12 ms·
WireGuard for MacOS
- jamesb93 8y agoWhy only 10.14 and up? most devs I know havent gone past 10.12.
- zx2c4 8y agoDetails on 10.14 APIs are in this mailing list post: https://lists.zx2c4.com/pipermail/wireguard/2019-February/003869.html https://lists.zx2c4.com/pipermail/wireguard/2019-February/00...
- tambourine_man 8y agoMojave has been a smooth sailing from day one for me. A few rendering issues from the move to Metal but no KPs or major incompatibilities. Sooner or later, things stop running. On the iOS side, I was surprised to learn you can’t run Netflix on an iOS 9 device. I think the days of hanging on to old system versions are over.
- scarface74 8y agoThat’s surprising. Netflix works on the original iPad with iOS 5.
- tambourine_man 8y agoBut can you download it from the App Store or is it just running the old version? I couldn't.
- scarface74 8y agoIf you have downloaded it previously, it prompts you if you want to “download the last compatible version”. As long as you’ve downloaded it previously you can redownload it.
- tambourine_man 8y agoYeah, but if you haven’t, you are out of luck
- scarface74 8y agoYou can download the app using an older version of iTunes. https://www.lifewire.com/download-apps-to-ipad-using-itunes-4103798 https://www.lifewire.com/download-apps-to-ipad-using-itunes-... Once it shows up as a previous purchase in your account, you can download it from your iPad. You don’t have to sync with iTunes.
- tambourine_man 8y agoNice, thanks
- r00fus 8y agoUh. I have an old iPad1 that can’t run iOS10 but runs Netflix fine. Have you tried updating the app?
- tambourine_man 8y agoCan’t install it. Can’t be downloaded from the App Store. You probably downloaded the version that did some time ago and it just continued to run
- roblabla 8y agoSome of us with mac pros or hackintosh literally can't update to mojave, because of missing nvidia drivers. And high sierra was such a clusterfuck that I'm glad I missed out on it.
- sxcurry 8y agoCurious - how do devs develop on a 2.5 year old OS. Aren’t there risks that things won’t work in recent releases?
- jamesb93 8y agoWe test with machines that have it, but we don't operate day to day on 10.14. It's more about offering backwards compatibility so the majority of users can benefit.
- Fnoord 8y agoSierra (10.12) isn't supported for long: "Extended support ends in September 2019. iTunes, in August 2020" [1] And while High Sierra (10.13) had its quirks [for which I could understand your response, plus all non Retina only work with 10.13 as latest, officially), Mojave (10.14) has been smooth. If not only for the dark mode (finally!). [1] https://en.wikipedia.org/wiki/MacOS_Sierra https://en.wikipedia.org/wiki/MacOS_Sierra
- Down_n_Out 8y agoI'm using Wireguard in combination with Pi-Hole on a cheap VPS as a VPN on my iPhone, it's blazingly fast and super stable. Will be trying this on my Mac as well now.
- Phenomenit 8y agoHow cheap are we talking here?
- out_of_protocol 8y agoDo you know any good guides on configuring server to act as a vpn/proxy (i.e. routing)? Regular wireguard articles don't cover this use-case at all, assuming reader know everything beforehand
- nixgeek 8y agoDo you have a Patreon or some other means of supporting you?
- reaperhulk 8y agoThe project accepts donations: https://www.wireguard.com/donations/ https://www.wireguard.com/donations/
- morpheuskafka 8y agoI'm excited to hear that they are making a new TUN infrastructure for Windows. After the website redesign, OpenVPN doesn't even ship builds of Windows-TAP anymore and it is quite a pain to build, plus you have to sign it yourself. One of my current projects will need a TUN and we've decided to make it Linux only because its just too much work to support Windows. There is a new VPN provider API only accessible to UWP apps, but there is literally zero documentation or examples beyond the auto generated .NET API docs.
- iknowstuff 8y ago> There is a new VPN provider API only accessible to UWP apps, but there is literally zero documentation or examples beyond the auto generated .NET API docs. I thought it was just me! Is this the reason why WireGuard decided not to use those APIs after all?
- miles 8y ago> OpenVPN doesn't even ship builds of Windows-TAP anymore WireGuard's creator discussing OpenVPN's TUN/TAP driver and a possible alternative back in 2017[0]: The OpenVPN Windows kernel TUN/TAP driver is really super scary. That alone has a larger code base than all of WireGuard... [0] https://news.ycombinator.com/item?id=15597883 https://news.ycombinator.com/item?id=15597883
- pizza 8y agoIf I want to use WireGuard on Windows, what's my best option, currently? TunSafe? Looks like there's some development on Windows going on atm but no releases afaik https://git.zx2c4.com/wireguard-windows https://git.zx2c4.com/wireguard-windows
- mmozeiko 8y agoI use TunSafe for something like a year. It is great. Everything is pretty seamless. And with it I get better speeds than OpenVPN when connecting to Linux machine across Atlantic ocean.
- 8y ago
- benbristow 8y agoI love the screenshot page, funny! Comic Sans and over-the-top JavaScript effects. https://data.zx2c4.com/wireguard-for-macos-screenshots-february-2019/ https://data.zx2c4.com/wireguard-for-macos-screenshots-febru... Brings me back to the days of JavaScript Kit and Dynamic Drive
- crooked-v 8y agoThe "trail following the cursor" effect is an instant jolt of year 2000 nostalgia for me.
- Hamuko 8y agoLooks great. I've been using WireGuard on the command line with my work MacBook and it's been solid despite the massive warnings about alpha software. I'll have to look into switching to this next week.
- dombili 8y agoIt works great. As a user, I love that it's being distributed via the Mac App Store. The one and only nitpick I have is the lack of bulk import support of the config files, but that's something I can live without. I'm looking forward to the Windows version. Thank you for taking the long and careful route with it.
- zx2c4 8y agoYou can bulk import by selecting a .zip archive of files, actually. But perhaps we can make the open file dialog multiselect. Good idea. I added it to the TODO list here: https://docs.google.com/document/d/1BnzImOF8CkungFnuRlWhnEpY2OmEHSckat62aZ6LYGY https://docs.google.com/document/d/1BnzImOF8CkungFnuRlWhnEpY...
- dombili 8y agoOh, I didn't know that. ZIP import solves the issue for me, but I'm glad you've got the multi-select feature on your to-do list.
- fauigerzigerk 8y agoI am extremely unhappy about not being able to install any software on my Mac without Apple's approval. This information changes a lot for me. I certainly hope that there are still viable workarounds at this point. But this is a step in a very dangerous direction.
- joosters 8y agoRight-click on a (non-signed) program you want to run, and select 'Open'. Now MacOS will ask if you want to run this software or not, and it can remember this decision so you can just run it as normal in the future.
- fauigerzigerk 8y agoI know. I've done that many times. But what the WireGuard guys are saying sounds like it's something very different: "Because it uses these deep integration APIs, we're only allowed to distribute the application using the macOS App Store (whose rejections, appeals, and eventual acceptance made for quite the stressful saga over the last week and a half)"
- gok 8y agoDoes this use the golang implementation internally?
- js2 8y agoIt appears so: https://git.zx2c4.com/wireguard-ios/tree/ https://git.zx2c4.com/wireguard-ios/tree/
- pixelcort 8y agoWhich APIs were only available via Mac App Store that prevented distribution outside it?
- IshKebab 8y agoI'm assuming they are referring to the Network Extension API. It seems the forced transition to the MacOS app store has begun. I give it 10 years before apps from outside the store cannot run at all without disabling SIP.
- Wowfunhappy 8y agoAs long as SIP can be disabled I don't mind this outcome. However, that's a very big and important condition.
- 1over137 8y agoSIP is useful though. It would be better that we could have SIP enabled and still be able to install whatever we want without going through App Store.
- Wowfunhappy 8y ago> SIP is useful though I am very skeptical on this point. macOS, like all Unix systems, already limits privileges for non-root users. What do you accomplish by placing limits on root as well? If a malicious application gets root, you are very screwed. The app can encrypt most of your hard drive, monitor most keystrokes, do nasty things with your hosts file, and steal most of your personal data. It won't be able to directly inject itself into other processes and certain critical OS files we protected, but how relevant is that? As I see it, SIP's main purpose is to (1) prevent non-technical users from (completely) hosing their systems by copying and pasting terminal commands from the internet, and (2) to protect TCC.db so that apps can't bypass Apple's privacy system. If you're able to turn off SIP, you have enough technical knowledge than #1 isn't necessary. I suppose #2 may have some limited value, but not much. If I am completely off base on this, feel free to educate me—but in my several years of research I have not come across any plausible scenarios for when SIP's protection would be helpful. ------ Edit: One other relevant note: Apple lets you selectively disable and enable parts of SIP. So you'd likely be able to turn off sideload-blocking (or whatever it is) without disabling SIP completely, if you want to for whatever reason.
- xCatbodi 8y agohow would I go about implementing a killswitch for this? I'd like for it wait until I said its OK to either try to reconnect or allow network without WireGuard connection. I was very happy with how Tunnelblick would do this for shitty internet scenarios. Is something like that even necessary in this situation? also: i do have connect on demand on. apologies if stupid question
- 8077628 8y agoOn the configs I've seen, "killswitch" is a few lines that tell iptables to stop sending when the connection drops. I don't know how tunnenblick does it, but this might actually, and I'm not joking, be a job for applescript? Since it looks like wireuard doesn't do killswitch on its own. http://krypted.com/mac-security/command-line-firewall-management-in-os-x-10-10/ http://krypted.com/mac-security/command-line-firewall-manage... might be a starting point.
- akerl_ 8y agoConnect-on-demand does what you want. OSX will use this connection when it needs to network, and if it can't make the VPN start, the connection will stall.
- KenanSulayman 8y agoI had been using wireguard-go (macports) on the Mac for a few months now and I'm simply amazed by the performance. Also using it on my phone. Weirdly enough when it's on my connection is more stable, probably because it bypasses the traffic shaping by my ISP through its UDP use. I couldn't find any information on whether or not this uses wireguard-go internally? Or maybe even the Rust implementation? p.s. the snow on https://data.zx2c4.com/wireguard-for-macos-screenshots-february-2019/ https://data.zx2c4.com/wireguard-for-macos-screenshots-febru... is pretty hilarious
- qalmakka 8y agoThe is no native XNU kext or bsd module AFAIK, so I guess it must be using the Go implementation underneath.
- loeg 8y agoThere is a WIP (Net)BSD wireguard implementation, but that's a long way from something you could just use on MacOS, and the developers are unaffiliated with zx2c4. https://github.com/ozaki-r/netbsd-src/tree/wireguard https://github.com/ozaki-r/netbsd-src/tree/wireguard
- zx2c4 8y agoThere's also a WIP OpenBSD port in progress. Over the next week or so I've got some plans to try to start working more closely with these developers and make sure the BSD kernel ports are first party supported implementations.
- dividedbyzero 8y agoThis looks amazing. I currently use OpenVPN to tunnel into a Kubernetes cluster, it's great how simple debugging distributed apps has become due to being able to do that. I wonder if I could use WireGuard to do the same, it appears to be much easier to set up.
- sascha_sl 8y agoYes, and if you're installing it on all your nodes anyway, you can use it to encrypt a flannel overlay net too. https://github.com/coreos/flannel/blob/master/dist/extension-wireguard https://github.com/coreos/flannel/blob/master/dist/extension...
- amaccuish 8y agoI look forward to solutions to solve autoconfiguration. I love how with say OpenConnect, I just enter a server address and my address and auth methods are all configured automatically. Otherwise very much a fan of WG!
- helper 8y agoThey are working on it: https://git.zx2c4.com/wg-dynamic/about/docs/idea.md https://git.zx2c4.com/wg-dynamic/about/docs/idea.md
- ridgeguy 8y agoApp store tells me it requires MacOS 10.14. Any chance of eventual 10.13 compatibility?
- zx2c4 8y agohttps://lists.zx2c4.com/pipermail/wireguard/2019-February/003869.html https://lists.zx2c4.com/pipermail/wireguard/2019-February/00...
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- adamfeldman 8y agoI've had a great experience deploying Wireguard using Streisand [1]. I'm excited to migrate to this GUI client, instead of using `wg-quick` in the macOS terminal. With Streisand, I only needed to choose some options and input a few credentials. 20 minutes later, Streisand had created a locked-down, self-updating box dedicated to hosting nothing but Wireguard. I deployed to a $5/month Digital Ocean droplet. [1]: https://github.com/StreisandEffect/streisand https://github.com/StreisandEffect/streisand Streisand previously on HN: https://news.ycombinator.com/item?id=18903780 https://news.ycombinator.com/item?id=18903780, https://news.ycombinator.com/item?id=8082444 https://news.ycombinator.com/item?id=8082444
- nsomaru 8y agoAFAIK all software on Streisand does not auto update so you need to redeploy periodically (and the repo hasn’t been updated in a while, the main author has little time for it anymore) which isn’t great if you’ve shared certs with non technical users
- adamfeldman 8y agoFurther detail for the curious: Recent enhancements to Streisand include automatic updates for Wireguard: https://github.com/StreisandEffect/streisand/issues/513#issuecomment-431588195 https://github.com/StreisandEffect/streisand/issues/513#issu.... Streisand automatically installs Ubuntu security and other updates using the "unattended-upgrades" package: https://help.ubuntu.com/community/AutomaticSecurityUpdates https://help.ubuntu.com/community/AutomaticSecurityUpdates. Streisand's unattended-upgrades config https://github.com/StreisandEffect/streisand/blob/master/playbooks/roles/common/templates/50unattended-upgrades.j2 https://github.com/StreisandEffect/streisand/blob/master/pla...
- nsomaru 8y agoStreisand installs around 70 different services. If all of them are not patched there’s a good chance your box becomes vulnerable over time. Remember, you’re piping all your internet traffic through this box.
- dbcooper 8y agoDoes this support obfuscation now?
- charliebrownau 8y agoAny plans for an open source client for Windows 7/8 in the works with File Menu on top left and proper close/min/exit buttons on top right Anyone else sick and tired of web apps/electron and touch screen ui on PC
- charliebrownau 8y agoYet to see a decent SSH server for Windows 7 and 8 also
- 8077628 8y agoThe real question is, where can I get some hott wireguard swag?
- vinay_ys 8y agoJason, thank you for Wireguard. It is just awesome! Which hosting provider is recommended for running your own wireguard server? I have tried various cloud providers like (digital ocean, google, aws etc) I noticed that Apple ID and app store does not work when traffic exits via these cloud instances. Has anyone else faced this issue? Any solutions?
- pyt 8y agoI've been running a VPN (currently WireGuard, previously StrongSwan) on a VPS through https://www.vultr.com/ https://www.vultr.com/ for a little over a year now and have had no issues with the App Store. Signed-out Google Search, however, is a different story...
- out_of_protocol 8y agoDo you know any good guides on configuring server to act as a vpn/proxy (routing mostly)? Regular wireguard articles don't cover this use-case at all, assuming reader know everything beforehand
- 0x38B 8y agoI just set up Wireguard on a VPS. I followed the installation instructions at https://www.wireguard.com/install/ https://www.wireguard.com/install/ For VPN setup, the Arch Wiki is a great reference: https://wiki.archlinux.org/index.php/WireGuard#Specific_use-case:_VPN_server https://wiki.archlinux.org/index.php/WireGuard#Specific_use-... I also set up Unbound + Stubby with DNS-over-TLS. For what it's worth, the RELATED, ESTABLISHED rule in FORWARD is a bad thing to forget; I was getting all sorts of interesting ICMP timeout errors because I didn't have it. New connections from clients were allowed, but I didn't have a rule to allow related and established, which made some things work, but mostly not.
- out_of_protocol 8y agoLooks great, thanks!
- emadb 8y agoQuestion: how many of you uses a crypted VPN Tunnel daily? We all know that privacy is important and it will became more and more important in the next few years. Does tools like WireGuard help in these cases? Or I miss the main focus? Should we all used a private VPN tunnel?
- chrisper 8y agoIt depends on what you want to protect. It is obviously great if you use a lot of public wifi for example. It's also great if your government is spying on you. Otherwise you just delegate the privacy issues from your ISP to the ISP of your output server. Personally, there is no reason to run a VPN all time from your home connection.
- gmac 8y agoI run one most of the time (IKEv2). I'm in the UK, and do it on principle to stop my ISP storing details of every domain I visit on behalf of government agencies. If I were in the US I'd do it to prevent my ISP selling that data on. (I also thought about setting something up for others, but this is currently 100% vapourware: http://digitalsnorkel.net/ http://digitalsnorkel.net/)
- jtms 8y agoReally great name - you should keep going with this!
- doubletgl 8y agoHow does it compare to Tunnelblick and Viscosity? Any reason to switch if I'm using a paid subscription to a mainstream VPN provider?
- apexalpha 8y agoTunnelblick and Viscosity are _implementations_ of a protocol: OpenVPN. Wireguard is a different protocol than OpenVPN. Not just a different implementation of the same.
- Fnoord 8y agoTrue, but all 3 are a frontend (Tunnelblick/Viscosity for OpenVPN and WireGuard for macOS is a frontend for the Go implementation). You could argue someone's asking for a comparison of the UIs. FWIW, I've tested the UI, and I very much like it, except that the whole public and private key are visible on the screen. The Android version only shows it partly (could be my resolution).
- simplify 8y agoCan someone explain the use cases for WireGuard? I think I'm pretty new to this whole topic.
- bmh 8y agoI have a few computers at home. I'd like to access them securely from anywhere in the world. WireGuard makes that easy.
- deleted 8y ago[deleted]
- _jcwu 8y agoIt basically replaces IPSec. You might want to look that up. There should be plenty of information regarding that.
- deleted 8y ago[deleted]
- wahern 8y agoA fairer assessment is that it replaces ESP (the stream encryption portion of IPSec) and a small subset of IKE features. If you look at the ecosystem of software arising around the core Wireguard protocol, much of it is a [poor] recapitulation of IKE. Key management and PKI in particular, not bulk encryption, is the hard part of IPSec (in so far as its hard), and Wireguard doesn't actually solve that. I wouldn't be surprised if someone eventually hacked Wireguard configuration management into an existing IKE daemon.
- Accacin 8y agoSo I use Mullvad, that have WireGuard servers setup. Downloaded the config files (which work perfectly on Linux) and I can't get WireGuard for iOS to work at all. I get the VPN icon in the top left but I have no actual internet connection (on either WiFi or 4G). Downloaded the TunSafe Client and the very same config files work perfectly. Obviously I'd prefer to use the WireGuard app though, but I cannot get it to work at all sadly.
- tcd 8y agoFunny how the developer doesn't respond to [1] from a VPN provider about improving security...DO NOT USE if you want to actually be secure! [1]:https://lists.zx2c4.com/pipermail/wireguard/2019-January/003777.html https://lists.zx2c4.com/pipermail/wireguard/2019-January/003...
- gnur 8y agoThis only applies to commercial VPN providers, if you run this at home there is nothing insecure about the issues mentioned in that post.
- Tharre 8y agoOn the contrary, it has triggered development of wg-dynamic[0] which should eventually fix those issues. [0] https://git.zx2c4.com/wg-dynamic/ https://git.zx2c4.com/wg-dynamic/
- zx2c4 8y agowg-dynamic was proposed well before that email. Actually, that email came after discussion the two of us had shortly prior to the email.
- kkm 8y agoThank you for the work <3
- mikkelam 8y agoSlightly offtopic.. but can WireGuard circumvent netflix country restriction? i.e. can it be used to watch netflix content in other countries?
- ownagefool 8y agoPretty much any VPN be used to change your location. However, it depends where the server lives, what IP you get from that, and whether or not it's on a blacklist by netflix. Wireguard is the protocol/tech, not a VPN Service Provider.
- zahllos 8y agoThis depends on your VPN service provider, not the WireGuard software - the software itself simply tunnels your traffic to the VPN provider, who then route it out to the internet. It doesn't matter if you use IPsec, OpenVPN, PPP, L2TP or WireGuard to send your traffic to your provider if their address has been blacklisted. What WireGuard does get you is a much simpler configuration format for VPNs (IPsec is notoriously overcomplicated) and a modern set of cryptography choices (most other VPN techologies are old and come with legacy baggage, or strange TLS-like connection setup that then becomes its own thing like OpenVPN).
- mikkelam 8y agoGotcha, makes sense
- tomeson 8y agoGoogle is now paying $17000 to $22000 per month for working online from home. I have joined this job 2 months ago and i have earned $20544 in my first month from this job. I can say my life is changed-completely for the better! Cheeck it out what i do So I started------>>>> http://www.Geosalary.com http://www.Geosalary.com
- antihero 8y agoExcellent! How easy is it to connect to our algo VPN servers with this? Edit: Very easy, you just scan the QR!
- Aissen 8y agoI can't wait for WireGuard to be merged into the Linux Kernel, so that we can start using it everywhere.
- gvand 8y agoThanks for this, have been following the project for a while. A minor annoyance, right now the usual option that allows to forward all traffic through the vpn is missing (the os and others put everything in an advance options pane accessible via button on the main screen) and route have to be configured manually each time... please keep this in mind for the next release ;)
- kdtsh 8y agoYou should be able to route all traffic through to the VPN by setting AllowedIPs to 0.0.0.0/0.