Live data from Hacker News

Response to “WireGuard: great protocol, but skip the Mac app”

lists.zx2c4.com

171–180 of 392 posts

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#171
post #10

Earlier quoted context omitted.

> This appears to be a very typical response from an Apple user who doesn't understand the lengths and hoops developers have to jump through to work around Apple's many, many restrictions, bugs and limitations. Eh? Isn't that a description of the original complaint, and the 'a response' submitted here is from WireGuard creator/lead Jason/zx2c4 explaining much as you do the restrictions, bugs, and limitations he's tri…

Apologies, I indeed meant the original post to which Jason was responding. By "response" I meant the response of the user to the WireGuard Mac app. Again apologies, I somehow jumped a few mental hoops of my own when commenting.

Ah, but the original post, which triggered the uninformed ranting against WireGuard, was not itself from someone who was ignorant of the lengths and hoops developers have to jump through to work around Apple's many, many restrictions. Furthermore, its author outlined how to work around the problems with the app by using Macports instead.

What about the problems? Well, it's free. They owe me nothing. But, you should still be aware what you are getting into when you choose to [use the app]. That's why I wrote this post: to serve as a warning to others. Let my frustration save you the same in the future.

When it comes to WireGuard, just stick with the tried and true low-level Unix approach, even on your Macs. Your sanity will thank you.

I just hope the iOS version never flips out on me.

Anyone who has a problem with that state of affairs has a beef with Apple, and should not be posting their displeasure to the WireGuard mailing list.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#172
post #44

The iOS and macOS apps have been the biggest point of stress and frustration when building EteSync[1]. The API is buggy as hell and very limited (if at all available) and the review process is arbitrary and can cause updates to be rejected. You can never know if your workarounds will be accepted or rejected. Sometimes they can even get rejected in future app updates. The EteSync experience is subpar on Apple devices,…

"it's beyond me why would anyone willingly use an Apple product" With respect, then, you aren't making much of an effort to understand.

I have an iPhone and macOS for development. I clocked a lot of hours on them over the years.

I admit, I was sometimes jealous of mac hardware, for example the new M1, magsafe, and etc (though not the terrible keyboards). Though I was never jealous of an iPhone's hardware. I was never ever jealous of the software. I always found it buggy and user-hostile.

The line you quoted was specifically about the user-hostility. You are using a machine that you can't control and actively fights you. It's mind boggling to me that developers agree to use such a system. Is this such an unreasonable opinion?

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#173
post #17

This is a response to the Rachel by the bay blog post https://rachelbythebay.com/w/2020/12/24/wg/ Personally I rarely use a mac, and don't do wg on demand, but one thing that did annoy me was being unable to set dns search domain, which wasn't mentioned in the blog post, but I believe is also caused by OSX deficiencies.

DNS search in MacOS is managed by their DNS infrastructure which is documented under resolver(5).

That lets you route the resolution of particular domains to specified nameservers. The files live in /etc/resolver but can also be manipulated with scutil.

So it's not an OSX deficiency, it's an OSX difference, similar to launchd vs systemd.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#174

Earlier quoted context omitted.

Is it? Anyhow, it does not mean that it is illegal, which was the original question. I guess most ToS are not enforceable in practice. The worst that may happen is that you "lose the warranty" of your macOS install and you cannot ask Apple for support. No big deal.

So I'm not an expert, but isn't it still simply pirating software? I mean what's the difference between this and pirating Photoshop for example?

Adobe sells Photoshop, Apple does not sell macOS (and freely publishes download links for the latter.)

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#175
post #44

The iOS and macOS apps have been the biggest point of stress and frustration when building EteSync[1]. The API is buggy as hell and very limited (if at all available) and the review process is arbitrary and can cause updates to be rejected. You can never know if your workarounds will be accepted or rejected. Sometimes they can even get rejected in future app updates. The EteSync experience is subpar on Apple devices,…

This sums up my experience developing on macOS as well. Apple forces you to use broken API's and then you have to find workarounds to make your app usable.

Someone should start an Apple developer support group on appledevsupport.group or something and get users to upvote broken API's (and broken terms of service: like mentioning donations are accepted in a free app!) that need fixing. Getting enough developers in one place to embarrass them might be the only way to make Apple care.

Filing onerous radar reports to help Apple is not my job.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#176

> We faced rejections in submitting the app, because they decided to change their policy on the app having a link in the "About WireGuard" tool window to www.wireguard.com/donations/ (which they previously had allowed explicitly; now they want 30% or something) Last year Google started to ban donation links in FOSS apps, WireGuard was one of the first victims [0], completely removed from the store. I didn't know that…

As a Russian movie quote goes, [after someone disapproves of a pair of boots] "Aha, so the boots are good, gotta buy them".

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#177
post #111
post #88

Earlier quoted context omitted.

IANAL - but I'm pretty sure the app platforms are breaking many laws here, not allowing people to freely donate. Like free speech, able to ask for help, freedom to do business, abuse of monopoly. They might be able to get away with a transaction fee, and a store fee, but they should not be able to censor text, links, etc. This is the new Mafia. If you don't play by their rules (theirs, not the law) your business dies…

Yes, you are obviously NAL. The rules are clear and are applied evenly; it is the even application of the rule that is causing the problem here. FOSS-advocates think they are special snowflakes who deserve an exception to the rule about asking for payment. The app stores (both Apple and Google) clearly disagree and think that this is something that will be easily gamed and abused. Nothing is preventing these apps fro…

The Apple guidelines clearly state that donations through Safari are allowed. Nobody's being a special snowflake here, much to your chagrin I'm sure.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#178
post #121
post #43

Earlier quoted context omitted.

I couldn't agree more. You're not paying for the app, or the service, those are free and you are simply making a donation. I can imagine that Apple may want to define 'FOSS' to some extent (donations need to go to a non-profit with a board, software needs to be licensed under one of the following licenses, etc), but there should be some room for supporting FOSS that is included in an App Store.

> Apple may want to define 'FOSS' to some extent "The stuff we won't pay for, but will make other people pay for, even tho we did nothing for it"

"... therefore we should take our cut."

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#179
App Store gatekeeping needs to burn. It may be helpful for the tech-illiterate who want simple and safe apps, but it's not a viable for a healthy ecosystem of broad ranging applications. It's crazy to think I can't install an app from a developer I trust from their website.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#180
post #166

Earlier quoted context omitted.

But it seems they do, eg. rachelbythebay stopped using Wireguard because of the mess.

she stopped using Wireguard (and ranted about it) rather than stopped using Apple's products (which are ultimately responsible for the failures she complained about in Wireguard)

Right. And Rachelbythebay is way more technically inclined than most users; if she wasn't able to correctly apply the blame to Apple, then normal users are definitely not going to be able to do that. Developers need to be more up-front about why these issues exist, we need an education push.

For all the criticism about how Fortnight framed its issues on iOS (and some of that criticism was warranted), coming out of the gate strong with a consistent message that Apple was to blame was likely the only way to get any 'normal' user to even consider that there were multiple issues and viewpoints at play. There's no such thing as subtlety or nuance when you're trying to talk to that demographic about why their phone/desktop doesn't do the thing they want it to do.

In the long term, I don't know. On one hand, these issues do affect final users, but communicating with final Mac users is difficult.

But on the other hand, Wireguard isn't going away, it's a clearly better protocol. So right now, final Mac users assume it's the devs' fault. But are they going to assume that when literally everyone around them has decent VPN clients and their Mac experience is just miserable? Mac users aren't completely isolated from the Linux/Windows world, at some point they're going to realize the pattern if all of the software on their platform is just worse.

Post reply on HN