3 ms·
Nice work, but I'm wondering why does it have to be in kernel? Couldn't it still be fast and written in a safer than C language considering the security contex
by RRRA 10y ago
Nice work, but I'm wondering why does it have to be in kernel?
Couldn't it still be fast and written in a safer than C language considering the security context? (Or we'll still need to get grsec in there... :)
Cheers!
- microcolonel 10y agoI suspect it has to be in kernel for efficiency reasons. Because applications access network devices through kernel interfaces; the kernel has to context switch and copy data to and from the userspace VPN process; This can be quite slow. On a microkernel system, the standard way of connecting to the network stack might be through direct shared memory; and on such a system you could manage to run the VPN in userspace at essentially no cost. However, on Linux, most of the network stack is in the kernel; the ABI for interacting with network hardware is stable. So while in theory you could write an efficient userspace VPN, it would require you to modify or at very least recompile your applications.
- JohnGrin 10y agoThanks for information! ExpressVPN is pretty good. I checked it at free vpn check service https://2ip.io/privacy/ https://2ip.io/privacy/ and it shows a high level of efficiency.