16 ms·
Linux under WSL2 can be leaking
- Voline 6y agoWe have tested a few other VPN clients from competitors and found that all of them leak in the same way. The way Microsoft has implemented virtual networking for Linux guests makes it very difficult to properly secure them.
- qz2 6y agoIt’s a shit show. Can’t trace packets either via wireshark on the host and tcpdump doesn’t work on the guest. I’ve gone back to virtualbox and eviscerated WSL. Another total waste of my life.
- debian_lover 6y agoBetter yet just install linux and if you need windows, use it in a locked down VM
- GekkePrutser 6y agoConceptually this makes sense. It doesn't really run Under windows, it runs beside windows. Unlike WSL1 which was basically part of Windows. It's strange tcpdump doesn't run though as WSL2 is running a real kernel. Personally I really liked the resource efficient WSL1 approach and I lament that they dropped it. But I know for some usecases (e.g. docker) a real Linux kernel was needed.
- muststopmyths 6y ago>It's strange tcpdump doesn't run though as WSL2 is running a real kernel. It works just fine. Just tested it
- qz2 6y agoTry dumping UDP packets from the host to the WSL machine...
- rrdharan 6y agoIt was theoretically more resource efficient but practically worse and harder to optimize. A state of affairs that VMware has exploited for a couple decades.
- muricula 6y agoWere you using WSL 1 or 2? WSL 1 networking didn't work the way I expected, but WSL 2 seems to support proper Linux networking since it's just a Linux VM under the hood.
- mikece 6y agoI would think that anyone who relies on a VPN for safety or is really particularly security conscious (1) isn't using Windows 10, (2) has networking disabled if they are using it, for example, in a VM, and (3) is probably using a dedicated device like a Slate router or pfSense box as their VPN point.
- jetpackjoe 6y agoWith the way these companies advertise, they make it seem like a silver bullet for internet anonymity. Almost every YouTube video I've seen recently seems to have one as a sponsor, and I am sure they are picking up many non-technical customers. I don't think users of NordVPN, ExpressVPN, MullvadVPN et al. are as sophisticated as you think.
- mikece 6y agoThe way Express VPN's ad copy reads it seems their own people don't understand the difference between encryption and traffic tunneling (much less encryption in transit versus encryption at rest).
- jeroenhd 6y agoThe non-technical customers probably aren't running WSL2 either. In fact I think very few of them actually need a VPN. Those who torrent in litigious countries have a benefit from their VPN provider but I doubt most others don't know about the behaviour changes that need to take place to make a VPN effective. I think VPNs can be a powerful tool for many people who would normally not be able to find out about their existence, but the predatory nature modern VPN ads have taken is quite sad. This leads to some cases of Youtube fan bases angrily calling out shitty VPN ads while the video creators just want to pay their bills, a situation nobody wants.
- GekkePrutser 6y agoIf they're not that sophisticated they probably won't use WSL anyway though, so it's not a huge issue in that sense (unless some malware specifically installs WSL2 to get around it).
- 6y ago
- the8472 6y agoSometimes that's a feature. At least with VirtualBox I have made the experience that NAT virtual networking leads to significant slowdown on a linux guest compared to bridging one of the host's ethernet adapters. I suspect that's due to windows' firewall software or similar things happening in the host system. It also means one less hop to debug when it comes to network issues. I think the question is whether you consider a VM more like another machine in your network that merely happens to run on the same hardware or a part of the host system.
- rrobukef 6y agoFrom a firewall POV: Can the host system reliably interact mechanically with the VM? I.e., can the host get root in the VM? If so, a firewall only reduces the attack surface by eliminating the obvious.
- Angeo34 6y agoMicrosoft code has bugs in privacy relevant code? Next you gonna tell me DDG and Brave are honeypots? What a surprising coincidence.
- SebSebsensen 6y agoDid you even read the article or previous comments before the MS bashing reflexes kicked in?
- wanderr 6y agoRelated issue with some workarounds that people are reporting various levels of success with: https://github.com/microsoft/WSL/issues/5068 https://github.com/microsoft/WSL/issues/5068
- jeroenhd 6y agoPotential workaround: is it possible to configure VPN clients to _ignore_ the WSL2 runtime and instead run a VPN client inside WSL2? That way the Linux network config can deal with the Linux side of things and the Windows network config can deal with the Windows VPN routing. Of course you can just configure OpenVPN inside WSL2 and also run a VPN on the desktop but that's tunnels in tunnels and that way madness and network issues lies.
- Digit-Al 6y ago>Of course you can just configure OpenVPN inside WSL2 and also run a VPN on the desktop but that's tunnels in tunnels and that way madness and network issues lies. It's tunnels, all the way down :-)
- GekkePrutser 6y agoIf I read it correctly that wouldn't be tunnels in tunnels. It would be 2 separate tunnels side by side. Which is not necessarily a bad thing. WSL2 is basically a VM and any VM which binds directly to the Adapter (e.g. not NAT mode) will have the same behaviour. In some cases you'd even want it to do this.
- jeroenhd 6y agoIf I read the article correctly, the traffic only leaks when the VPN disconnects or reconnects. This means the default situation would be a tunnel inside a tunnel. WSL2's NAT is close to a standard Hyper-V NAT adapter but there's unexpected differences (like the localhost binding) that make it stand out.
- shmerl 6y agoUsing WSL should be a very last resort anyway. Just use Linux straight on your hardware if you have a choice and ditch Windows.
- debian_lover 6y agoThis. WSL is like supergluing a BMW motor to the hood of a burned out 1999 Honda Civic. Its still going to run like garbage no matter how much you put lipstick on that pig
- nikisweeting 6y agoIt's getting better all the time though, and it's way better than nothing when you don't have a choice.
- deleted 6y ago[deleted]
- Enginerrrd 6y agoYeah I've never understood the use case there exactly....
- shmerl 6y agoOne use case MS thought of was to give excuse to lazy corporate IT not to support Linux on the desktop, to prevent Windows usage dropping among developers. I think that was their main intent.
- Jonnax 6y agoWhy? In my opinion Linux desktop environments are terrible compared to Windows. How's the display scaling these days? Is it still a better experience to run a 4k monitor at a lower resolution? What's the Nvidia driver situation? Still janky because their drivers are doing their own thing?
- johnisgood 6y agoI have not experienced any NVIDIA driver related issues for over a decade. I cannot comment on the rest. I think there are great desktop environments and window managers for Linux.
- debian_lover 6y agoIs anyone really Surprised by this? If you want security then you dont use Windows. Windows subsystem for linux is a joke. Just install linux like everyone else
- wing-_-nuts 6y agoA bit off topic, but this sort of transparency is why I don't mind paying $6 / mo for a vpn when mullvad's competitors are much cheaper. Their wireguard support is great, and their speeds are much faster than what I got through openVpn on pia.
- Aaronstotle 6y agoAlso a huge fan of paying with BTC and their use of account ids instead of emails, wish they would accept XMR also.
- speedgoose 6y agoDid you consider the average pollution of bitcoin transactions?
- jdc 6y agoDo you have a number for us?
- CameronNemo 6y agocleancoins.io
- smartbit 6y agoGood question. OTOH, did anyone ever consider the average pollution of the banking system? 10.000th of banks, 200+ central banks, BIS, IMF, ECB, etc, etc. Millions of employees, millions of desktops & servers, day-in-day out. Anyone with a link to a guestimate?
- roywiggins 6y agoThere's no way that a single $6 credit card transaction uses as much energy as sending $6 worth of bitcoin, which is the relevant measure.
- sally1620 6y agoThis is the exact reason I didn't try running weird VPN configs like this. The reliable way is to run Linux inside a VirtualBox and have it connected to VPN on its own. Currently, I run Linux on a Xen domU and configure VPN client inside the guest. PS: I don't want all my traffic to go through VPN. Especially things like Netflix or Youtube where VPNs are blocked (and VPN BW is lower anyway).
- adriancr 6y agoYou can set up a docker vpn client as well
- sally1620 6y agoI tried docker. "Always Require VPN" didn't work with docker.
- adriancr 6y agoI do it like this, can provide scripts if you're interested. One docker image with openvpn: 1. at startup erases all routes except to VPN gateway and 8.8.8.8. 2. before and after connect it only has routes through VPN (no default ones - if vpn goes down, network goes down until re-established) Start it like: # ... --name vpn ... Another docker image with what I want VPNed gets started with the network of the first # ... --net container:vpn ... I keep a browser within the second docker image (firefox) and use my main machine to show it. Note: you want to pass '--no-remote' to it and likely split /dev/shm It can't really leak since it doesn't have routes to do anything other then through VPN.
- garethrowlands 6y agoWSL2 _is_ Linux inside a VM that's a peer of Windows. Having it connect to VPN on its own is _exactly_ what you have to do.
- sally1620 6y agoIt is a VM with a lot of hacks. For most tasks it is good but for complicated situations it will get you. I used to run Linux VM inside HyperV before WSL2 released, and it worked like a charm. WSL2 just adds a lot of hacks to integrate Windows & Linux experience.
- AndrewDucker 6y agoSo, if I'm understanding correctly the Linux system gets access to the raw Ethernet system, and so bypasses the Windows firewall. Seems not entirely unreasonable - if you want Linux to use a firewall then install one into it. But it should definitely be well publicised/documented, because otherwise people won't realise they have a gaping hole in their greens m defences.
- ajross 6y agoRight, this is as much a feature as it is a bug. But it's absolutely something that should be documented and under control of the host-side security layer.
- logical_person 6y agovmswitch is configurable by the host. these VPN authors have no clue what they're doing, windows firewall rules should not in any case be applied to traffic coming from a VM. ridiculous.
- rbanffy 6y ago> windows firewall rules should not in any case be applied to traffic coming from a VM I can't agree with this. Everything is running on Windows. The VM runs on Windows and WSL exchanges data with Windows all the time. That the data on the Windows side can leak because I installed a Microsoft-approved product from the Microsoft store on a Windows box with a Microsoft firewall is unacceptable.
- kodablah 6y agoI have noticed similar simply because the Cisco AnyConnect client doesn't work with WSL2 and is a known issue [0]. But that seemed to be blocking traffic instead of just allowing all traffic over non-VPN. However, openconnect does work fine as does the UWP-based AnyConnect client. I wonder how those latter two are successful tunneling traffic (or if it's only if they are started before the wsl2 vm is). 0 - https://github.com/microsoft/WSL/issues/4277 https://github.com/microsoft/WSL/issues/4277
- filmgirlcw 6y agoYeah, there are some issues with some corporate VPNs and WSL2 right now (disclosure: I work at Microsoft but not on WSL2 but I’ve been in touch with that team regarding some of the issues) that are actively being worked on. I think that’s a bit different than this, though it’s possibly related. As you said, the situation there is traffic is blocked. WSL and WSL2 are fundamentally different in how they work. In fact, the poor I/O performance (caused in part by Windows Defender) in WSL is part of what led to the Hyper-V based approach to begin with. My guess is that something might need to change either in the way VPNs use the firewall rules in Windows when passing on to WSL2 or in WSL2 to make for more granular control over how that stuff is passed on - to address the Mullvad. Because as it stands now, the way Mullvad performs under WSL2 seems to be by design (by WSL2 design, if not Mullvad’s design). Obviously, many users who enable a VPN in Windows will want that connection to persist when they use WSL2 — but I can also think of plenty of scenarios where that might not be the case, which I imagine makes coming up with a solution more difficult. I will say, the WSL2 team is incredibly responsive to feedback. You can file issues on GitHub and the team is very active on Twitter. If this is something that can be fixed on the WSL2 side, I feel confident the team will work to do it.
- mdoms 6y ago> But that seemed to be blocking traffic instead of just allowing all traffic over non-VPN Not what's happening here (despite the title).
- smarx007 6y agoThe title is wrong. The VPN traffic does NOT leak. What leaks is the traffic that the VPN software tries to block when the VPN connection is not active. Mullvad uses Windows Firewall to block all internet access if VPN is not active (if the user configured so) and WSL2 bypasses this by not going through Windows Firewall. When the VPN is active, WSL2 traffic IS tunneled through the VPN. UPD: The solution may be to have Windows Firewall rules apply to WSL2 or have Mullvad control Linux internet access through on-the-fly UFW settings update or completely disconnect internet (but that likely does not work nicely and is why Mullvad went for the Windows Firewall based solution in the first place).
- closeparen 6y agoA good reminder that you really want proxying done on a separate device (router, Raspberry Pi, etc) physically between the endpoint and the internet.
- smarx007 6y ago1000 times this. See https://mullvad.net/en/help/openwrt-routers-and-mullvad-vpn/ https://mullvad.net/en/help/openwrt-routers-and-mullvad-vpn/ for a relevant guide, see under the "Add a kill switch" for the equivalent functionality.
- vmception 6y agoDoes anyone have a raspberry pi hardened disk image for this? I just don't have time to troubleshoot all these things anymore
- gerdesj 6y agoThis sounds like working as designed and not a flaw. If your Linux box needs a firewall then put one on it. As the article says, the VM is using Hyper-V networking so it is likely that the connection is either bridged with a virty software switch or is NATted in some way but with a short cut through the host firewall. If the VM has an IP on your LAN it is bridged and if it doesn't and you don't have to fiddle with your internet router then NAT is in play. Linux has lots of options for firewalling. For Windows sysadmins, firewalld with a GUI could be a reasonably familiar option. Failing that, ufw is quick and reasonably easy for simple use cases. If you are feeling macho, then roll your own with iptables or nftables. The last time I did that properly was with ipchains ...
- Animats 6y agoWhy would someone run a VPN client on Linux under Windows, anyway, as opposed to just running it on Windows?
- Bedon292 6y agoThey are running it on Windows. It attempts to deny all outbound traffic if the VPN is not connected, but the WSL2 traffic does not follow that rule and gets out anyways.
- agustif 6y agoI can't even get mine to work or install at my work machine...
- Bedon292 6y agoDocker on Windows can run on WSL2 backend as well. So I assume this would also apply to Docker traffic too. Other interesting note, Docker Windows does some funky stuff with firewalls too. It puts and any/any exception in the firewall when you install it [1]. So may also be important to know with VPN stuff. [1] https://twitter.com/richturn_ms/status/1270766764356366336 https://twitter.com/richturn_ms/status/1270766764356366336
- yjftsjthsd-h 6y ago> Other interesting note, Docker Windows does some funky stuff with firewalls too. It puts and any/any exception in the firewall when you install it It does something similar on Linux, actually. Huge pain when trying to firewall servers only to discover that Docker happily bypasses all of your rules.
- stefan_ 6y agoIf you run your VPN tunnel on the same machine that is emitting your super-serious must-be-tunneled traffic, you are always just one configuration mishap or even software exploit (if you happen to be a Firefox Tor browser user) away from revealing your real connection.
- crb002 6y agoIs there a wireshark config for WSL2 so you can browse traffic? eBPF support in WSL2 sufficent?
- vilifiedtwin 6y agoCan't you run VPN client on the Linux guest? I think it is good that the Linux subsystem bypasses Windows firewall.
- deleted 6y ago[deleted]
- siproprio 6y agoWSL 2 also leaks memory, by default it consumes up to 4GB. It's awful.
- donor20 6y agoThe idea of the a linux distribution is going to be using the WINDOWS firewall?? seems a bit crazy to me. I expect the distributions on WSL to use their own firewall - that's half of the fun of using WSL. PLEASE don't push fake news like this that results in distribution on WSL having to deal with / modify the window firewall - that would be a total nightmare!
- mehrdadn 6y agoMy guess is people are confused because Microsoft has marketed WSL2 as a replacement for WSL1, and it makes sense for WSL1 to go through the Windows firewall, so people assumed WSL2 would behave similarly.
- fphhotchips 6y agoIf nothing else, I now understand that I'm going to have to read up more on how WSL2 actually works, because I found WSL1 to be a really elegant way of running Linux on Windows without having a whole bunch of virtualisation in place, but it sounds like there's more virtualisation now, and also Hyper V networking has previously broken my network stack.
- mehrdadn 6y agotl;dr is WSL2 is just a VM running under Hyper-V. The host is hence Hyper-V, not Windows.
- AcerbicZero 6y ago"WSL2 uses Hyper-V virtual networking and therein lies the problem" Pretty much sums it up.
- xnyan 6y agoI can’t re-create the issue with the mullvad client, or on my work-issued laptop with the Cisco Any-Connect VPN. Everything is dropped the second the VPN goes up.
- maple3142 6y agoA little bit off-topic, but I have a problem with WSL2 and Wireguard for Windows. When I enable Wireguard for Windows, WSL2's default DNS server will stop working, but directly setting dns server to 8.8.8.8, 1.1.1.1 or something similar works.
- ani-ani 6y agoThis is due to Hyper-V, which is being rolled out on Windows 10 and required for WSL2. The OS is now running as a VM, and virtualized programs like WSL2 are running alongside - these VMs can't control each other's traffic. It's interesting that a feature meant to improve sandboxing actually makes firewalling and VPN more difficult, in its current state. I think the the proper fix is at the Hyper-V level, which might need to explicitly manage firewall and VPN features.
- Rapzid 6y agoWindows 10 can control the Linux VMs traffic because it can control Hyper-V.
- pjmlp 6y agoNope, it can request Hyper-V to do stuff, just like any other guest.
- ani-ani 6y agoWe're using vague terms, but the point is that controlling the VM is not the same thing as controlling the VM's traffic, especially in the model where your OS is not actually hosting the VM (since Hyper-V is a type 1 hypervisor).
- Rapzid 6y agoI believe my statement holds true for any practical purpose being discussed, and it's particularly aimed at type 1 hypervisors. In a Xen setup you wouldn't say "dom0 doesn't control the vm traffic". It controls the hypervisor. The root partition is the same way in hyper-v: Root Partition – Manages machine-level functions such as device drivers, power management, and device hot addition/removal. The root (or parent) partition is the only partition that has direct access to physical memory and devices. It may not automatically send traffic through the windows FW because the networking setup now has traffic on a virtual switch/bridge, but the VPN creators have all the access they would ever need to control the networking from the root partition..
- ncmncm 6y agoFor reference, this kind of problem is avoided on QubesOS (another, Xen-based, hypervisor system) by routing all traffic through another VM that entirely owns the network hardware. I run my Wireguard on that VM. The host OS image, dom0, also routes its network traffic through that VM, to get updates. (It doesn't trust the updates it gets that way; it checks their signatures.) QubesOS provides another VM as a dedicated firewall just to route untrusted guests' traffic through, first. With enough cores, it all runs fast. For many users, all guest VMs are untrusted. Dodgy programs like browsers get their own VMs, spun up as needed and discarded. That does take a fair bit of RAM; my maxed-out 16GB laptop notices the strain. But memory is cheap these days, if you have the sockets to put it in. As an aside, dom0 also mediates access to the UI hardware, including display RAM. Each guest can run X, but its pixels are copied to the real display by dom0. Guest VMs can't see one another's pixels or input traffic. dom0 also mediates access to audio and video streams, and can route them to selected VMs as needed. (In a future release they plan to manage the display in its own VM, because display drivers are a big attack surface of their own.) It all works astonishingly well. Incidentally, this model of a hypervisor with all the user-level OSes as VMs, including the host, originated at IBM in the 1960s. That worked in a megabyte or two, which seemed like a lot at the time.
- erredois 6y agoThis is interesting, I wonder if it's possible to simulate this behavior configuring the hyper-V networking layer.
- ncmncm 6y agoAlmost certainly. I know of people who run Windows 10 in a Qubes VM. It is dizzying to think of what they are really doing: running a Hyper-V system, with its own VMs, in a VM on a Xen hypervisor.
- dagaci 6y agoLet me get this right: Installing WSL2 causes HyperV to be installed. When Hyper-V is installed, HyperV replaces Windows as the Machine Host. Therefore Windows itself becomes a guest OS of Hyper-V, and the installed Linux also becomes a guest of HyperV. So what mullvad would prefer is that Linux traffic to be routed through the adjacent Windows Guest by default, so that the windows software can control the Linux network traffic. I think a better solution would be to explore creating a VPN solution for HyperV OS itself if possible...
- darumderum 6y agoAs I can bypass Kaspersky SSL interception for basically the same reason, I see this as a win and hope it won't change
- j0057 6y agoStrange then that the WSL2 guest gets a RFC1918 private address, because that would imply that the host is NATing traffic to and from the guest. However that does not happen through the ordinary Hyper-V NAT routing machinery -- at least Get-NetNat shows nothing in Powershell and in fact multiple people have reported broken WSL2 networking because they had leftover NAT rules from old Hyper-V VM's. It would help to have some conceptual documentation here about what WSL2 is doing.