3 ms·
Doesn’t creating a raw socket need elevated permissions?
by nynx 2y ago
Doesn’t creating a raw socket need elevated permissions?
- tptacek 2y agoThey're not creating raw sockets†. The neat thing about WireGuard is that it runs over vanilla UDP, and presents to the "client" a full TCP/IP interface. We normally plug that interface directly into the kernel, but you don't have to; you can just write a userspace program that speaks WireGuard directly, and through it give a TCP/IP stack interface directly to your program. † I don't think? I didn't see them say that, and we do the same thing and we don't create raw sockets.
- vlovich123 2y agoSo it tunnels TCP/IP over Wireguard UDP?
- tptacek 2y agoCorrect (I mean, that's fundamentally what WireGuard is: a UDP TCP/IP tunnel, with strong modern encryption).
- ignoramous 2y agoYes; also see: https://github.com/WireGuard/wireguard-go/blob/12269c2761734b15625017d8565745096325392f/tun/netstack/examples/http_client.go https://github.com/WireGuard/wireguard-go/blob/12269c2761734...