Live data from Hacker News

Vulnerabilities exploited in VPN products used worldwide

ncsc.gov.uk

31–40 of 140 posts

Re: Vulnerabilities exploited in VPN products used worldwide

#31
post #16

Earlier quoted context omitted.

Wireguard isn't even stable yet - it's not even been mainlined by the Kernel which is one of the main selling points that it will eventually be included. It's alpha level software at this point and should not be relied upon or even trusted.

I've been using it for almost a year with literally zero issues. The closes to a problem was the lack of a windows client (though there was a third-party option a used for a while), which is now fixed. If this is alpha-quality software, I look forward to seeing like what the beta and release versions look.

I'm also using it, but the reality is that the Wireguard team states it's not production ready for good reason. If your threat model includes state level actors or you are a high value target to sophisticated cracking groups, I wouldn't use wireguard yet.

A lot of cryptographic protocols have come and gone, once thought secure. And 10-100x as many implementations of a specific protocol have fallen to mistakes, even built on secure protocols.

That said, if your threat model consists of relatively low level threats, like blocking your ISP from spying on you to sell your info to advertisers, I'd highly recommend wireguard. It works really fast and well.

Re: Vulnerabilities exploited in VPN products used worldwide

#32

Earlier quoted context omitted.

It does mean that. Free software and open source mean different things.

Is this open source or source available? There is a meaningful distinction.

What is the distinction?

Re: Vulnerabilities exploited in VPN products used worldwide

#33
post #10

>These vulnerabilities are well documented in open source. Seeing this awkward use of "open source" a lot lately. Its almost as if people think "readable on the internet for free" equals open source.

It does mean that. Free software and open source mean different things.

No. Open source has a precise defition that is equivalent with Free Software:

[1] https://opensource.org/osd-annotated

[2] https://en.m.wikipedia.org/wiki/Open_source

Re: Vulnerabilities exploited in VPN products used worldwide

#34
post #9

Earlier quoted context omitted.

Why do you prefer Wireguard over Openvpn?

Others pointed this out already, but I'd like to second the simplicity. It's much, much easier to set up wireguard, especially compared to the mess that is openvpn. I had to use algo to set up openvpn originally, and God help you if you're not on ubuntu. Secondly, wireguard is faster. If you're dealing with lots of users, CPU could be limited; in such environments, wireguard has allowed me up to fifty percent more th…

[deleted]

Re: Vulnerabilities exploited in VPN products used worldwide

#35

Earlier quoted context omitted.

Is this open source or source available? There is a meaningful distinction.

What is the distinction?

Open Source fullfills the open source definition: https://opensource.org/osd-annotated. Source available is software where you can look at the source, but do not have the rights you have with Open Source.

Re: Vulnerabilities exploited in VPN products used worldwide

#36

Earlier quoted context omitted.

It does mean that. Free software and open source mean different things.

No. Open source has a precise defition that is equivalent with Free Software: [1] https://opensource.org/osd-annotated [2] https://en.m.wikipedia.org/wiki/Open_source

It's not equivalent with Free Software. Free Software has stricter requirements.

Re: Vulnerabilities exploited in VPN products used worldwide

#37
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

What do you think about cloudflare's vpn offerings? 1.1.1.1 and cf access?

I don't know about them really but Cloudflare Warp is using the Wireguard protocol.

Re: Vulnerabilities exploited in VPN products used worldwide

#38
post #9
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

Why do you prefer Wireguard over Openvpn?

Wireguard codebase is tiny at it has been reviewed by a lot of skilled eyeballs.

Re: Vulnerabilities exploited in VPN products used worldwide

#39
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

>The gold standard, as ever, is Wireguard.

Not disagreeing with you about the state of commercial VPN products, but regarding WG specifically. Something I don't see in the other replies just yet is that Wireguard doesn't yet have an ecosystem around it, but is designed for that in a good way. By which I mean, it follows the Unix philosophy of focusing on one specific task and doing it very well, and it has succeeded in that admirably even at its early stage of development. And long term I think that will result in better, more secure and more reliable solutions. But in the immediate term solutions/ecosystems around it don't exist and I think that makes for legitimate scalability problems for anyone who doesn't want to roll their own infrastructure. It very explicitly doesn't want to deal with integrating with key management/HSMs/AD policies/whatever. Eventually WG itself will be used along with those, and there will be nice GUIs on it, and so on. Hopefully it'll simply become the standard for VPN products to rely upon and the world will be a better place for it.

But in these early days it can't slot in everywhere because it's not even meant to. That'll take more time, maybe kernel mainlining (maybe after the WG port to the crypto API Jason announced last week?) and integration with the *BSDs. It's still in a fairly significant growth phase.

Re: Vulnerabilities exploited in VPN products used worldwide

#40
post #23

Earlier quoted context omitted.

Yes, I know that is the problem, but that doesn't make it any less self-inflicted.

How is having to conform to an audit performed by an external party as required by regulatory agencies or legislation "self-inflicted"?

They could push back instead of rolling over. You don't usually even need to question the law, just your auditors -- the phrasing of the law is often something that provides adequate provision for reasonable action. If your auditors are unreasonable, fire them.
Post reply on HN