8 ms·
Show HN: Encrypted VPN in 2k lines of Go
- sAbakumoff 9y agoIs it just me or Golang started gaining momentum recently? More and more related articles/OSS projects/HN links show up every day.
- terminalcommand 9y agoI think Golang is very suitable for network programming tasks. It gives you wonderful libraries to work with sockets, strict rules to structure your code, automatic memory management, goroutines for concurrent programming etc. Most network related small apps were written in C, now you can write them in Go. With the added benefit of simple libraries, memory management and goroutines. You don't have to mess arround with platform specific sockets, threading libraries etc. Plus every piece of code you open is written in understandable Go. With C, there is years of baggage, multiple standards, pre-compiled headers, undefined behaviour etc. And lastly, new is always more exciting than old :)
- lurker- 9y agoWhen I first saw Go I was put off by its syntax, but after giving it a chance I very quickly fell in love with it. I've used C#, Python, Ruby, Java, C, Obj-C, JS and Go for mid-large scale projects. Go is the only language I've ever truly loved; sometimes I even feel like I'm writing poetry (as ridiculous as that may sound). The community is really incredible^, I've yet to encounter anything that didn't have great documentation or solved by packages. My favorite SO answer of any language is probably this one by icza: https://stackoverflow.com/questions/22892120/how-to-generate-a-random-string-of-a-fixed-length-in-golang https://stackoverflow.com/questions/22892120/how-to-generate... . I also feel that it's very easy to read and understand other peoples code compared to other languages (imo, the only aspect of Go that I think can be difficult for newcomers to grasp is pointers). All in all, I feel very confident that I'll still be writing Go code after ten years. ^ (Although I hate when certain "elitists" downvote questions because they feel they've been sufficiently answered elsewhere.. if a SO answer says how to display time to YYYY-MM-DD:HH-MM then don't complain if someone ask how to display time as YYYY-MM-DD.. I have a strong dislike towards jquery (or rather JS), but I think the great thing about jquery is that every imaginable edge-case seem to be documented)
- scaryclam 9y agoGenuine question as I've only dabbled in Go, but I've heard complaints from other dabblers that Go seems to encourage large files rather than breaking things up in a more modular fashion. Is that a reality? Or has the complainer just been unlucky in the code they've viewed?
- insertnickname 9y agoI don't see any reason why Go would encourage large files. A Go package consists of every Go source file in a directory. You can use as many or as few files as you want per package.
- scaryclam 9y agoYeah, I found it a strange assertion to make, so was wondering if it held any water. Sometimes different languages have different ways of working, which seem odd to novices entering the space from a different background, so I didn't want to assume that they were wrong. Looks like it may be a case of coming across some less well written projects and making assumptions about the entire language, which is nice as Go seems fun :)
- captncraig 9y agoWe don't really have the "one class one file" beat into us like in java or c#. That means you gotta think a little to see how a package naturally splits up. Some people are better at that then others.
- fmpwizard 9y agoI have been using Go for about 4 years at work and I would say they have been unlucky with the code they have looked at. You have the freedom to organize your code as you wish, you can easily go from one extreme to the other, one function per file to 1000 in one file. The only thing that isn't encouraged is to have very small packages, for example, if your project ends up split into 10 packages, but each of them is just one file (or one code file plus a test file), then most Go developers would suggest to group more files into a single package.
- ikeyany 9y agoNo it's not you [0]. Rust, Go, R, and Python have the highest year-to-year growth. [0] https://stackoverflow.blog/2017/09/06/incredible-growth-python/ https://stackoverflow.blog/2017/09/06/incredible-growth-pyth...
- Cthulhu_ 9y agoPython is interesting in that list, given how it's at least 4 times as old as all of the other ones in that list. What's behind that? I don't recall any major developments after Python 3, and most of the news behind that one was about its backwards incompatibility (and currently how 2.x isn't about to go anytime soon)
- pricechild 9y agoThey followed up on that question with another blog post: https://stackoverflow.blog/2017/09/14/python-growing-quickly/ https://stackoverflow.blog/2017/09/14/python-growing-quickly...
- rrdharan 9y agoExplosion of interest in machine learning and data science and decent Python-based tools for those fields.
- goatlover 9y agoPython's huge popularity in scientific computing fields along with it being widely taught in schools. Notice also that R was on the list, which is obviously due to huge uptick in data science. R has been around for awhile as well.
- Kurtz79 9y agoNice, I'll try it out once I get home. A couple of question: - What is the throughput once you fixed the issues ? - If you were to implement a client for mobile (iOS, Android), how would you go about it ? (Just theoretically, I understand it's a personal project) I'm using openvpn on a cloud server and one of the big advantages is the availability of mobile client apps.
- twitchyliquid64 9y agoThroughput: It depends on the link, but I'm getting 16mbps peak where my connection to my ISP gets me 20mbps peak. Mobile: You have to use the APIs that are available on the platform to hook into the network layer. After that its pretty straightforward though - you open some TLS connections, do verification, and encapsulate network traffic in some simple structs.
- _joel 9y agoI guess the main question is why should I use/trust this above OpenVPN/Tinc or WireGuard etc?
- hyperbovine 9y agoBecause your government banned those.
- ivanfon 9y agoBecause you can easily read and understand the code.
- dsacco 9y agoFor what it’s worth, this only really applies to a comparison against OpenVPN or IPSec. WireGuard has similar code complexity and size, and is approximately the same when compared against the incumbent VPN options.
- zokier 9y agoI don't think the comparison to Wireguard is apples-to-apples. Wireguard implements it's own semi-custom cryptosystem (Noise) whereas subnet rides on top of Go standard TLS implementation. So depending on how you view things, Wireguard is either much simpler (if you compare to the whole TLS stack) or much more complex (if you assume Go TLS to be reliable/trustworthy)
- zx2c4 9y agoMaybe I misunderstood your comment, but WireGuard is less than 4k LoC, which is a few orders of magnitude smaller than OpenVPN or IPsec.
- dsacco 9y agoYep you misunderstood, I was saying WireGuard has similar code complexity to the Go VPN implementation linked here :)
- 9y ago
- perlpimp 9y agolanguage used in the project is Erlang, not Go.
- Retr0spectrum 9y agosshuttle is another great tool with a similar use case. One advantage is that it doesn't require any server setup at all, as long as you have ssh access. https://github.com/sshuttle/sshuttle https://github.com/sshuttle/sshuttle
- kzahel 9y agoSshuttle is very cool. But it only does TCP and UDP. (no ICMP)
- zx2c4 9y agoA neat thing about sshuttle is that it restreams TCP connections inside of the SSH tunnel so that you don't incur the classic TCP-over-TCP problem [1]. [1] http://sshuttle.readthedocs.io/en/stable/how-it-works.html http://sshuttle.readthedocs.io/en/stable/how-it-works.html
- userbinator 9y agoUpon reading the title I wondered "would anyone ever create a VPN client that doesn't use encryption?" and thought, with the "2k lines" as additional evidence, that it was the source code which was somehow encrypted/obfuscated to e.g. prevent censorship... I was also expecting to see a single file at that line count, but then again I'm not really familiar with Go. Is this style of "many tiny files in multiple nested directories" common/expected for Go? I know it's rather common in many other languages, but also not what I expect when I see "Simple" or explicit mention of a low line count.
- captncraig 9y agoI wouldn't use that repo as a representative of what "go code looks like". Most go repos are pretty similar in "structure", but I really don't know how to navigate this. The 'src' directory looks like the author is really fighting the gopath concept, but also trying to vendor dependencies. I agree, if my hook was "in xx lines of code" I would try to avoid boilerplate and keep it all together as much as possible.
- deleted 9y ago[deleted]
- tyingq 9y ago>would anyone ever create a VPN client that doesn't use encryption?" They do, but generally call it tunneling. L2TP and GRE links that don't use IPSEC are fairly common on private WANs. I suspect the author was trying to point out that the encryption was included in the 2k lines, versus say, calling out to ssh.
- arianvanp 9y agoRelated: Wireguard is a new VPN for linux in 4k lines of C https://www.wireguard.com/ https://www.wireguard.com/ the model of wireguard has been proven correct by formal methods. Builds on modern crypto, and they kept code short for auditing purposes.
- jorrizza 9y agoThere's also a work-in-progress Go implementation of Wireguard, found over here: https://git.zx2c4.com/wireguard-go/about/ https://git.zx2c4.com/wireguard-go/about/
- hamandcheese 9y agoFrom the linked page: > There is no group of users that should be using the code in this repository here under any circumstances at the moment, not even beta testers or dare devils. Despite the warning I attempted to use it, but without any real docs I didn't get very far.
- zx2c4 9y agoThe Go implementation is not done yet! But it will be soon. In the meantime, feel free to use the Linux kernel implementation, which works quite well and has extensive documentation and man pages: - https://www.wireguard.com/ https://www.wireguard.com/ - https://www.wireguard.com/quickstart/ https://www.wireguard.com/quickstart/ - https://www.wireguard.com/install/ https://www.wireguard.com/install/ - https://git.zx2c4.com/WireGuard/about/src/tools/wg.8 https://git.zx2c4.com/WireGuard/about/src/tools/wg.8 - https://git.zx2c4.com/WireGuard/about/src/tools/wg-quick.8 https://git.zx2c4.com/WireGuard/about/src/tools/wg-quick.8
- hamandcheese 9y agoI’ve played with the Linux implementation, I love it! But I use a Mac so I can’t join the VPN I made :/
- sethammons 9y agoThe project structure is fighting againts norms. The author should not have src checked in. They should have their package as the root so it is "go get-able" and does not require the user to alter their GOPATH. To ensure that the proper dependency versions are present, they should vendor the dependencies. I would have opened an issue on GitHub for them, but I am not signed in currently. Cheers on releasing a neat tool. EDIT: got off my mobile and to a laptop and submitted https://github.com/twitchyliquid64/subnet/issues/3 https://github.com/twitchyliquid64/subnet/issues/3.
- genieyclo 9y agoGood job! I'm looking into trying Go soon, is there something you'd recommend looking at for learning the Go ecosystem norms?
- sethammons 9y agoThe first is doing the tour at golang.org, then reading Effective Go at https://golang.org/doc/effective_go.html https://golang.org/doc/effective_go.html. There are lots of good reads at the golang blog, such as https://blog.golang.org/organizing-go-code https://blog.golang.org/organizing-go-code. I really enjoy Go, and hope you do too!
- twitchyliquid64 9y agoThanks! This is definitely something I need to get around to once I read up a bit more on vendoring.
- freedomben 9y agoCheck out the `dep` tool: https://github.com/golang/dep https://github.com/golang/dep It is the future of official vendoring tools. You could also look at `govendor`: https://github.com/kardianos/govendor https://github.com/kardianos/govendor I've used govendor in some projects and found it agreeable. Best of luck :-)
- weitzj 9y ago
- astockwell 9y agoDoes this work on Windows? I see the TODO item "Get working on OSX", but if this project could bring x-compatibility on the big 3 platforms (thanks Go!), that could really set it apart.
- twitchyliquid64 9y agoI'm afraid not :/ Windows is a whole new kettle of fish to get working - you need a device driver to emulate TUN/TAP. That said, I'm using a library called Water for the low-level networking, and that library just added support for Windows. Implementing full windows support only requires you to implement a few network methods (such as helpers_linux.go) - PRs welcome :)
- e12e 9y agoAm I reading this correctly in that this uses TLS - and ends up tunneling TCP and UDP over TCP?
- twitchyliquid64 9y agoCorrect. While simple, this does have the performance impact you're alluding to. On my 20mbps (down) connection, I peak out at 16mbps on subnet. The 'double congestion-control' effect can be alleviated by opening 10 or so TLS connections and pumping the packets down those, to spread the effects of TCP congestion control.
- hamandcheese 9y agoIn other comments the author seems to already be aware, but for anyone wondering why TCP over TCP is less than ideal, this is a good read: http://sites.inka.de/bigred/devel/tcp-tcp.html http://sites.inka.de/bigred/devel/tcp-tcp.html