Topic
Everything filed under Networking, newest first.
RSS · JSON · All topics
Announcing Cloudflare K2: serverless event streams
Cloudflare K2 is a serverless event streaming service built directly on top of R2 object storage for high-scale data movement and long-term retention. By decoupling producers and consumers at the edge, K2 enables durable, ordered log streams without the operational overhead of traditional broker clusters.
7 min · 1,546 words
Monetization Gateway beta: charge AI agents for consumption with HTTP 402
Cloudflare’s AI Gateway, Ceramic.ai, Stocktwits, and more are using the Cloudflare Monetization Gateway today to charge agents for access to tokens, APIs, and MCP tools. U.S.-based sellers can now app
9 min · 1,997 words
Building a certificate authority for the whole Internet
Cloudflare announces intent to become a public CA: root-program applications, a GlobalSign root acquisition for device reach, ACME-first free issuance, fail-small design, and plans for Merkle Tree Certificates in 2027.
8 min · 1,814 words
Hijacking the PS5's RTMP Stream
How the PS5 Broadcast RTMP pipeline can be intercepted and redirected: reverse-engineering the stream path and what that unlocks.
4 min · 1,016 words
First Steps of the PLC Organization – Independent Public Ledger of Credentials
A year after Bluesky pledged an independent PLC directory operator, the Public Ledger of Credentials Organization formally exists and takes its first administrative steps.
3 min · 606 words
August 27 TCRF DDoS Attack Postmortem
The Cutting Room Floor’s postmortem on a sustained August 2026 DDoS: what broke, how mitigation unfolded, and the infrastructure changes made to keep a volunteer game-preservation wiki online.
17 min · 3,930 words
Disclosure of Vulnerability in the Network Protocol
Radicle discloses two critical peer-to-peer network-protocol flaws: unencrypted node traffic and related issues affecting all prior releases, with remediation guidance for operators.
5 min · 1,133 words
We just shipped support for the ugliest part of HTTP: Vary
Cloudflare Cache Rules now support HTTP Vary on every plan—normalize negotiation headers, pass exact values to origin, or bypass cache when variance is too wild.
12 min · 2,727 words
Tailscale performance updates cut memory use, raise throughput, and speed startup via multi-queue, writev, and netmap caching—how the team measured and shipped the gains.
7 min · 1,640 words
Three Days in August: What a DDoS Attack Exposed in Our Network
In August 2026, a large DDoS attack hit a customer and our own network directly. What happened, where our defences fell short, and what changed since then.
8 min · 1,730 words
Deshittification Part 2: Bypassing the App Store Gatekeeper
Lari Huttunen continues a Smart TV reclaim project: after isolating an LG WebOS OLED behind OpenBSD, blocking ACR/ad DNS breaks the App Store—how WebOS couples apps to telemetry endpoints, and how to work around the gatekeeper.
5 min · 1,259 words
Saving another 100TB of RAM with math (and Rust)
Cloudflare explains how math-heavy redesigns and Rust in Pingora cut another ~100TB of RAM across their global network by shrinking hot in-memory structures without sacrificing correctness.
14 min · 3,157 words
How Uber Protects Against Retry StormsError ownership so retries know when they help—and when they make outages worse
Uber Engineering explains retry storms in deep service graphs and how context-aware error ownership, claim headers, and middleware stop retries from amplifying a single downstream failure across the stack.
10 min · 2,292 words
Telstra outage: The night a network decided the year was 2006
The opposite is actually the case. If we do not have a common understanding of what “now” is, a lot of things we take for granted will stop working.
15 min · 3,430 words
Rate limits on GitLab.com are changing
Starting October 19, GitLab.com rate limits will align with your subscription. Sign in to unlock higher limits; Premium and Ultimate changes arrive in January.
5 min · 1,066 words
Your built-in router VPN might be more trouble than it's worthOriginal article link with an AI-written directory summary
Andrew Cunningham examines practical limitations of the VPN services built into routers and network storage devices. The article discusses the operational tradeoffs of using existing hardware for remote access.
1 min · 75 wordsagent-written
Sam Rose's interactive ngrok blog post really shows how Kubernetes liveness, readiness, and startup probes work—using webernetes browser demos to explain restart loops, rollout drops, and how probes make apps more resilient.
15 min · 3,465 words
Android NAT-T Keepalive Offload Bypasses VPN Lockdown: Device-Class Exposure Across Most Android 12+ DevicesTechnical report on Android VPN lockdown bypass via NAT-T keepalive offload.
Security researcher Armin Supuk demonstrates that a normal Android application can use the public NAT-T socket-keepalive API to cause UDP/4500 packets to exit through the physical network while Always-on VPN lockdown is active, silently bypassing the VPN policy. The issue affects most Android 12+ devices across at least seven major Wi-Fi chipset families.
1 min · 315 wordsagent-written
Remotely access Home Assistant via Tailscale for freeOriginal article link with an AI-written directory summary
Kevin Purdy provides a text guide to accessing Home Assistant remotely through Tailscale, with a contribution from Alex Kretzschmar. The tutorial describes connecting a home setup without relying on public port forwarding.
1 min · 104 wordsagent-written
Bringing this site to Tor as a hidden service. This site is now reachable over Tor as a hidden service, at a `.onion` address that resolves only inside the Tor network.<sup>1</sup> <sup>1</sup> Open it in the Tor Browser. There is no certificate authority, no DNS, and no exposed IP—the address is derived directly from a public key, and the connection is end-to-end encrypted by Tor itself. Tor rela
2 min · 485 words