Live data from Hacker News

In-kernel WireGuard is on its way to FreeBSD and the pfSense router

arstechnica.com

101–110 of 167 posts

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#101
post #16

Link to relevant announcement email: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649... There's also Jason's reply to apparently not-nice feedback of someone from NetGate: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649...

Netgate is weirdly hostile to a lot of opensource stuff, which should be strange given what all their tech is built on top of. This has been going on for years. (see opnsense etc)

I was about to buy a netgate router when I read the background of everything here on HN.

Basically, all the opensource claims don't amount to a hill of beans, because you cannot compile pfsense yourself, even for their hardware.

(I'm sure someone could come up with the link)

The firewall should be the ONE place where this would be critical. You have to run their binary.

I also think it phones home.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#102

Earlier quoted context omitted.

The opnsense fork has supported wireguard for a while, and has far less restrictive licensing. I highly recommend having a look.

Only if BBCan177 jumps ship. He's my hero.

Assuming you're referring to pfblockerng, you can have DNS blocking and IP blocking in OPNsense without the need for any plugins.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#103

Link to relevant announcement email: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649... There's also Jason's reply to apparently not-nice feedback of someone from NetGate: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649...

The patch, showing the fixes made:

https://cgit.freebsd.org/src/commit/?id=74ae3f3e33b810248da1...

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#104
post #97
post #55

Earlier quoted context omitted.

I did LOTS of research on what firewall/router distro to install to my new router a few months ago. See my comment history for considering different options. I have to say choosing OPNsense has been a great choice. All the things you said I can agree on, but I have to add one more thing: That quick search bar on the top-right corner where you can quickly type where you want to go. That thing is just super nice when j…

Same here but I've concluded that there is nothing better than a simple install of pure OpenBSD or FreeBSD and setting the rules on /etc/pf.conf. Its safer, faster, lighter and I could argue that is also easier to admin with just SSH and no web code in between. For example, in the latest version of OpenBSD which has a Wireguard kernel implementation, the management tool has been basically included in the ifconfig com…

Agree. I run openbsd, its simple.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#105
post #28
post #11

Earlier quoted context omitted.

Wow. Netgate come off as incredibly unprofessional. According to the article linked and the info here in that email you linked this is my conclusion: * Netgate tried to ship flawed code that has multiple security issues. * Jason Donenfeld, one of the lead Wireguard developers, went out of his way to work on rewriting it to be better in time for the 13.0 release of FreeBSD * This Netgate employee is angry that they we…

That was my impression too, then I went back a couple prior messages, and looked at the earlier announcement. Wihle Netgate looks to have overreacted (at least from the info we have), I can understand why they would be upset. This was in the original announcement: The first step was assessing the current state of the code the previous developer had dumped into the tree. It was not pretty. I imagined strange Internet…

Reminded me of the type of statements he made last year on another set of mailing lists:

https://news.ycombinator.com/item?id=24430424

https://mail-index.netbsd.org/tech-net/2020/08/22/msg007842....

https://mail-index.NetBSD.org/current-users/2020/08/22/msg03...

https://mail-index.NetBSD.org/tech-kern/2020/08/23/msg026693...

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#106

Earlier quoted context omitted.

> However, you are directing your disdain (about pfSense) toward us. I don't think I am; who's us in that sentence? > To what end? What is it you want to achieve? I'm scratching an itch. If Netgate can screw the community that helped pfSense gain popularity then surely it is perfectly acceptable for a member of that community to express a little disdain.

> who's us in that sentence? Everyone in this thread. > it is perfectly acceptable for a member of that community to express a little disdain. Okay. I never inferred otherwise. If venting is the total of your goal here are you okay we blow that off or is there something else you're hoping for? To be clear, I've no animosity toward your posts. My 'hidden' agenda is this: Because hostility takes a toll on the recipient…

> To be clear, I've no animosity toward your posts.

No worries, no animosity assumed.

> If venting is the total of your goal here are you okay we blow that off or is there something else you're hoping for?

I don't like venting. I said I was scratching an itch but venting makes it sound like it had no substance at all and suggests what Netgate did was alright. To be clear, I think the more Netgate gets criticized and called out the better. But I had no hopes beyond that.

> My 'hidden' agenda is this: Because hostility takes a toll on the recipients (us) ...

Putting aside that I'm not completely on board with the hostility characterization either, you're recipients of it only in the sense that you happened to read it. I disagree with you about the degree to which Netgate deserves the criticism of course, but none of the "hostility" was addressed to you or anyone else in this thread.

It shouldn't be taxing. It's pick-me-up to anyone who's read one too many overly positive comments about the pfSense Plus shenanigans.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#107

Scott Long from Netgate's response: https://www.netgate.com/blog/painful-lessons-learned-in-secu... "Unfortunately, the public discussion has also veered into vague claims and slanderous attacks. This is where the lack of transparency, the lack of respect, and the inflation of ego is damaging and unproductive. We had hoped for a better collaboration than this, and it makes me doubt the motives of the attackers. And y…

I think this... pretty much speaks for itself. Wow.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#108

Scott Long from Netgate's response: https://www.netgate.com/blog/painful-lessons-learned-in-secu... "Unfortunately, the public discussion has also veered into vague claims and slanderous attacks. This is where the lack of transparency, the lack of respect, and the inflation of ego is damaging and unproductive. We had hoped for a better collaboration than this, and it makes me doubt the motives of the attackers. And y…

Wow. I'm a complete outsider to this, not using FreeBSD or pfSense or Wireguard - but this blog post makes Netgate seem incredibly unprofessional. Especially to anyone who actually read the mailing list exchanges.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#109

Scott Long from Netgate's response: https://www.netgate.com/blog/painful-lessons-learned-in-secu... "Unfortunately, the public discussion has also veered into vague claims and slanderous attacks. This is where the lack of transparency, the lack of respect, and the inflation of ego is damaging and unproductive. We had hoped for a better collaboration than this, and it makes me doubt the motives of the attackers. And y…

Wow. I'm a complete outsider to this, not using FreeBSD or pfSense or Wireguard - but this blog post makes Netgate seem incredibly unprofessional. Especially to anyone who actually read the mailing list exchanges.

It is not great.

I think this is all pretty much over now, right? FreeBSD is pulling back from a kernel WireGuard I think everyone agrees wasn't ready for prime time in mainline FreeBSD, and everyone's working getting it ready for a future release.

I don't really understand what pfSense had to gain from a post like this, but, it's their blog.

Re: In-kernel WireGuard is on its way to FreeBSD and the pfSense router

#110
post #90
post #74

Earlier quoted context omitted.

> It's not an elaborate insult. My read on it wasn't that it was an elaborate insult, but more that it was far more denigrating than it needed to be, if he was trying to be professional. That doesn't mean it was purposeful, sometimes people just don't really associate the statements they make with how it may be perceived. I think it could have been communicated clearly and succinctly with something along the lines of…

I get your point about perceptions, but there's also another aspect of why I found it important and necessary to describe just how poor the code was: When you're talking about replacing and rewriting the implementation on the eve of release, you better have a good reason for doing so. Stuffing a rewrite of security critical code into the kernel at the last minute is a big red flag. The main question that immediately…

You did good, Jason. Honestly after this streissand effect from them taking technical criticism personally and threatening you, I'm probably just going to avoid anything using code they might have written... that's on them. Responding to a perceived non-professionalism by talking like that to you -- from their COMPANY EMAIL at that? If I were their boss I'd definitely start making some considerations regarding the irony of this.
Post reply on HN