6 ms·
Anyone interested in setting up their own VPN should check out Algo: https://github.com/trailofbits/algo https://github.com/trailofbits/algo
by ensignro2340 9y ago
Anyone interested in setting up their own VPN should check out Algo: https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- hyperpower 9y agoWhat's the advantage of this over OpenVPN?
- jakebasile 9y agoIt's natively supported by more operating systems. Namely, macOS and iOS. Also generates mobileprofile files that you can AirDrop to your device and have it set up in an instant.
- armitron 9y agoOn the flipside, it introduces monstrous dependency (strongSwan) written in memory unsafe C, is nowhere near as flexible as OpenVPN and is blocked by many networks since it can't operate over arbitrary ports and forces you to manage/own the server-end. 1) If I wanted to do that, I'd use OpenVPN rather than strongSwan. They're both written in C, but I get extra flexibility by using OpenVPN. Their "TLS is suspect" stance doesn't hold water in my view. 2) When I don't want to set up my own server, OpenVPN allows me to use or even chain lots of third party servers and create my own nested VPN topologies. Installing an OpenVPN client on my phone or tablet takes a few minutes. So, to summarize, Algo would be interesting if it didn't introduce dependency on memory unsafe code or minimized such dependency. But it doesn't. On the client, I do not see why I should trust Apple's IPSEC implementation (racoon?) more than OpenVPN client which is another point they tried to make. As it currently stands, it does not compare favorably to OpenVPN in any way.
- superkuh 9y agoOr reconsider the need for a VPN at all. By using a VPN you cut yourself off from participating as an equal citizen on the net. If it's just for browsing the web, irc, or the like it's much easier and better just to use a socks 5 proxy to a cheap VPS. I like shadowsocks-libev. But then again I don't use popular browsers that cram in fancy new features every week to expose new leaks and attack surfaces.
- Hnrobert42 9y ago> By using a VPN you cut yourself off from participating as an equal citizen on the net. What?
- superkuh 9y agoYou can't host servers off a VPN. You don't have control or use of your own ports. You can consume and that's about it.
- matthewmacleod 9y agoI’m not sure why you have that idea. I’m not entirely familiar with how most off-the-shelf VPN providers work, but I have a simple IKEv2 VPN hosted on Digitalocean that just gives me a public IP address, to which I can route a thing I want. This service appears be be specifically tailored for that use case, though I know nothing about it: https://staticvpnip.com https://staticvpnip.com
- Sohcahtoa82 9y agoIf I wanted to host servers, I'd host them somewhere else, not on my home internet connection. I'm really not sure what point you're trying to make, or how you're defining "participating" in this context.
- superkuh 9y ago> If I wanted to host servers, I'd host them somewhere else, not on my home internet connection. But why? You probably have a tens to hundreds of megabit connection that is always on. You have powerful computers that wouldn't even notice a webserver running. Buying a domain costs $8 and pointing it at home is as simple as changing the DNS entry a couple times a year or using DynDNS services. And what you don't have is a need for all the complexity and requirements that most automatically assume they need just because they're drowing in them in their day job. Hosting from home is more than enough for a personal website. It cuts the gordian knot of deciding what types of speech and content will be allowed on any given service. It prevents the perverse incentives of spying and selling users. It allows you to add things to your site on a whim just by copying a file to your web directory or opening an text editor. All the tools of your operating system, this refined and extremely usable software is now just there. Now you don't need a database. No need for a CMS. No need for scaling or containers or 99.9999% uptime. Hosting from home allows you to participate in the 'net in a way that is just natural. When there's not 5 layers of abstraction between you and the web you really can participate and build whatever you want. And since you don't need all that abstraction, dynamic content, and CMS (your OS is the CMS!) the security problems everyone loves to jump on simply vanish. Say you want to monitor your logs, well, you don't need to go install some dynamic language parser and prettifier full of attack surfaces. You just tail the log and grep. You open it in OpenOffice if you really have to have a GUI. You can set alerts as easily as tailing a log. You see day to day the type of bots, people, and referers and how they come to your site all without google analytics. You can respond to people using your site in real time; I love adding personal messages to people as they browse my site(s). This is what I mean by participating in the net. Getting down into it. It's a beautiful thing and it solves so many problems that can't even be approached when you're using someone elses computer and someone else's connection. And if you're in the USA you completely bypass third party doctorine and actually have an expectation of real privacy. I just don't get the hostility to the concept I see on HN.
- mehrdadn 9y agoWhat's so "legacy" about L2TP that it refuses to support it? Unlike others it's actually both secure and supported natively on most platforms...
- ensignro2340 9y agoSorry, I'm not actually affiliated with the project, I just use it, so you'll have to shoot your question to the people behind it.
- rahimnathwani 9y agoNot 'anyone'. Algo is not suitable for avoiding censorship, and it doesn't target this use-case.
- patentatt 9y agoI use it just to secure open or shifty public wi-fi in cafes and such. I do trust the data center the VPN terminates in more than the open wifi at the corner cafe, so it works for me.
- patentatt 9y agoFYI: Windows' built-in IKEv2 VPN client is not leaking IPs. Works great with Algo.