Increasingly it seems like heavily opinionated foundational tools and frameworks are overtaking more highly configurable alternatives, at least in terms of breadth of usage or popularity. Could this be a positive change? Does this represent a healthy response cognitive fatigue in a world with configuration options at every possible layer? Or does this shift to less readily configurable tools represent an overall nega…
WireGuard Gives Linux a Faster, More Secure VPN
91–100 of 306 posts
Re: WireGuard Gives Linux a Faster, More Secure VPN
#92Don't forget to support Jason, WireGuard's author, on Patreon. https://www.patreon.com/zx2c4
Wow, 10k$/month is a lot more than a 'sustainable full-time job' would pay :) At least here in Europe. But of course what he's getting now ($1212) is nowhere near that.
I prefer this model for opensource software. We get an awesome product and he gets enough money to sustain himself while maintaining it. Seems like a fair deal for all.
Re: WireGuard Gives Linux a Faster, More Secure VPN
#93Earlier quoted context omitted.
Of course I am sure he is extremely happy spending 5 years developing the next big thing then others rebrand it for enterprise and become rich.
Jason comments here all the time and is quite easy to talk to, and I think we're all better off hearing from real Jason, not some imaginary angry Jason you've invented. Not least because there are actual abuses in the WireGuard ecosystem, and your imaginary Jason is obscuring them behind fake abuses.
Re: WireGuard Gives Linux a Faster, More Secure VPN
#94Earlier quoted context omitted.
This is a common critic of WireGuard, but it looks like those service are looking for excuses to explain why they don't propose WireGuard yet. As far as I understang it: > What they probably need to do is to assign each customer a fixed private IP for use within their VPN, e.g. from 10.0.0.0/8. Actually, they can set a different IP for each session and rotate them by given it to the client out of band, for example wh…
> Actually, they can set a different IP for each session and rotate them by given it to the client out of band, for example when it authenticates to the service. Like I said, Wireguard does not have the concept of sessions. You could add your own proprietary "stuff" around Wireguard to add that concept, but then you don't need anything extra from Wireguard. You add the keys of the users as part of the session setup a…
Re: WireGuard Gives Linux a Faster, More Secure VPN
#95What makes Wireguard more secure? The article appears to make some weak claims about a smaller codebase and less configuration options but I don't think that translate directly into it being more secure?
Smaller codebase means less chance of bugs. But I agree, it should really be audited properly before this statement can be made.
In addition, the crypto design (beyond it being opinionated and thus no way to misconfigure into using the "null cipher") is arguably much more secure by design than other systems. For instance, WireGuard eliminates entire classes of vulnerabilities through careful protocol design while also adding fairly neat features (such as being impossible to port scan) -- the author explains this much more eloquently than I can[2].
[1]: https://www.wireguard.com/formal-verification/ [2]: https://www.youtube.com/watch?v=CejbCQ5wS7Q (about 23 minutes in)
Re: WireGuard Gives Linux a Faster, More Secure VPN
#96So when they say it will be embedded into the Linux Kernel, what does that mean exactly? Does that mean I will be able to open a terminal an type: WireGuard and from then on my connection to the internet will be secure so long as I don't close the terminal or what?
> Does that mean I will be able to open a terminal an type: WireGuard and from then on my connection to the internet will be secure It's more like how iptables/nftables is part of the kernel. You need a recent kernel along with user space tooling. But it will become part of virtually every Linux distribution. As for "my connection to the internet will be secure" - that's possible, but the main use case right now is "…
Re: WireGuard Gives Linux a Faster, More Secure VPN
#97Is there a version of Ubuntu that has GUI NetworkManager support for WireGuard? I’m missing the convenience of toggling the VPN on and off from the system menu.
Versions >= 1.20 have support for all the bits and pieces (including routing all traffic). Initial support landed in 1.18.
https://packages.ubuntu.com/search?keywords=network-manager&...
Re: WireGuard Gives Linux a Faster, More Secure VPN
#98Re: WireGuard Gives Linux a Faster, More Secure VPN
#99Earlier quoted context omitted.
this cisco anyconnect system? https://www.cvedetails.com/vulnerability-list/vendor_id-16/p... doesn't seem very secure to me.
CVEs mean that a company can take action to mitigate a vulnerability. Wireguard is not mature enough to have something like that. A known vulnerability is bad, but not nearly as bad as an unknown vulnerability. This is not a knock on Wireguard, I use wireguard and love it. It just has several hoops to jump through before it is ready for widespread adoption. Like NIST approving it to be used instead of IPsec or OpenVP…
but even ignoring all of that, wireguard has significantly better security guarantees. https://www.wireguard.com/formal-verification/ claims that "WireGuard has undergone all sorts of formal verification, covering aspects of the cryptography, protocol, and implementation." with references to several formal proofs of the protocol.
furthermore, wireguard has actually received a CVE: CVE-2019-14899, which was posted here only a few weeks ago. it's not wireguard-specific though, it's a general problem with VPN setup on general-purpose operating systems.
Re: WireGuard Gives Linux a Faster, More Secure VPN
#100Earlier quoted context omitted.
Tailscale looks promising. ( https://tailscale.com/ )
I am sick of people shilling to this thing here. Stop exploiting HN for free advertising. Every Wireguard post here has become a free ad for this company. EDIT: Stop supporting parasites repackaging and rebranding open source and selling it while leaving the author who single handedly made this entire thing possible begging for donations on Patreon