4 ms·
WG itself doesn't support user authentication of any kind, it's just a tunnel. If you have the right key and send a properly signed packet WG will pass it. Encr
by hendersoon 2y ago
WG itself doesn't support user authentication of any kind, it's just a tunnel. If you have the right key and send a properly signed packet WG will pass it. Encryption keys are not authentication in of themselves.
- adtac 2y ago> properly signed packet How would an adversary do this without the private key? Wireguard uses ChaCha20Poly1305, an AEAD scheme. The first A stands for Authenticated.
- arrakeenrevived 2y agoThis is pedantism, and is also just wrong. "if you have the right key" IS authentication. Encryption keys are used as a form as authentication all the time, it's one of the main use cases of public/private key encryption. I challenge you to explain how OpenSSH does non-password authentication without referring to encryption. Authentication just means proving who or what you are. Secret keys, whether they be passwords or encryption keys, are one of the primary ways to do this. Just because the key is also used for something else in addition to, or as part of, that process doesn't change it from being authentication.
- yjftsjthsd-h 2y agoWell, regular WG authenticates at the host level (roughly), not the user level, which can matter. I think this actually does auth at the user level, but there is some nuance there.
- yjftsjthsd-h 2y agoIf the tool runs in userspace and authenticates with a key stored in the user's home directory, isn't it authenticating the user? AIUI this isn't running a generic tunnel; it's shuffling packets inside the program and then putting WG UDP on the wire.
- beeboobaa3 2y ago...much like an ssh key?
- lyu07282 2y agoWhich can have a passphrase and an agent, all sorts of MFA. One benefit to wireguard though is it's using UDP with a much less noisy handshake, you will never even know if the port you tried connecting to runs it (if your firewall is configured correctly). It's much more stealthy, an ssh server will pronounce it's version banner and public host key to literally anyone.