5 ms·
I think selective application tunneling for windows is an incredibly useful thing and I wondered for a long time why it wasn't more popular until I realized how
by brndnbuilds 4y ago
I think selective application tunneling for windows is an incredibly useful thing and I wondered for a long time why it wasn't more popular until I realized how difficult it is to implement.
TunnlTo uses WireSock https://www.wiresock.net/ https://www.wiresock.net/ which is a custom network driver built by Vadim Smirnov. He'll be on later to answer any technical questions. He is the expert in networking and kernel level drivers.
I wouldn't call it bullet-proof enough for a killswitch yet but certainly is something we're working towards. The response so far from HN is encouraging so it looks like it will be worthwhile dedicating more time to the project to get it to that level.
- hexmiles 4y agoI also would love to know how it was able to do it. I tried implemented something similar for an application, but I wasn't able to tunnel only selected application in the end I use a SOCKS proxy and manually configured the application that I wanted to use it, but it would love a less "hacky" way to do it (not all app support SOCKS proxy).
- muststopmyths 4y agoYou keep saying driver, but wiresock says it’s usermode. Can you clarify ? Not trying to be a jerk, just that I’d be more inclined to try out a purely usermode application than install a driver.
- zacharachnia 4y agoI assume since Wiresock is using BoringTun(https://github.com/cloudflare/boringtun https://github.com/cloudflare/boringtun) under the hood, it works similar to other userspace implementations of wireguard, (e.g. wireguard-go, wireguard-rs) in that it uses a TUN device to deliver packets to the userspace implementation, and back out to the network. So, no driver installation required, but CAP_NET_ADMIN is required to create the TUN device.