Live data from Hacker News

Response to “WireGuard: great protocol, but skip the Mac app”

lists.zx2c4.com

181–190 of 392 posts

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#181
post #67
post #21

In case the author is reading this, I recently started using Wireguard in Mac OS with the Mac app and the experience has been great. Not only is it much faster other VPNs that I used in the past, but compared to other clients (Forticlient and Tunnelblick), the overall experience feels much nicer, IMO. Thank you so much for your work!

> Not only is it much faster other VPNs IPSec is as fast as Wireguard. And there is native client in MacOS. As for bloated codebase, there is an OpenBSD iked rewrite.

With IPSec native client in MacOS, there are several problems:

- multiple users on the same machine cannot have their own credentials for the same tunnel; you have to create several tunnels and each user sees all of them. Obviously, you cannot save password then.

- if you want to setup routing for your L2TP split-tunel, you have to create bash scripts (ip-up, ip-down) in /etc/ppp. Not even Linux makes you to do this by hand.

Compared to this, Wireguard for Mac is much more polished.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#182
post #123
post #67

Earlier quoted context omitted.

> Not only is it much faster other VPNs IPSec is as fast as Wireguard. And there is native client in MacOS. As for bloated codebase, there is an OpenBSD iked rewrite.

Doesn't IPSec need a "clean" network connection, without any NAT in the middle? Wireguard was designed to work well even in the presence of NAT.

If you enable UDP encapsulation, it will work over NAT.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#183

Couldn’t you just change the url to /about instead of /donations? Seems sort of the thing sketchy sites do to say one thing and link to another. If I want to donate to a project I want to browse the site and learn more about rather than straight to the donation page. Seems like a money grab to take me to the donation page.

> Seems sort of the thing sketchy sites do to say one thing and link to another. There is no misleading link. It's only a "Donation" button on the About window that opens a hyperlink, similar to this one [0]. How is it supposed to be a money grab? TBH, I don't think anyone ever bother to click it to begin with... [0] https://pbs.twimg.com/media/EnhRYTTXMAEW9TX?format=jpg

Yeah, I am willing to admit it was a loose interpretation of "sketchy" but it was that it's titled "About WireGuard" then takes you to a donation page that I was thinking about. Why not just call it "Donate to WireGuard" or link it to an /about page. You could have donation information on the about page in addition to information about WireGuard.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#184

As a Mac admin VPP/App Store distribution is still quite finicky. I don’t understand why Apple has to flex and restrict NetworkExtension/VPN apps to Mac App Store. More iOS-ification of the OS.

And the funny thing is, that Cisco Anyconnect (now comes with NetworkExtension!) is not in Mac App Store.

One rule for small, other rule for big.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#185
post #161
post #143

Earlier quoted context omitted.

I have certainly heard of apps removing all links to their website because Apple reviewers have followed a help/feedback link, gotten to their main website, and then found purchase/donation links there and rejected the review.

Any references for this? I have only heard of this happening when the page is clearly for donations (like this case) or almost exclusively composed of 'give us money' content.

https://news.ycombinator.com/item?id=24192021

1. App links to developer's blog. At one point the top post is about their patreon. Apple removes app until post is amended.

2. Also apparently the bandcamp app has no links to their website, for the same reason.

https://news.ycombinator.com/item?id=19378914

Amazon Kindle app could not link to amazon.com as users could purchase books there without giving apple their cut

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#186
post #44

The iOS and macOS apps have been the biggest point of stress and frustration when building EteSync[1]. The API is buggy as hell and very limited (if at all available) and the review process is arbitrary and can cause updates to be rejected. You can never know if your workarounds will be accepted or rejected. Sometimes they can even get rejected in future app updates. The EteSync experience is subpar on Apple devices,…

This sums up my experience developing on macOS as well. Apple forces you to use broken API's and then you have to find workarounds to make your app usable. Someone should start an Apple developer support group on appledevsupport.group or something and get users to upvote broken API's (and broken terms of service: like mentioning donations are accepted in a free app!) that need fixing. Getting enough developers in one…

I don't think I've ever run into a "broken" API on MacOS.

But I haven't seen a "well documented" one either. There's a lot of arcane knowledge in targeting MacOS.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#187
post #22

This appears to be a very typical response from an Apple user who doesn't understand the lengths and hoops developers have to jump through to work around Apple's many, many restrictions, bugs and limitations. In my day job, our Apple developers have spent years finding solutions to iOS restrictions around CallKit, Push Notifications and NSTodaysProblem, and those are just the things Apple has intentionally restricted…

I love Jason’s response and think it carries the right tone and is delivered near flawlessly. It’s clearly frustrating to deal with Apple’s platform lockdown, and he captures such in a professional and rational manner. Bravo. What bothers me is that I’ve experienced an increasing number of maintainers of supposed cross platform projects simply not care about macOS anymore to the extent that they’re openly hostile tow…

"Cross-platform" is not a promise that it will work on every platform, and saying that to be cross-platform without that including MacOS is "hostile towards MacOS users" is unreasonable. The most you can reasonably hope for, in something you can get for free, is that if it says it works on a given platform, then it is reasonably functional there.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#188

> We faced rejections in submitting the app, because they decided to change their policy on the app having a link in the "About WireGuard" tool window to www.wireguard.com/donations/ (which they previously had allowed explicitly; now they want 30% or something) Last year Google started to ban donation links in FOSS apps, WireGuard was one of the first victims [0], completely removed from the store. I didn't know that…

Jason was planning to challenge the App Store rejection after the fix for the WireGuard regression has been published, though I'm not sure what's the current state of the issue. The rejection is wrong, because the App Store review guidelines clearly spell out that apps may request donations through Safari. On the other hand, apps cannot use in-app purchases to request donations, unless they are published by an approv…

The wording is vague enough that having a link in your app for donations could easily be (and apparently is) considered a violation.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#189
post #172

Earlier quoted context omitted.

"it's beyond me why would anyone willingly use an Apple product" With respect, then, you aren't making much of an effort to understand.

I have an iPhone and macOS for development. I clocked a lot of hours on them over the years. I admit, I was sometimes jealous of mac hardware, for example the new M1, magsafe, and etc (though not the terrible keyboards). Though I was never jealous of an iPhone's hardware. I was never ever jealous of the software. I always found it buggy and user-hostile. The line you quoted was specifically about the user-hostility.…

I've used both platform, and I find iOS user friendly and easy to use. I also found iOS easier to develop for than Android, though admittedly it's been a few years since I've developed on either. Opinions are funny like that.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#190

Earlier quoted context omitted.

> We badly need a really-open alternative F-Droid is a thing

For now. When they change that optional setting they introduced recently which blocks sideloading applications outside of the official store and make it non-optional, what are we going to do? Use special Chinese Android builds with Ali store (or whatever it's called)? Boiling the frog slowly and all.

> When they change that optional setting they introduced recently

What setting was introduced recently? I remember such settings all the way back to the Nexus One.

In fact, things were more closed back then as Android phones bought from AT&T had it hard coded to disable third party apps. I'm not aware of a US carrier doing that any more.

Post reply on HN