Live data from Hacker News

In-kernel WireGuard is on its way to FreeBSD and the pfSense router

arstechnica.com

11–20 of 167 posts

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#11

Link to relevant announcement email: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649... There's also Jason's reply to apparently not-nice feedback of someone from NetGate: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649...

Wow. Netgate come off as incredibly unprofessional.

According to the article linked and the info here in that email you linked this is my conclusion:

* Netgate tried to ship flawed code that has multiple security issues.

* Jason Donenfeld, one of the lead Wireguard developers, went out of his way to work on rewriting it to be better in time for the 13.0 release of FreeBSD

* This Netgate employee is angry that they weren't able to ship their bad code and starts throwing accusations of a smear campaign.

Am I understanding what happened correctly? Because it really makes this Firewall/Router look really bad.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#12
post #5

PSA: pfSense is closed-source [1]. It was discussed last month here on HN [2]. OPNsense is the equivalent FOSS alternative [3]. [1] https://github.com/rapi3/pfsense-is-closed-source [2] https://news.ycombinator.com/item?id=25894420 [3] https://en.wikipedia.org/wiki/OPNsense

I don't think this is completely accurate, nor is it recent. Their "community edition" is open source and free: https://www.pfsense.org/download/ Also, they have https://github.com/pfsense/

Community Edition will diverge from Pfsense+ with the 2.6 release. They have also made no commitments there will be any releases after that - "it's up to the community".

They will, however, gatekeep what features the community is allowed to add. Community Edition is more or less a dead man walking at this point, they just refuse to come right out and say that.

Someone asked if they'd allow one of the REST API projects to be put into upstream and they gave some ridiculous answer about how they'd review any commit but alluded to the fact they won't actually accept it. Because what would they do if the maintainer left? Their suggestion was to fork it. Which, ironically, is exactly what OPNsense did and then Jim Thompson acted like a misbehaving 6 year old and created a website trying to bash them and didn't even have the spine to own up to it until there was a court order.

https://opnsense.org/opnsense-com/

I'm not sure why ANYONE would waste any effort on adding anything to pfsense at this point when they won't actually commit to accepting features upstream that competes with PFsense+.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#13
post #12
post #5

Earlier quoted context omitted.

I don't think this is completely accurate, nor is it recent. Their "community edition" is open source and free: https://www.pfsense.org/download/ Also, they have https://github.com/pfsense/

Community Edition will diverge from Pfsense+ with the 2.6 release. They have also made no commitments there will be any releases after that - "it's up to the community". They will, however, gatekeep what features the community is allowed to add. Community Edition is more or less a dead man walking at this point, they just refuse to come right out and say that. Someone asked if they'd allow one of the REST API project…

I've been on the wrong end of the Netgate brigade/shills/apologists before due to a few blog entries, and it's not fun.

I'm just glad others are seeing the darker side of them.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#14

PSA: pfSense is closed-source [1]. It was discussed last month here on HN [2]. OPNsense is the equivalent FOSS alternative [3]. [1] https://github.com/rapi3/pfsense-is-closed-source [2] https://news.ycombinator.com/item?id=25894420 [3] https://en.wikipedia.org/wiki/OPNsense

The dramas [0] between PFSense, OPNsense, and IPFire [1] always seems to come up.

I ended up going with PFSense and it works fine. It's open enough that you can always dive in to figure out what's going on. Perhaps philosophically suboptimal, but for all practical purposes it's worked great for my home!

[0] https://www.reddit.com/r/homelab/comments/dg2wme/opnsense_vs...

[1] https://www.ipfire.org/

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#15

I've been waiting for pfSense+Wireguard for a while. OpenVPN has been very good to me but I'm psyched to trade up.

pfSense has the only friendly admin GUI for OpenVPN that I know of, besides the proprietary Access Server. Will they do the same for Wireguard?

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#16

Link to relevant announcement email: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649... There's also Jason's reply to apparently not-nice feedback of someone from NetGate: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649...

Netgate is weirdly hostile to a lot of opensource stuff, which should be strange given what all their tech is built on top of. This has been going on for years. (see opnsense etc)

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#17

PSA: pfSense is closed-source [1]. It was discussed last month here on HN [2]. OPNsense is the equivalent FOSS alternative [3]. [1] https://github.com/rapi3/pfsense-is-closed-source [2] https://news.ycombinator.com/item?id=25894420 [3] https://en.wikipedia.org/wiki/OPNsense

The shade I occasionally see thrown toward pfSense is curious to me. This isn't push-back at the parent comment but me expressing a bit of confusion.

I've used pfSense since 2009 or so. I was skeptical when Netgate entered the picture but since I've had no reason to complain. It's been a continuous and usually smooth timeline of serving me well.

A relevant sidebar is that I've been part of different, stellar volunteer efforts - started by a core team that was trying to improve or fix something worthwhile. It is inevitable that core teams members will eventually run low on time/energy and changes must follow. Those changes can be anything and usually are.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#18
post #16

Link to relevant announcement email: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649... There's also Jason's reply to apparently not-nice feedback of someone from NetGate: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649...

Netgate is weirdly hostile to a lot of opensource stuff, which should be strange given what all their tech is built on top of. This has been going on for years. (see opnsense etc)

Netgate funds a lot of FreeBSD work, and employs FreeBSD committers. I certainly wouldn't describe them as hostile to open source.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#19

I've been waiting for pfSense+Wireguard for a while. OpenVPN has been very good to me but I'm psyched to trade up.

The opnsense fork has supported wireguard for a while, and has far less restrictive licensing. I highly recommend having a look.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#20

PSA: pfSense is closed-source [1]. It was discussed last month here on HN [2]. OPNsense is the equivalent FOSS alternative [3]. [1] https://github.com/rapi3/pfsense-is-closed-source [2] https://news.ycombinator.com/item?id=25894420 [3] https://en.wikipedia.org/wiki/OPNsense

Woah, I have been using pfsense for quite a while but never knew it was closed source until now.
Post reply on HN