4 ms·
Agreed. You're already setting up SSH and deleting it soon so why bother setting up the IPs, adding your public key, getting the server's public key, configurin
by 0xCMP 5y ago
Agreed. You're already setting up SSH and deleting it soon so why bother setting up the IPs, adding your public key, getting the server's public key, configuring iptables, and configuring wireguard locally when you could just SSH?
Only benefit I'd see is wireguard would be easier to use on a mobile device, but the setup requires the ability to run ansible and do ssh already so... that's not really practical.
- yjftsjthsd-h 5y ago> why bother Last I checked, wireguard had much better performance than sshuttle. May or may not matter for your use case, but it's a reason.
- NavinF 5y agoYes! Last time I used sshuttle (bypassing content blocks in India by tunneling to a server in the US), my bandwidth dropped from 10mbps to 1mbps. Back then wireguard didn’t exist, but IPSEC could easily saturate the 10mbps link. I suspect it’s a combination of TCP-over-TCP and a horrible default buffer size that makes sshuttle unusably slow.
- ignoramous 5y agoYou don't need VPNs to bypass censorship blocks in India. Well, at least in my experience. Apps that manipulate TCP packets locally to break fingerprinting [0] like GoodbyeDPI (Windows) [1], GreenTunnel (cross platform CLI) [2], Intra (Android) [3] have been adequate. [0] https://nitter.net/vinifortuna/status/1304189371688660992 https://nitter.net/vinifortuna/status/1304189371688660992 (https://twitter.com/vinifortuna/status/1304189371688660992 https://twitter.com/vinifortuna/status/1304189371688660992) [1] https://github.com/ValdikSS/GoodbyeDPI https://github.com/ValdikSS/GoodbyeDPI [2] https://github.com/SadeghHayeri/GreenTunnel https://github.com/SadeghHayeri/GreenTunnel [3] https://github.com/Jigsaw-Code/intra https://github.com/Jigsaw-Code/intra
- NavinF 5y agoNeat! I’ll keep that in mind next time I travel. Tho I’d still use a self-hosted VPN to hide the destination IP when I don’t mind the latency.
- birdyrooster 5y agoTry using DNS VPN on an airplane to bypass in-flight internet paywall, now that is some unusably slow internet. Still works though magically.
- NavinF 5y agoI assume you’re talking about tunneling TCP over DNS queries. Does that really work on airplanes? A link to the code would be appreciated. I thought captive portals force you to use their DNS servers by grabbing all UDP packets with the DNS port (regardless of destination IP) and those servers respond with the webserver’s IP regardless of what you query.
- birdyrooster 5y agoIt does TXT record lookups or equivalent. Those get resolved correctly without any interference from the captive portal. Here is something similar in technical nature to what I have used in the past (free DNS VPN apps on ios) https://github.com/JadenGeller/Burrow-Client https://github.com/JadenGeller/Burrow-Client
- anderspitman 5y agoPretty sure sshuttle doesn't suffer from TCP over TCP, similar to how normal SSH tunnels don't because they operate at layer 4 and copy the bytes manually onto the multiplexed connection. Layer 2-3 tunnels is typically where you run into issues.
- NavinF 5y agoAh you’re completely right.