klzgrad:WebSocket 代理方向技术上偏弱,不值得推进
在 naiveproxy PR #835(Add WebSocket upstream transport,已关闭)讨论中表示:WebSocket 代理在当前 Cloudflare 自助订阅协议下仍不被允许(2.2.1(j) 禁止用其服务提供 VPN 或其他类似代理服务),但如他在 issue #775 中所回复,Cloudflare 条款并非主要技术顾虑。他认为该 PR 本身「borderline AI slops」,以当前形式不会被接受,不过算是一次值得认真技术回应的半正式尝试。理由是:常见合法 WebSocket 应用(聊天、在线状态、游戏、行情推送)流量行为狭窄且规律,而足以承载异构流量的应用(远程桌面、云 IDE)属于小众,匿名集更小、更易被审查者研究;因此在当前互联网流量分布下,WebSocket 隧道无法在承载通用浏览器流量时良好模仿某个目标应用,即使采用 Chromium 网络栈也无法实现行为真实感。结论:整个 WebSocket 代理方向在技术上偏弱,不值得推进。
作者原文@klzgradIt should be noted that websocket proxying is still not permitted under the current Cloudflare Self-Serve Subscription Agreement
2.2.1 Restrictions Unless otherwise expressly permitted in writing by Cloudflare, you will not and you have no right to: (j) use the Services to provide a virtual private network or other similar proxy services.But as I replied in https://github.com/klzgrad/naiveproxy/issues/775, Cloudflare terms were not the main technical concern.
Note that this PR by itself is borderline AI slops and would not be accepted in its current form. But this PR would be a half-serious attempt at bringing something to the discussion that warrants a serious technical response.
The issue with websocket tunneling is that most common legitimate websocket applications such as chat, presence, games, or market feeds have narrow and regular traffic behavior, and applications broad enough to encompass heterogeneous traffic, such as remote desktops or cloud IDEs, are niche and offer a smaller anonymity set and are easier for a censor to study closely. Thus, common websocket workloads are behaviorally too narrow, while behaviorally broad websocket workloads are not common enough. Under the current Internet traffic distribution, websocket tunnels cannot behave as a good parrot of some target application while carrying generic browser traffic. Even if a websocket proxy adopts the Chromium net stack, it cannot achieve behavioral realism.
Therefore I argue the entire direction of websocket proxying is technically weak and not worth pursuing.