Live data from Hacker News

TunSafe WireGuard Client for OS X

tunsafe.com

11–20 of 48 posts

Re: TunSafe WireGuard Client for OS X

#11
post #10

Is there by any chance a speed comparison against IPSec (IKEv2) i.e. strongSwan with AES-NI? I haven’t used OpenVPN in many years, so such a comparison would be much more interesting.

From experience I can tell you that IPSec is much faster than OpenVPN.

I have no issues getting Gbit over IPSec (Strongswan), but with OpenVPN I always maxed out around ~400Mbit.

EDIT: Looks like I misunderstood your comment and it seems like you want a comparison to Wireguard... oops

Re: TunSafe WireGuard Client for OS X

#12
post #9

Previous HN discussion on TunSafe from earlier this week: https://news.ycombinator.com/item?id=16515637

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

Re: TunSafe WireGuard Client for OS X

#14
post #10

Is there by any chance a speed comparison against IPSec (IKEv2) i.e. strongSwan with AES-NI? I haven’t used OpenVPN in many years, so such a comparison would be much more interesting.

It's extremely fast, the benchmarks I've seen show that it's even faster than the IPSec config you describe.

Re: TunSafe WireGuard Client for OS X

#15
post #9

Previous HN discussion on TunSafe from earlier this week: https://news.ycombinator.com/item?id=16515637

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

Did it put you off using openssh/openvpn/libressl/etc? Is there the Torvalds effect? Let maintainers express their discontent in the form they prefer.

I see how @zx2c4 might be concerned about possible reputation risks due to the release of this closed-source implementation at the earliest WireGuard stage. Given that the author of TunSafe is not a security expert. Especially if (suddenly) TunSafe turns out to have security flaws, right before the WireGuard team releases an official open-sourced implementation. However, WG is an open protocol, and @ludde has the right to develop and sell whatever he wants on its basis.

Re: TunSafe WireGuard Client for OS X

#16
post #9

Previous HN discussion on TunSafe from earlier this week: https://news.ycombinator.com/item?id=16515637

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

Same here. I was planning on using WG for personal infra and was actively routing for it in a corp environment, but his attitude has put me off. I'm sticking with OpenVPN for the time being.

I use viscosity as my openvpn client on macs. I love Viscosity and was planning on asking them to support WG. Not anymore though... The author seems to be stuck in a past where closed source vs open source was a binary decision. We've gone past that point in history.

It's one thing to say "I can't or won't vet a closed source client, so I can't officially support it" and another to actively advise against it.

On the other had TunSafe could hire a well-known third party agency to go through the source and vet the agency for security holes. That would add back and credibility taken away by the way the author responded. Since the project is open-source, if I had the resources, I might go as far as pay the same agency to vet both close-source client and the open source server implementation... But we're not talking about Cisco/Juniper/Major-Vendor here, so I don't see that happening.

@ptacek (or anyone else working on this space) how much would it cost to vet wireguard for security holes? Is there a standard way of charging (e.g. per lines of code) or depends on multiple variables? ps. Asking ptacek because of his prev comments [1].

[1]: https://news.ycombinator.com/item?id=14598639

Re: TunSafe WireGuard Client for OS X

#18
post #15

Earlier quoted context omitted.

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

Did it put you off using openssh/openvpn/libressl/etc? Is there the Torvalds effect? Let maintainers express their discontent in the form they prefer. I see how @zx2c4 might be concerned about possible reputation risks due to the release of this closed-source implementation at the earliest WireGuard stage. Given that the author of TunSafe is not a security expert. Especially if (suddenly) TunSafe turns out to have se…

I'd say the author comes across as immature, which is kind of a bad look if you are making security software.

Re: TunSafe WireGuard Client for OS X

#19
post #16

Earlier quoted context omitted.

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

Same here. I was planning on using WG for personal infra and was actively routing for it in a corp environment, but his attitude has put me off. I'm sticking with OpenVPN for the time being. I use viscosity as my openvpn client on macs. I love Viscosity and was planning on asking them to support WG. Not anymore though... The author seems to be stuck in a past where closed source vs open source was a binary decision.…

> @ptacek (or anyone else working on this space) how much would it cost to vet wireguard for security holes?

You may be interested in @ptacek's response on this matter a while back[1].

[1] https://news.ycombinator.com/item?id=16327350

Re: TunSafe WireGuard Client for OS X

#20
post #17

Here is some discussion about tunsafe. https://lists.zx2c4.com/pipermail/wireguard/2018-March/00244...

That's not a "discussion", but a nasty spiteful post full of extreme, but baseless allegations.

That's not the whole story. There are further responses in that thread, including the opposing viewpoint from the TunSafe author.

* https://lists.zx2c4.com/pipermail/wireguard/2018-March/00246...

* https://lists.zx2c4.com/pipermail/wireguard/2018-March/00246...

are the most relevant ones. (There are more, but they go slightly offtopic.)

Post reply on HN