Live data from Hacker News

Response to “WireGuard: great protocol, but skip the Mac app”

lists.zx2c4.com

331–340 of 392 posts

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#331
post #173
post #17

This is a response to the Rachel by the bay blog post https://rachelbythebay.com/w/2020/12/24/wg/ Personally I rarely use a mac, and don't do wg on demand, but one thing that did annoy me was being unable to set dns search domain, which wasn't mentioned in the blog post, but I believe is also caused by OSX deficiencies.

DNS search in MacOS is managed by their DNS infrastructure which is documented under resolver(5). That lets you route the resolution of particular domains to specified nameservers. The files live in /etc/resolver but can also be manipulated with scutil. So it's not an OSX deficiency, it's an OSX difference, similar to launchd vs systemd.

when I type "ping foo" or visit "http://foo", I want my search domain to add ".my.domain.com" to the end as configured in DNS.

I can do this on the OSX networking tab where I set DNS server, but from what I read that feature isn't available for the wireguard client.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#332
post #300

Earlier quoted context omitted.

Only nonprofits are allowed to use in-app purchases on the App Store, while other apps must use Safari for fundraisers, read the guidelines in their entirety. > One of the reasons why I do not gift money to WireGuard developer(s) is that they have taken the steps to obscure where and to whom the money is going, which is in and of itself fishy. Just labelling something as 'donation' does not make it so. Your remark ab…

I actually read them, and they also happen to be quoted upthread. 3.2 Other Business Model Issues [list is not exhaustive] 3.2.1 Acceptable (vi) Approved nonprofits may fundraise directly within their own apps or third-party apps, provided those fundraising campaigns adhere to all App Review Guidelines and offer Apple Pay support. These apps must disclose how the funds will be used, abide by all required local and fe…

I'm confused. Wireguard and Jason/zx2c4 are not a non-profit, nor do they advertise as one. Why are you making it sound like he is doing something nefarious?

The argument for the ruling being bad is: the app links to the wireguard webpage (not within the app) which contains information on how to donate. That's like if in my app, I linked to my twitter profile, and my twitter profile contained a link to donate to me. It shouldn't be a problem.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#333

Earlier quoted context omitted.

For now. When they change that optional setting they introduced recently which blocks sideloading applications outside of the official store and make it non-optional, what are we going to do? Use special Chinese Android builds with Ali store (or whatever it's called)? Boiling the frog slowly and all.

Android is open source.

You may as well celebrate TiVos running Linux. If the device is locked down, it's hardly a victory that it's running obstensibly free software.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#334
post #279
post #215

Apple doesn't deserve to have such careful and detail-oriented FOSS developers like Jason, developing for their platform. He is genuinely wasting time in order to work around Apple's developer-unfriendly platform. Not that I should be telling devs where they should spend their time... but I feel like so much effort is being devoted to fix Apple's issues. > When I'm debugging these issues, I'll often times spend a few…

> Apple should be losing devs in favor of other better platforms, not the other way around. So far, good hardware, close-to-*ix-OS software, and penetration are kind of make them a hard competitor to beat. What other "better" platforms are you thinking about?

Honestly, I was thinking on "better" as in "more developer-friendly", especially regarding the phrase I quoted... i.e. Microsoft Windows.

As for myself, I work on Linux systems, so my preferred platform would be a beefy PC with some Linux distro.

Yes, Apple makes good hardware. Or, at least lets say they worked hard on creating a distinctive perception about their quality on the consumer's minds. On the other hand, for some reason people tend to avoid spending similar amounts of money in the other ecosystems (or that's what I feel in my circles). I mean, try spending the same money that you would pay for the latest iPhone or Macbook, and you will get a fabulously spec'd Android phone or laptop.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#335

Earlier quoted context omitted.

Apologies, I indeed meant the original post to which Jason was responding. By "response" I meant the response of the user to the WireGuard Mac app. Again apologies, I somehow jumped a few mental hoops of my own when commenting.

Ah, but the original post, which triggered the uninformed ranting against WireGuard, was not itself from someone who was ignorant of the lengths and hoops developers have to jump through to work around Apple's many, many restrictions. Furthermore, its author outlined how to work around the problems with the app by using Macports instead. What about the problems? Well, it's free. They owe me nothing. But, you should s…

Agreed, the beef needs to be with Apple, developers targeting the platform are trying their best, and to say that they shouldn't support the platform if they can't deliver a quality product is disingenuous; you can have a quality product and Apple's policies and restrictions can absolutely destroy your UX; I've experienced this first hand.

It's not that Apple doesn't budge, if people shout loud enough; their Push/APNS change deadline was pushed back twice, it can happen again if enough people push enough for them to start treating their 3rd party developers like first class citizens.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#336
post #123
post #67

Earlier quoted context omitted.

> Not only is it much faster other VPNs IPSec is as fast as Wireguard. And there is native client in MacOS. As for bloated codebase, there is an OpenBSD iked rewrite.

Doesn't IPSec need a "clean" network connection, without any NAT in the middle? Wireguard was designed to work well even in the presence of NAT.

In IKEv2 it’s optional but IPsec NAT traversal (NAT-T) uses UDP port 4500.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#337
post #268

Earlier quoted context omitted.

Having a link to an external web page to receive donations is not considered a violation on the App Store, this is a mistake by a reviewer. Collecting funds "within the app" means that the payment flow is completed without leaving the app. They explicitly list two ways for any app to accept donations, by redirecting the user to an external web service opened in Safari, or by collecting payments using a text message.…

> "Having a link to an external web page to receive donations [by a registered charity or a non-profit] is not considered a violation on the App Store" Which e.g. "PayPal@zx2c4.com" is not, clearly. The words you are missing are important. One of the reasons why I do not gift money to WireGuard developer(s) is that they have taken the steps to obscure where and to whom the money is going, which is in and of itself fi…

Why though? What do you forsee the issue being with where the money could be going?

If Jason is recommending a way to donate to the project, who cares where it goes? If he puts it straight in his pocket and uses it to buy pizza or a computer game, it's still serving its purpose as far as I'm concerned. I have donated, and will do so again, and I'm perfectly happy with the money being used that way.

In a sense, for me, it's a thank you for the work thus far, not an payment for more work.

I imagine many see this differently, so I'm interested to hear some other opinions.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#338

Earlier quoted context omitted.

Completely agree. Apple has nothing but contempt for its developers, and treats them like indentured servants. "Oh it took 10 years to get your app working right? Well, it doesn't work right anymore after yesterday's patch."

That could be said for any platform these days. It's certainly not specific to Apple!

It's completely untrue in my experience working with WWW, GNU, and POSIX. Compared to Android, Apple, Facebook, Twitter, eBay, and many other platforms I've developed for, I feel supported and catered to, and if I have a problem or a question, there is an actual human on the other end to guide me, politely and helpfully.

Developing for Windows back in the day, it was about halfway there. I had zero ability to communicate back to the platform owners, but I rarely if ever felt shit on, disrespected or disregarded. In contrast, on Win32, I felt like everything I wanted to do had already been considered ahead of time, thought through, and there was an existing and elegant solution available.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#339
post #67

Earlier quoted context omitted.

> Not only is it much faster other VPNs IPSec is as fast as Wireguard. And there is native client in MacOS. As for bloated codebase, there is an OpenBSD iked rewrite.

iirc, ipsec is considered somewhat of a security nightmare by modern standards, given that it difficult to fully understand and very easy to misconfigure in an insecure way. I would only recommend using ipsec over wireguard when legacy compat matters.

IKEv2 can be configured securely, but by someone that that is familiar with that particular minefield. Both on Windows and MacOS the GUIs configure weaker security by default (the cynic may wonder why!).

On MacOS you can use Apple Configurator /Apple Profile Manager and on Windows Powershell, to configure stronger security.

The nice thing with WireGuard is it’s either secure or it’s off.

As you say, it’s easy to misconfigure IPSec and the number of experts gets smaller day by day.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#340

> We faced rejections in submitting the app, because they decided to change their policy on the app having a link in the "About WireGuard" tool window to www.wireguard.com/donations/ (which they previously had allowed explicitly; now they want 30% or something) Last year Google started to ban donation links in FOSS apps, WireGuard was one of the first victims [0], completely removed from the store. I didn't know that…

On the flip side, Apple is hosting and distributing this app for free

This could be normalizing effort; no end runs around allowed in software from our repo?

It’s rather our fault though, yeah? For popularizing their kit and agreeing to pay for “package management as a service” as devs in the first place.

Post reply on HN