Live data from Hacker News

Vulnerabilities exploited in VPN products used worldwide

ncsc.gov.uk

21–30 of 140 posts

Re: Vulnerabilities exploited in VPN products used worldwide

#21

Earlier quoted context omitted.

Empathy for a self-inflicted problem? Why?

Because they undergo audits that have arbitrary rules, sometimes making it harder or impossible for them to use tools like wireguard.

Yes, I know that is the problem, but that doesn't make it any less self-inflicted.

Re: Vulnerabilities exploited in VPN products used worldwide

#22
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

Lots of loose language in your post. Show me a FIPS140-2 Wireguard implementation.

I could be wrong, but it’s superseded by FIPS140-3.

Anyway, compliance doesn’t necessarily imply security.

Re: Vulnerabilities exploited in VPN products used worldwide

#23

Earlier quoted context omitted.

Because they undergo audits that have arbitrary rules, sometimes making it harder or impossible for them to use tools like wireguard.

Yes, I know that is the problem, but that doesn't make it any less self-inflicted.

How is having to conform to an audit performed by an external party as required by regulatory agencies or legislation "self-inflicted"?

Re: Vulnerabilities exploited in VPN products used worldwide

#24
post #9
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

Why do you prefer Wireguard over Openvpn?

I spent over two days setting up OpenVPN the first time I used it and less than an hour the first time I set up Wireguard. Wg seems a bit more reliable too, sometimes my OpenVPN sessions would time out and require manual intervention, but since switching to wireguard it always seems to "just work".

Re: Vulnerabilities exploited in VPN products used worldwide

#26
post #9
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

Why do you prefer Wireguard over Openvpn?

Others pointed this out already, but I'd like to second the simplicity. It's much, much easier to set up wireguard, especially compared to the mess that is openvpn. I had to use algo to set up openvpn originally, and God help you if you're not on ubuntu.

Secondly, wireguard is faster. If you're dealing with lots of users, CPU could be limited; in such environments, wireguard has allowed me up to fifty percent more throughput than with openvpn. It's also newer and probably not as optimized, so may get better. Finally, the new tap/tun driver on windows is orders of magnitude better than the openvpn one.

Re: Vulnerabilities exploited in VPN products used worldwide

#27
post #10

>These vulnerabilities are well documented in open source. Seeing this awkward use of "open source" a lot lately. Its almost as if people think "readable on the internet for free" equals open source.

It does mean that. Free software and open source mean different things.

Is this open source or source available? There is a meaningful distinction.

Re: Vulnerabilities exploited in VPN products used worldwide

#28
post #16
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

Wireguard isn't even stable yet - it's not even been mainlined by the Kernel which is one of the main selling points that it will eventually be included. It's alpha level software at this point and should not be relied upon or even trusted.

I've been using it for almost a year with literally zero issues. The closes to a problem was the lack of a windows client (though there was a third-party option a used for a while), which is now fixed. If this is alpha-quality software, I look forward to seeing like what the beta and release versions look.

Re: Vulnerabilities exploited in VPN products used worldwide

#29

Earlier quoted context omitted.

Lots of loose language in your post. Show me a FIPS140-2 Wireguard implementation.

I could be wrong, but it’s superseded by FIPS140-3. Anyway, compliance doesn’t necessarily imply security.

Unless you are purposely trying to pedantic, one should know that FIPS140-3 just came out. You can't even search the Cryptographic Module Validation Program (CMVP) tool for FIPS140-3 standard level yet. FIPS140-2 for all practical purposes is the current standard to measure against.

And if you really are negating FIPS140-X and what it means to large organizations and government entities... you should do some reading to understand why it exists. It isn't standards hand-waving. It is fairly in-depth and aims to ensure your cryptographic primitives and low level operations are not totally fucked out of the box.

It doesn't solve most security issues by a long shot, but it does try to give you some minimum levels of assurance that it doesn't totally suck crypto operations-wise.

Anyways - I up-voted your reply regardless because I wanted to engage in some meaningful dialogue, and I believe we have. Cheers!

Re: Vulnerabilities exploited in VPN products used worldwide

#30
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

> Commercial enterprise VPN products are an open sewer,

Commercial enterprise VPN products exist for one reason:

To allow the enterprise security office to tick off the checkbox on the quarterly compliance forms that essentially says: "using a VPN to provide secure communications".

Security is only a secondary consideration, if it is even considered at all.

Post reply on HN