Live data from Hacker News

TunSafe WireGuard Client for OS X

tunsafe.com

31–40 of 48 posts

Re: TunSafe WireGuard Client for OS X

#31
post #24

Earlier quoted context omitted.

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

I have always found it odd that people seem to feel the need to personally like the creator of something.

There’s a difference between liking someone (which doesn’t really matter) and trusting their judgement (which is what I think folks mean here). I feel it’s somewhat important for the later to be true, especially with security related software.

Re: TunSafe WireGuard Client for OS X

#32
post #9

Previous HN discussion on TunSafe from earlier this week: https://news.ycombinator.com/item?id=16515637

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

You are not alone, see the following exchange on LKML, where Donenfeld immediately "disciplines" another subscriber for asking some minor question that was not 100% on topic:

https://lkml.org/lkml/2017/12/7/1745

Follow-up by David Miller:

https://lkml.org/lkml/2017/12/8/533

That said, I like the idea of WG like I liked the idea of systemd.. but Donenfeld just seems to be another Poettering in the making.

Re: TunSafe WireGuard Client for OS X

#33
post #14
post #10

Is there by any chance a speed comparison against IPSec (IKEv2) i.e. strongSwan with AES-NI? I haven’t used OpenVPN in many years, so such a comparison would be much more interesting.

It's extremely fast, the benchmarks I've seen show that it's even faster than the IPSec config you describe.

> the benchmarks I've seen

I think GP was asking for links to that, able to share?

Re: TunSafe WireGuard Client for OS X

#34
post #9

Previous HN discussion on TunSafe from earlier this week: https://news.ycombinator.com/item?id=16515637

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

I feel the opposite way.

Subscribed to the Wireguard mailing list for a while and the author seems very friendly, even to help requests that are really .. stretching what a mailing list should be for.

Yes, this reply was rather harsh, but if there's someone who jumps on a somewhat popular project and implements (competing, it seems cross platform clients are 'coming soon') commercial/closed source clients than I do understand some .. frustration.

On top of that: Both the author of TunSafe and Wireguard seems to agree that - at least on Windows - TunSafe requires a rather scary tun driver?

(I am not a security expert..)

Re: TunSafe WireGuard Client for OS X

#35
post #10

Is there by any chance a speed comparison against IPSec (IKEv2) i.e. strongSwan with AES-NI? I haven’t used OpenVPN in many years, so such a comparison would be much more interesting.

Preliminary benchmarks are available on the website.

https://www.wireguard.com/performance/

EDIT: Note these are obviously for the reference implementation, not TunSafe.

Re: TunSafe WireGuard Client for OS X

#36

Earlier quoted context omitted.

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

I feel the opposite way. Subscribed to the Wireguard mailing list for a while and the author seems very friendly, even to help requests that are really .. stretching what a mailing list should be for. Yes, this reply was rather harsh, but if there's someone who jumps on a somewhat popular project and implements (competing, it seems cross platform clients are 'coming soon') commercial/closed source clients than I do u…

Also the official not-ready-yet WireGuard cross platform Go/Rust clients require this "scary" driver.

Re: TunSafe WireGuard Client for OS X

#37
post #30

Earlier quoted context omitted.

That's not the whole story. There are further responses in that thread, including the opposing viewpoint from the TunSafe author. * https://lists.zx2c4.com/pipermail/wireguard/2018-March/00246... * https://lists.zx2c4.com/pipermail/wireguard/2018-March/00246... are the most relevant ones. (There are more, but they go slightly offtopic.)

Do I read it correctly that they banned @ludde from the wireguard IRC channel because his software wasn't open source? Damn.

Yes - that's what the WireGuard author did. I didn't even discuss TunSafe.

Re: TunSafe WireGuard Client for OS X

#38

Earlier quoted context omitted.

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

I feel the opposite way. Subscribed to the Wireguard mailing list for a while and the author seems very friendly, even to help requests that are really .. stretching what a mailing list should be for. Yes, this reply was rather harsh, but if there's someone who jumps on a somewhat popular project and implements (competing, it seems cross platform clients are 'coming soon') commercial/closed source clients than I do u…

If you've created a new open protocol I'd imagine most people would welcome new implementations, especially on platforms that you don't currently support.

Re: TunSafe WireGuard Client for OS X

#39

Earlier quoted context omitted.

I don't know how reasonable it is, but the attitude of the WireGuard maintainer in that thread really puts me off using it. Call it the de Raadt effect.

You are not alone, see the following exchange on LKML, where Donenfeld immediately "disciplines" another subscriber for asking some minor question that was not 100% on topic: https://lkml.org/lkml/2017/12/7/1745 Follow-up by David Miller: https://lkml.org/lkml/2017/12/8/533 That said, I like the idea of WG like I liked the idea of systemd.. but Donenfeld just seems to be another Poettering in the making.

To be fair, his own reply to that was reasonable: https://lkml.org/lkml/2017/12/8/714

Re: TunSafe WireGuard Client for OS X

#40
post #10

Is there by any chance a speed comparison against IPSec (IKEv2) i.e. strongSwan with AES-NI? I haven’t used OpenVPN in many years, so such a comparison would be much more interesting.

Preliminary benchmarks are available on the website. https://www.wireguard.com/performance/ EDIT: Note these are obviously for the reference implementation, not TunSafe.

Interesting, haven’t run IPSec under Linux, is this expected performance?

Seems rather low compared to what I’ve experienced under FreeBSD. An i7 Ivy Bride & Broadwell and should be aleast comparable to my almost decade old Nehalem-EP Xeon, shouldn’t it?

Post reply on HN