-lite.
nikolay 2 days ago [-]
What a stupid move! So, you have a Workers subdomain, a Zero Trust subdomain, and now a Wallet subdomain - one company with random handles! Cloudflare does not get identity!
nikolay 2 days ago [-]
For example, Meta does. When they started offering reserved usernames on Facebook, they gave advance notice and gave everybody an equal start. With WhatsApp usernames, they also allowed you to pick your Instagram username or your Facebook username. That's how it should be done. What Cloudflare did is basically push me not to use their offering, because I couldn't get my username. I'm not going to rebrand just for them! I'm sure most were reserved by crooks, not real customers, to blackmail the legit parties!
QuantumNoodle 1 days ago [-]
So this wallet thing is an identity, so when I have to use it on various sites then they effectively don't need cookies anymore to track me?
Many people set their DNS to 1.1.1.1 -- would be easy for cloudflare to resolve any TLD it feels like
ranguna 2 days ago [-]
Read most of the article, still not sure why we need this. Is this a stablecoin bank for agents?
If so, why not interact with an exchange?
Also, not sure how many merchants out there accept stablecoins. Probably not many.
hackernud3s 2 days ago [-]
This is interesting but how do site operators cash out? Is is non-custodial only like binance?
zooloo99 2 days ago [-]
Agentic commerce is such an interesting space!
Alipay and Coinbase already have similar offerings in market.
wxw 2 days ago [-]
Cloudflare's in a good position to be an agent infra provider. Durable objects and serverless/workers are great agent primitives.
It makes sense that they're leaning into an all-in-one platform play, i.e. if you use DOs, you might as well use our wallet/sandbox/AI gateway/etc. too.
- permission-ed system when we’ve got lightning and super low cost blockchains. They could even run their own L2.
- I am typing my name in a cafe and hear some clacking sounds. I was puzzled there for a full minute to where the sound was coming from. Who thought this is a good idea?
- So I finish the reservation and there is actually no product yet?
This was always a vaguely desired thing, but the implementation details was always a form of OIDC federation which is mind-numbingly complex and not worth the hassle. Just shove an api key or a shared secret of some sort and move on. Only accounts that are very high value targets for attacks (cloud infra accounts, CIs infra, billing, and things they interact with implement OIDC federation. But that awesome Thai recipe blog has no chance of implementing something like that.
With Agents driving internet traffic, there is a desire to have identities for them. And since it’s inherently easy for them to leak these identities (look at the million sandbox solutions that all share the same dumb goal of “protect the API Key or password”), having short lived tokens for everything (AWS IAM or Azure Managed Identity like) simplifies the entire process. Agreeing on the single IdP was the problem, there are like 40 (Google, Apple, Microsoft, Facebook, Twitter, even GitHub, and Amazon have SSO not to mention all the regional specific ones)
There is a legitimate need for that, and it looks like cloudflare figured if they are that “internet agent identity provider”, then there is a lot of power and control over the internet and AI use in general.
Without domain validation, what is this user's intention other than fraud/impersonation?
I've already got an active impersonator running a website under my brand name and confusing my customers.
You swallow the corporate propagana hook, line and sinker if you think there's a demand for all of CF's vibeslopped crap and their unsolicited rentseeking.
At the same time, something tells me what is coming isn't going to be as recognizable as these products build for.
The only thing I see that’s unique for “agents” when it comes to cloud services is finally paying attention to provisioning speed and developer iterations.
Last year, for the first time in my career, I heard c-suite exec concerned about projects with multi-hour long CI or deployments that take hours because “agents can’t be successful” as they need to iterate way more.
How is https://cloudflare.pay resolving?
If so, why not interact with an exchange?
Also, not sure how many merchants out there accept stablecoins. Probably not many.
Alipay and Coinbase already have similar offerings in market.
It makes sense that they're leaning into an all-in-one platform play, i.e. if you use DOs, you might as well use our wallet/sandbox/AI gateway/etc. too.
Web Security is Too Hard
https://news.ycombinator.com/item?id=49172834
- permission-ed system when we’ve got lightning and super low cost blockchains. They could even run their own L2.
- I am typing my name in a cafe and hear some clacking sounds. I was puzzled there for a full minute to where the sound was coming from. Who thought this is a good idea?
- So I finish the reservation and there is actually no product yet?