4 ms·
We have tested a few other VPN clients from competitors and found that all of them leak in the same way. The way Microsoft has implemented virtual networking fo
by Voline 6y ago
We have tested a few other VPN clients from competitors and found that all of them leak in the same way. The way Microsoft has implemented virtual networking for Linux guests makes it very difficult to properly secure them.
- qz2 6y agoIt’s a shit show. Can’t trace packets either via wireshark on the host and tcpdump doesn’t work on the guest. I’ve gone back to virtualbox and eviscerated WSL. Another total waste of my life.
- debian_lover 6y agoBetter yet just install linux and if you need windows, use it in a locked down VM
- GekkePrutser 6y agoConceptually this makes sense. It doesn't really run Under windows, it runs beside windows. Unlike WSL1 which was basically part of Windows. It's strange tcpdump doesn't run though as WSL2 is running a real kernel. Personally I really liked the resource efficient WSL1 approach and I lament that they dropped it. But I know for some usecases (e.g. docker) a real Linux kernel was needed.
- muststopmyths 6y ago>It's strange tcpdump doesn't run though as WSL2 is running a real kernel. It works just fine. Just tested it
- qz2 6y agoTry dumping UDP packets from the host to the WSL machine...
- rrdharan 6y agoIt was theoretically more resource efficient but practically worse and harder to optimize. A state of affairs that VMware has exploited for a couple decades.
- muricula 6y agoWere you using WSL 1 or 2? WSL 1 networking didn't work the way I expected, but WSL 2 seems to support proper Linux networking since it's just a Linux VM under the hood.
- mikece 6y agoI would think that anyone who relies on a VPN for safety or is really particularly security conscious (1) isn't using Windows 10, (2) has networking disabled if they are using it, for example, in a VM, and (3) is probably using a dedicated device like a Slate router or pfSense box as their VPN point.
- jetpackjoe 6y agoWith the way these companies advertise, they make it seem like a silver bullet for internet anonymity. Almost every YouTube video I've seen recently seems to have one as a sponsor, and I am sure they are picking up many non-technical customers. I don't think users of NordVPN, ExpressVPN, MullvadVPN et al. are as sophisticated as you think.
- mikece 6y agoThe way Express VPN's ad copy reads it seems their own people don't understand the difference between encryption and traffic tunneling (much less encryption in transit versus encryption at rest).
- jeroenhd 6y agoThe non-technical customers probably aren't running WSL2 either. In fact I think very few of them actually need a VPN. Those who torrent in litigious countries have a benefit from their VPN provider but I doubt most others don't know about the behaviour changes that need to take place to make a VPN effective. I think VPNs can be a powerful tool for many people who would normally not be able to find out about their existence, but the predatory nature modern VPN ads have taken is quite sad. This leads to some cases of Youtube fan bases angrily calling out shitty VPN ads while the video creators just want to pay their bills, a situation nobody wants.
- GekkePrutser 6y agoIf they're not that sophisticated they probably won't use WSL anyway though, so it's not a huge issue in that sense (unless some malware specifically installs WSL2 to get around it).
- 6y ago
- the8472 6y agoSometimes that's a feature. At least with VirtualBox I have made the experience that NAT virtual networking leads to significant slowdown on a linux guest compared to bridging one of the host's ethernet adapters. I suspect that's due to windows' firewall software or similar things happening in the host system. It also means one less hop to debug when it comes to network issues. I think the question is whether you consider a VM more like another machine in your network that merely happens to run on the same hardware or a part of the host system.
- rrobukef 6y agoFrom a firewall POV: Can the host system reliably interact mechanically with the VM? I.e., can the host get root in the VM? If so, a firewall only reduces the attack surface by eliminating the obvious.