Live data from Hacker News

In-kernel WireGuard is on its way to FreeBSD and the pfSense router

arstechnica.com

71–80 of 167 posts

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#71

is there any linux equivalent of pfsense+freebsd ?

OpenWrt? I'd be interested to know what the differences are.

OpenWrt is more of a replacement for the market routers. It's a nice Linux-based router distro with a good/great ui in LuCI. The downside of this is that upgrading OpenWRT is a bit similar than upgrading a closed-source OS of the consumer routers: you flash it and you must reinstall all packages after the upgrade. This means an upgrade between major versions is maybe a bit too much of work.

OPNsense/pfSense have similar upgrade strategies as FreeBSD has: you upgrade the core os to the latest version, then all ports. This is usually a really simple and kind of boring system, which is something you really value in a computer that manages your whole house's internet traffic...

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#72
post #57

Earlier quoted context omitted.

Keep in mind, back in February of 2020 when Kip Macy first announced that Netgate had hired him to port Wireguard, Jason offered to help. First Kip declines the offer, then seems to warm slightly to it, but ultimately appears to have not actually engaged Jason. If I'm Jason and I offer my help (for free), they don't take me up on my offer, then try to release code that would make my baby look quite ugly, I would prob…

"Kip Macy" don't you mean Matt Macy ?

There's not a good way for me to respond to that without going off-topic. The following is assuming that wasn't a rhetorical question, if it was rhetorical I guess we may just agree to disagree:

Until he issues a public apology for his actions, I'll refer to him as Kip. Changing your name to run from the google searches is completely understandable, and I support second chances, but you need to show a bit of remorse IMO.

https://abcnews.go.com/US/exclusive-landlord-hell-defends-te...

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#73
post #57

Earlier quoted context omitted.

Keep in mind, back in February of 2020 when Kip Macy first announced that Netgate had hired him to port Wireguard, Jason offered to help. First Kip declines the offer, then seems to warm slightly to it, but ultimately appears to have not actually engaged Jason. If I'm Jason and I offer my help (for free), they don't take me up on my offer, then try to release code that would make my baby look quite ugly, I would prob…

Sounds like Jason should trademark Wireguard (the name). Or build an alternative brand. That way Netgate's actions, or the actions of other wireguard implementations, will not reflect on the reputation of his project/product/technology.

He did trademark the name. I don't think Jason is going to tell the FreeBSD project that they can't use the name "wireguard" for their implementation of "wireguard" just because Netgate put out shoddy code. It's not the FreeBSD project's fault.

https://www.wireguard.com/trademark-policy/

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#74
post #67
post #61

Earlier quoted context omitted.

Yeah, same. Even if all of the above is true, it reads like an elaborate insult. And that's fine if that what the author set out to do for some reason. Pretending it wasn't after the fact isn't being honest, in my opinion. A more professional and neutral announcement could just talk about code that needs to be refactored due to some incompleteness and vulnerabilities.

It's not an elaborate insult. To a much greater extent than in other security protocols, implementation security is a goal of WireGuard. The protocol itself was designed to support secure kernel implementations; for instance, it's designed in such a way as to not require on-demand dynamic memory allocation. It's part of the premise of the security model of WireGuard that it has secure kernel implementations. If you'r…

> It's not an elaborate insult.

My read on it wasn't that it was an elaborate insult, but more that it was far more denigrating than it needed to be, if he was trying to be professional. That doesn't mean it was purposeful, sometimes people just don't really associate the statements they make with how it may be perceived.

I think it could have been communicated clearly and succinctly with something along the lines of: "The first step was assessing the current state of the code the previous developer had dumped into the tree. We noticed some quality problems, some unimplemented protocol sections and more concerning, security issues with the code. Given these issues, we considered asking they remove the code, but instead Matt convinced me that we should rework it slowly and carefully for the next release cycle."

Notably, I think omission of the following inflammatory statements would have prevented a lot of problems:

- "It was not pretty."

- "I imagined strange Internet voices jeering, “this is what gives C a bad name!”"

- "the most spectacular buffer overflows"

- "the whole litany of awful things that go wrong when people aren’t careful when they write C."

Whether those entirely subjective statements are accurate, they are not the things you say about someone else's work output when you expect a useful dialogue with them, which is exactly why they are considered unprofessional.

I'm not defending Netgate's code here, or even the vehemence of their reaction and how they went about it, but merely noting that not only can I see how it devolved into this, I would go so far as to say it's obvious that this is why that type of language is avoided by most people trying to work professionally. Jason wrote some very unkind things, and Netgate blew up about it. There's enough blame here that they can both share some.

> The "ask" here from Jason was for everyone to slow their roll, take the flawed WireGuard implementation out of the tree, and give everyone a chance to make it more resilient. Considering the amount of work Jason had to go through to get WireGuard into the Linux tree, that seems like a very reasonable request.

Err, wasn't that actually not the ask, because he thought they wouldn't do so, so instead they worked it over in a short time-frame, only for it then to be removed when this argument broke out and it came to light?

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#75
post #58
post #42

Earlier quoted context omitted.

Similar reaction here. My first impression was Netgate being an arse. But then when you read the announcement I kind of understand why Scott is angry. Because while the post may have been in "good faith" in an Open Development and Open Source world, it surely isn't in a professional and business world especially when the work is sponsored ( being paid ). Jason should have informed Netgate the quality of the code is s…

> it surely isn't in a professional and business world especially when the work is sponsored ( being paid ). To play devil's advocate: Netgate isn't paying Jason, and they're taking his open source code to create a proprietary commercial project. I'd say Jason owes them exactly nothing in the way of courtesy or consideration. Could he have been more polite for the sake of being polite and community goodwill? Probably…

>and they're taking his open source code to create a proprietary commercial project.

I am not sure if that is the case. Netgate seems to have used their old crappy sponsored work for their Pfsense.

That is judging from the two pieces of information here. Jason doesn't need to be of consideration for Netgate. There could be other communication we dont know about. I can certainly understand why Scott is frustrated.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#76

Earlier quoted context omitted.

The shade I occasionally see thrown toward pfSense is curious to me. This isn't push-back at the parent comment but me expressing a bit of confusion. I've used pfSense since 2009 or so. I was skeptical when Netgate entered the picture but since I've had no reason to complain. It's been a continuous and usually smooth timeline of serving me well. A relevant sidebar is that I've been part of different, stellar voluntee…

> The shade I occasionally see thrown toward pfSense is curious to me. Every last bit of it is deserved. They made a promise to keep pfSense open source and they broke it as soon as they could. I see them hiding behind it's the newly announced pfSense Plus that is closed source, not pfSense CE and it's pure weaseling. I still use pfSense but I feel bad for ever being excited about it and contributing to their popular…

I'm not sure that over 10 years later is "as soon as they could". NetGate has made a huge number of open source releases, and while they have not held exactly to the platonic ideal of open source (literally every bit on the disc comes from an open repo) I think we can all agree that the vast majority of the existing CE code remains open. I also think that they get a lot of shade because some of their developers have been some of the loudest jerks in open source.

In my opinion, at the moment we have Schrodinger's open source: in the box there's a future pfSense CE which is well-maintained but differentiated from their commercial offering of pfSense Plus, and there's a pfSense CE which languishes from a lack of new features and slowly accrues an ever-larger trail of closed-won't-fix bugs.

At this time, which future will develop is anyone's guess; I suspect even NetGate don't really know. Even if they're planning on effectively abandoning CE in place, a backlash in the community could cause that to reverse.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#77
post #72

Earlier quoted context omitted.

"Kip Macy" don't you mean Matt Macy ?

There's not a good way for me to respond to that without going off-topic. The following is assuming that wasn't a rhetorical question, if it was rhetorical I guess we may just agree to disagree: Until he issues a public apology for his actions, I'll refer to him as Kip. Changing your name to run from the google searches is completely understandable, and I support second chances, but you need to show a bit of remorse…

I don't really think that the 'online mob' has the right to hold someone's past actions over their head, and expect some public appeasement before it relents.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#78

Im confused, pfsense 2.5 is out and has wireguard support. Is that version full holes I should be aware off?

Yes. The code you're running is described as having "random sleeps added to “fix” race conditions, validation functions that just returned true, catastrophic cryptographic vulnerabilities, whole parts of the protocol unimplemented, kernel panics, security bypasses, overflows, random printf statements deep in crypto code, the most spectacular buffer overflows" This is a kernel RCE just waiting to happen.

Anyone who wants to be able to throw some crypto CVEs on their resume could do worse than spending some quality time with this code.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#79
post #74
post #67

Earlier quoted context omitted.

It's not an elaborate insult. To a much greater extent than in other security protocols, implementation security is a goal of WireGuard. The protocol itself was designed to support secure kernel implementations; for instance, it's designed in such a way as to not require on-demand dynamic memory allocation. It's part of the premise of the security model of WireGuard that it has secure kernel implementations. If you'r…

> It's not an elaborate insult. My read on it wasn't that it was an elaborate insult, but more that it was far more denigrating than it needed to be, if he was trying to be professional. That doesn't mean it was purposeful, sometimes people just don't really associate the statements they make with how it may be perceived. I think it could have been communicated clearly and succinctly with something along the lines of…

Sure, but it's easy to clinically examine any communication and refine it with the benefit of both hindsight and low cortisol levels. My read of this situation is that everyone involved was stuck in a shitty situation; it got very briefly heated, and ended up where it should have: with another dev cycle to iterate on FreeBSD WireGuard.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#80

is there any linux equivalent of pfsense+freebsd ?

openwrt works well enough for routing, qos, adblock, vpn, etc.

So what does people typically use pfSense/OPNsense for which OpenWRT can’t do, or is a bad fit for?

Asking as a curious OpenWRT devotee.

Post reply on HN