Live data from Hacker News

Response to “WireGuard: great protocol, but skip the Mac app”

lists.zx2c4.com

201–210 of 392 posts

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#201
post #166

Earlier quoted context omitted.

she stopped using Wireguard (and ranted about it) rather than stopped using Apple's products (which are ultimately responsible for the failures she complained about in Wireguard)

Right. And Rachelbythebay is way more technically inclined than most users; if she wasn't able to correctly apply the blame to Apple, then normal users are definitely not going to be able to do that. Developers need to be more up-front about why these issues exist, we need an education push. For all the criticism about how Fortnight framed its issues on iOS (and some of that criticism was warranted), coming out of th…

> if she wasn't able to correctly apply the blame to Apple, then normal users are definitely not going to be able to do that

This isn’t a moral judgement. I apply the blame to Apple. But I also choose to keep using their product. Their products are less dispensable to me than another VPN protocol.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#202

Earlier quoted context omitted.

Android is open source.

The builds your phone comes with are not, and replacing them with your own assumes availability of things like unlocked bootloader. And then, of course, applications like your banking won't work, because they require Google SafetyNet attestation for your security .

If your bank decides that your business is worth less to them than a compliance checkmark, that's on them.

All my phones are rooted and it has never been an issue with any banking app I use. It's all about priorities. For some people, that's going to be the roman numeral name suffix dropdown in the registration form. For me it's the bank not telling me what I can do with my devices.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#203
post #113
post #44

The iOS and macOS apps have been the biggest point of stress and frustration when building EteSync[1]. The API is buggy as hell and very limited (if at all available) and the review process is arbitrary and can cause updates to be rejected. You can never know if your workarounds will be accepted or rejected. Sometimes they can even get rejected in future app updates. The EteSync experience is subpar on Apple devices,…

> it's beyond me why would anyone willingly use an Apple product Final users don't see this mess.

Hiya! Former mac native developer here, moving to a new company. My new corp gave me the option of a thinkpad running windows or a Mac, and I chose the mac just so I could have a sane terminal experience, UNIX-like tools, etc.

I would vastly prefer to use Linux, but unfortunately that's just not an option for a company-issued machine at this juncture--and in my experience it's easier to spin up a VM on a Mac than a Windows box.

Being a Mac native dev, I'm very acutely aware of the pain other devs go through with Apple and their APIs, but unfortunately Macs remain a better platform to write code on in my personal experience.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#204
post #131

Earlier quoted context omitted.

Video editors, designers, and sound mixer are a few example professions where users mostly use Apple products. Most companies have designers. Additionally, companies don't choose their whole software stack based on their VPN solution. They would just change a VPN solution if it's incompatible with what's there.

That was 5 years ago. By now, video editors and sound mixers are heavy windows users, because there's no halfway endurable Apple machine that you can purchase that supports 128GB of RAM and 8+ CPU cores and NVIDIA CUDA. Because like it or not, almost all video editing plugins use CUDA for acceleration. https://avid.secure.force.com/pkb/articles/download/Pro-Tool... The industry standard for movie mixing supports: mac…

> video editors and sound mixers are heavy windows users

Source? This is not reflected in any of the studios I know.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#205
post #43

> We faced rejections in submitting the app, because they decided to change their policy on the app having a link in the "About WireGuard" tool window to www.wireguard.com/donations/ (which they previously had allowed explicitly; now they want 30% or something) Last year Google started to ban donation links in FOSS apps, WireGuard was one of the first victims [0], completely removed from the store. I didn't know that…

I couldn't agree more. You're not paying for the app, or the service, those are free and you are simply making a donation. I can imagine that Apple may want to define 'FOSS' to some extent (donations need to go to a non-profit with a board, software needs to be licensed under one of the following licenses, etc), but there should be some room for supporting FOSS that is included in an App Store.

I think Apple/Google see that as a distinction without a difference. You're providing thing, the app, and because of that app and via that app people are giving you money. And since you're not a registered charity they want their pound of flesh.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#206
post #195

Earlier quoted context omitted.

With IPSec native client in MacOS, there are several problems: - multiple users on the same machine cannot have their own credentials for the same tunnel; you have to create several tunnels and each user sees all of them. Obviously, you cannot save password then. - if you want to setup routing for your L2TP split-tunel, you have to create bash scripts (ip-up, ip-down) in /etc/ppp. Not even Linux makes you to do this…

Why L2TP and not IKEv2?

Depends on the other side, too.

Otherwise, a good question for Ubiquity, why they don't support IKEv2 (among other things), when they are using strongswan underneath anyway.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#207
post #21

In case the author is reading this, I recently started using Wireguard in Mac OS with the Mac app and the experience has been great. Not only is it much faster other VPNs that I used in the past, but compared to other clients (Forticlient and Tunnelblick), the overall experience feels much nicer, IMO. Thank you so much for your work!

I wanted to add this. We have had a nearly flawless experience and the macOS app is really nice and polished. It feels like a nice native app, which is rare these days.

However, I've had issues since I upgraded to Big Sur. I can't edit my tunnels anymore.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#208
post #47

First off, what a level-headed friendly response from a developer who is clearly frustrated by Apple's bugs and policies. As someone who has had to support commercial software this is not easy to do consistently. Second, this has significantly tempered my lusting over the new M1 macs. I think I can be content with my ThinkPad's running Linux.

>from a developer who is clearly frustrated by Apple's bugs and policies.

Are there any developers who aren't?

>this has significantly tempered my lusting over the new M1 macs.

What sad is that when it comes to locking down computing devices Apple really is the vanguard of where things are going.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#209

Earlier quoted context omitted.

> We badly need a really-open alternative F-Droid is a thing

For now. When they change that optional setting they introduced recently which blocks sideloading applications outside of the official store and make it non-optional, what are we going to do? Use special Chinese Android builds with Ali store (or whatever it's called)? Boiling the frog slowly and all.

GrapheneOS, on whatever devices have proper security models at the time.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#210

This appears to be a very typical response from an Apple user who doesn't understand the lengths and hoops developers have to jump through to work around Apple's many, many restrictions, bugs and limitations. In my day job, our Apple developers have spent years finding solutions to iOS restrictions around CallKit, Push Notifications and NSTodaysProblem, and those are just the things Apple has intentionally restricted…

>This appears to be a very typical response from an Apple user

Nothing Jason from WireGuard wrote invalidates anything that the original blogger wrote. The Mac App sucks and Jason merely explained why. In other words, both Jason and Rachel are correct.

Post reply on HN