Live data from Hacker News

TunSafe WireGuard Client for OS X

tunsafe.com

21–30 of 48 posts

Re: TunSafe WireGuard Client for OS X

#22
post #16

Earlier quoted context omitted.

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

Same here. I was planning on using WG for personal infra and was actively routing for it in a corp environment, but his attitude has put me off. I'm sticking with OpenVPN for the time being. I use viscosity as my openvpn client on macs. I love Viscosity and was planning on asking them to support WG. Not anymore though... The author seems to be stuck in a past where closed source vs open source was a binary decision.…

> The author seems to be stuck in a past where closed source vs open source was a binary decision. We've gone past that point in history.

I'm not sure what you mean by this. We are at a point in history where 100% open source is more important than ever before.

Re: TunSafe WireGuard Client for OS X

#23
post #15

Earlier quoted context omitted.

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

Did it put you off using openssh/openvpn/libressl/etc? Is there the Torvalds effect? Let maintainers express their discontent in the form they prefer. I see how @zx2c4 might be concerned about possible reputation risks due to the release of this closed-source implementation at the earliest WireGuard stage. Given that the author of TunSafe is not a security expert. Especially if (suddenly) TunSafe turns out to have se…

It didn't stop me using them, but it certainly is off-putting. It's not a black and white issue though. The value I get from Linux easily outweighs any issues from Linus being a bit of a knob. I'm also unlikely to have to deal with Linus as a user. WireGuard, on the other hand, is a small project where the maintainer jumps in to discussions on HN. If that's how he behaves here, I'd rather not have to deal with that if I have a support question.

Re: TunSafe WireGuard Client for OS X

#24
post #9

Previous HN discussion on TunSafe from earlier this week: https://news.ycombinator.com/item?id=16515637

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

I have always found it odd that people seem to feel the need to personally like the creator of something.

Re: TunSafe WireGuard Client for OS X

#27
post #15

Earlier quoted context omitted.

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

Did it put you off using openssh/openvpn/libressl/etc? Is there the Torvalds effect? Let maintainers express their discontent in the form they prefer. I see how @zx2c4 might be concerned about possible reputation risks due to the release of this closed-source implementation at the earliest WireGuard stage. Given that the author of TunSafe is not a security expert. Especially if (suddenly) TunSafe turns out to have se…

Might be more appropriate to compare with "ssh" and a Tatu Ylönen-effect in the case of ssh. Although openssh certainly became a significant fork.

Re: TunSafe WireGuard Client for OS X

#28
post #19
post #16

Earlier quoted context omitted.

Same here. I was planning on using WG for personal infra and was actively routing for it in a corp environment, but his attitude has put me off. I'm sticking with OpenVPN for the time being. I use viscosity as my openvpn client on macs. I love Viscosity and was planning on asking them to support WG. Not anymore though... The author seems to be stuck in a past where closed source vs open source was a binary decision.…

> @ptacek (or anyone else working on this space) how much would it cost to vet wireguard for security holes? You may be interested in @ptacek's response on this matter a while back[1]. [1] https://news.ycombinator.com/item?id=16327350

Off-topic from that thread:

"(...) we're hosting the dude who wrote the Wireguard go implementation this summer (hey Mathias)"

Which pointed me at:

https://www.wireguard.com/xplatform/

I didn't realize there were some real efforts underway for cross platform support - that makes wg much more interesting (for my use-cases). Good to know! (I can live with higher performance linux-linux than linux-windows, mac-linux, linux-bsd etc; but forcing the need for a Linux "vpn router" as a vm or physical box is a tough sell. Not to mention a need for a real client for smart phones, though I suppose it should be possible to run wg on a rooted/custom rom Android phone, it'd be nice to have regular Android and ios clients).

Re: TunSafe WireGuard Client for OS X

#29
post #10

Is there by any chance a speed comparison against IPSec (IKEv2) i.e. strongSwan with AES-NI? I haven’t used OpenVPN in many years, so such a comparison would be much more interesting.

From experience I can tell you that IPSec is much faster than OpenVPN. I have no issues getting Gbit over IPSec (Strongswan), but with OpenVPN I always maxed out around ~400Mbit. EDIT: Looks like I misunderstood your comment and it seems like you want a comparison to Wireguard... oops

Yeah that’s my experience as well. That’s why I wanted a comparison. My router at home easily handles gigabit over IPSec even though the CPU is at least 8 years old.

Re: TunSafe WireGuard Client for OS X

#30
post #17

Earlier quoted context omitted.

That's not a "discussion", but a nasty spiteful post full of extreme, but baseless allegations.

That's not the whole story. There are further responses in that thread, including the opposing viewpoint from the TunSafe author. * https://lists.zx2c4.com/pipermail/wireguard/2018-March/00246... * https://lists.zx2c4.com/pipermail/wireguard/2018-March/00246... are the most relevant ones. (There are more, but they go slightly offtopic.)

Do I read it correctly that they banned @ludde from the wireguard IRC channel because his software wasn't open source? Damn.
Post reply on HN