3 ms·
New deployments should be with 1.1 using its new protocol. https://www.tinc-vpn.org/documentation-1.1/Simple-Peer_002dto_002dPeer-Security.html https://www.tin
by Freaky 8y ago
New deployments should be with 1.1 using its new protocol.
https://www.tinc-vpn.org/documentation-1.1/Simple-Peer_002dto_002dPeer-Security.html https://www.tinc-vpn.org/documentation-1.1/Simple-Peer_002dt...
- galadran 8y agoThat does look a lot better, however: a) its not supported by the stable release b) There are no claims about downgrade resistance. The manual specifies the new transport protocol is used if both clients support it and both have changed their configs to enable experimental mode. Can an attacker still force them to connect with legacy mode? c) Users have to ensure every single config on every client has the correct setting. d) It still doesn't have the identity hiding features of Wireguard. (Someone observing your network traffic can see which servers you are talking to from the transmitted signatures)
- Freaky 8y agoYou can disable legacy support by not generating any RSA keys, or by building with DISABLE_LEGACY.