16 ms·
GotaTun – Mullvad's WireGuard Implementation in Rust
- bjhsuw8ud 10mo ago[flagged]
- nevi-me 10mo agoIf anyone working on the implementation is here, was it not possible to upstream your changes to BoringTun? The blog mentions some changes but doesn't go into detail on that aspect.
- embedding-shape 10mo agoI'm guessing because BoringTun has been in a state of "currently undergoing a restructuring" for something like 3 years by now, I'm guessing Mullvad wasn't too keen to maybe/maybe not be able to contribute, and much more prefer being in 100% control of their own implementation. As someone who wants to see Wireguard succeed and in even wider use, this move makes sense from that perspective too. The more implementations we have available, the more we can trust that the protocol is secure and stable enough. Personally I also have about 100x more trust in Mullvad than Cloudflare both in terms of security but more importantly privacy, but that's just the cherry on top.
- kevincox 10mo agoBoringTun is unmaintained. There are various forks being developed. I work at Obscura VPN and faced with boringtun bugs a few years ago we evaluated a few of the forks and switched our client to be based on top of NepTUN (https://github.com/NordSecurity/NepTUN https://github.com/NordSecurity/NepTUN). I am curious why Mullvad started their own fork rather than building on top of one of the existing ones. It would be nice if there could be reconsolidation somewhere.
- ur-whale 10mo agoOne meta thing I've always wondered ... Are multiple implementations of the same protocol good or bad for security? Probably naively, I'm thinking: - diversity: good - doubling the attack surface: real bad What do the security folks out there think of the topic?
- stevefan1999 10mo agoThat's really good because it means it will be able to have more exposure, more exposure means more improvement, more improvement eventually dig out bad bugs and reduces the attack surface in the long run
- embedding-shape 10mo agoI think the general consensus is that it improves security of the protocol, but obviously that won't matter much if the implementation gets something wrong or has worse security by itself. Issues in the protocol itself would need all implementations to change, but issues in the implementation would obviously be isolated to one implementation. For something like Wireguard, I'd wager a guess that issues in the implementations are more common than issues in the protocol, at least at this stage.
- VoxPelli 10mo agoIf the implementation gets it wrong that can also be a sign of ambiguity in the protocol / standard and as such result in clarifications and an overall more well specified protocol
- mwalser 10mo agoI wouldn't say that multiple implementations are duplicating the attack surface since most users will not end up running them in parallel.
- ur-whale 10mo agoI meant at a global level (think as if you're attacking all wireguard users, not a single one)
- swiftcoder 10mo agoThe increased attack surface mostly only affects that one particular implementation though. So, yes, twice as many implementations that may contain exploitable bugs, but each new implementation could only be used to exploit a fraction of the total user base
- turblety 10mo agoNice, I love WireGuard. I ended up building WrapGuard [1] to run applications without root access to the host and choose Go to write it in. I don't really know Rust, but does it make more sense for firmware/networking type software? Is there even a difference? 1. https://github.com/puzed/wrapguard https://github.com/puzed/wrapguard
- skylurk 10mo agoPick the devil you know, as they say.
- unrealhoang 10mo agofrom TFA, the main advantage would be for embedded (as a library) use case, FFI with Go is harder.
- maxmcd 10mo agoI believe you are making use of gVisor’s userspace TCP implementation. I’m not sure if there is something similar in Rust that would be so easy to set up like this.
- gwehrli 10mo agoThere isn't something as mature as gVisor afaik. https://github.com/smoltcp-rs/smoltcp https://github.com/smoltcp-rs/smoltcp implements many of the same abstractions as gVisor.
- chjj 10mo agoVery cool project. Is it always an LD_PRELOAD or can it function as a standalone SOCKS proxy similar to wireproxy?
- turblety 10mo agoThanks chjj. Yeah it's always LD_PRELOAD. There is wireproxy [1] though that might do what you want? 1. https://github.com/whyvl/wireproxy https://github.com/whyvl/wireproxy
- imcritic 10mo agoI wish they would improve wireguard-the-protocol as well: wireguard doesn't stand a chance against gov/isp blocks.
- razighter777 10mo agoThat's more of a job for an encapsulating protocol. (shadowsocks or similar) Wireguard isn't designed to be obfuscating alone. It's just a simple l3 udp tunnel with a minimal attack surface.
- Hendrikto 10mo ago> It's just a simple l3 udp tunnel Wait, isn’t UDP L4? Am I missing something?
- nrds 10mo agoThat's the traditional answer parroted in the Wireguard documentation but a few hours' serious thought and design is enough to reveal the fatal flaw: any encapsulating protocol will have to reinvent and duplicatively implement all of the routing logic. Perr-based routing is at least 50% of wireguard's value proposition. Having to reimplement it at the higher level defeats the purpose. No, obfuscation _has_ to be part of the same protocol as routing. (Btw, same sort of thing occurs with zfs combining raid and filesystem to close the parity raid write hole. Often strictly layered systems with separation of concerns are less than the sum of their parts.)
- gvkhna 10mo ago
- Hakkin 10mo agoI definitely noticed the performance boost on my Pixel 8, for some reason it seems to really not like wireguard-go, it struggled to pull even 100mbps, maybe something unoptimized on Google's custom hardware. With the new GotaTun version I can pull 500mbps+, though unfortunately it also seems to have introduced a bug that randomly prevents the phone from entering a deep sleep state, so occasionally my battery will randomly start draining at 10x normal speed if I have it enabled until I reboot.
- Hasnep 10mo agoOh, this is the reason the Mullvad app on my Pixel 6a was suddenly able to connect in less than a second where before it would take 5-10 seconds, nice!
- vjerancrnjak 10mo agoSame behavior on raspberry pi 5. Might be just lack of arm optimizations.
- wyldfire 10mo agoIt's very likely that VPNs like this are not CPU-bound, even on somewhat whimpy CPUs. I'd wager even some microcontrollers could sling 500megabits/sec around without trouble.
- formerly_proven 10mo agoYou’re in for a surprise then once you actually go look at the performance.
- rcoder 10mo agoA Raspberry Pi 4 can manage something like 70Mbps of raw AES en/decryption flow: https://github.com/lelegard/aesbench/blob/main/RESULTS.txt https://github.com/lelegard/aesbench/blob/main/RESULTS.txt That CPU is pretty much a toy compared to (say) a brand-new M5 or EPYC chip, but it similarly eclipses almost any MCU you can buy. Even with fast AES acceleration on the CPU/MCU — which I think some Cortex MCUs have — you’re really going to struggles to get much over 100Mbits of encrypted traffic handling, and that’s before the I/O handling interrupts take over the whole chip to shuttle packets on and off the wire. Modern crypto is cheap for what you get, but it’s still a lot of extra math in the mix when you’re trying to pump bytes in and out of a constrained device.
- intsunny 10mo agoIts funny, this is another of the billions of reasons why Mullvad should be the VPN of choice. But so many fucking people can't ever get over that their favorite social media influencer/Youtuber is offering a code for 200% off of NordShark VPN, now with extra AI.
- swexbe 10mo agoI wish I could use Mullvad. But their IPs are banned from many streaming services and they don't change them often enough so I am stuck with Nord.
- puffybuf 10mo agoI would just pirate at that point. You're paying for the streaming service anyways. Use mullvad to download the torrent :). I'm pretty sure they ignore dmca requests. Not that they even know their customer's names if you pay with Mullvad amazon card.
- tumdum_ 10mo agoYou do know that NordSec maintains its own rust fork of BoringTun: https://github.com/NordSecurity/NepTUN https://github.com/NordSecurity/NepTUN ? :)
- gwehrli 10mo agoThere is also https://github.com/firezone/boringtun https://github.com/firezone/boringtun which is a fork by https://www.firezone.dev/ https://www.firezone.dev/
- eatbitseveryday 10mo agoIt became less of a choice for many after they sadly had to disable port forwarding.
- jorvi 10mo agoYeah, their reasoning is solid (easy to abuse) but it is still a very useful feature. AFAIK, at the moment your choices are AirVPN and ProtonVPN. AirVPN has static port forwarding and Proton has UPNP port forwarding.
- alias_neo 10mo agoIs there any way to switch to this implementation for generic WireGuard users? I tried downloading their Android app, but it's not generally usable for people who host our own WireGuard, which is fair enough.
- wasmitnetzen 10mo agoThe github repo is linked in the post which has build instructions: https://github.com/mullvad/gotatun https://github.com/mullvad/gotatun
- mintflow 10mo agoFor the similar reason I do not using any go based proxy code in my MintFlow app, and use rust to implement some proxy protocols. But my app’s wireguard is natively implemented by fdio vpp plugin, so it’s based on C.
- Bigpet 10mo agoI would not have guessed that iOS allows enough access to APIs to implement anything vpp-based. Very cool to see. I also enjoyed working with vpp (for the brief 6 months that I had with it).
- mintflow 10mo agoI was thinking that's hard, but I noticed that vpp get ported to FreeBSD using epoll shim library, and I learnt apple Darwin use some some userland of FreeBSD to do POSIX compatibility, then after some tests and hacking, most related to minor POSIX API adaptation such as mmap and one major coroutine need add some assembly code, and it work! But I think most disappointed to me is that apple do lack some vectorized network IO unless do some kernel extension or other sort non standard ways.
- jpxfrd3232 10mo ago[flagged]
- codethief 10mo agoFingers crossed that GotaTun will also make its way into the Tailscale Android app (since that's what I use to connect to Mullvad).
- ignoramous 10mo agoGotaTun is specific to Mullvad and the features they usually add make sense for a public VPN provider. Unlikely projects such as Tailscale adopt it. Besides, engineers at Tailscale, I don't think, strike me as startled by any hurdle too tall to debug, improve Go-based libraries. In fact, they pushed wireguard-go past 10gbps on Linux-based platforms back in April 2023! https://tailscale.com/blog/more-throughput https://tailscale.com/blog/more-throughput
- barfoure 10mo ago[flagged]
- gpm 10mo agoThey didn't. They forked an old unmaintained thing already written in rust to add new features...
- johnisgood 10mo agohttps://dosaygo-studio.github.io/hn-front-page-2035/news-honest.html https://dosaygo-studio.github.io/hn-front-page-2035/news-hon...
- apitman 10mo agoI would love to see more root cause analysis data on the crashes they were seeing with wireguard-go. I wonder if it was bugs in the library itself, or the FFI.
- 01HNNWZ0MV43FF 10mo agoYeah I'm surprised by that. I thought Wireguard was so simple and wireguard-go was so popular that it wouldn't crash. It's just UDP packets.
- hhdhwhw 10mo ago[flagged]
- huflungdung 10mo ago[dead]
- ex-aws-dude 10mo ago[flagged]
- coppsilgold 10mo agoCan you use DAITA with just gotatun (on linux) or do you require the Mullvad daemon?
- drexlspivey 10mo agoI thought Wireguard runs inside the kernel on Android since it ships as part of Linux now.
- kavouras 10mo agoI think it has to be enabled as a module, and the android kernel has it disabled.
- criticalfault 10mo agoAs far as I know, you need root permissions to add an interface. Even though the module is enabled, it's not used. The official wireguard app also mentions wireguard-go
- angristan 10mo agoApparently the module is there: https://www.xda-developers.com/google-adds-wireguard-vpn-android-12-linux-kernel-5-4/ https://www.xda-developers.com/google-adds-wireguard-vpn-and... But you need to be rooted to use it: https://lists.zx2c4.com/pipermail/wireguard/2022-September/007819.html https://lists.zx2c4.com/pipermail/wireguard/2022-September/0...
- cboyardee 10mo ago[dead]
- stronglikedan 10mo agoNow that's how you name things!
- vsgherzi 10mo agothe linked issues are quite interesting, why does go have to page in so much memory for the GoString? Is this for some sort of optimization? https://github.com/mullvad/mullvadvpn-app/pull/6727 https://github.com/mullvad/mullvadvpn-app/pull/6727 if anyone else is more familiar with go (I only really do rust) is there no solution to preventing stack smashing on goroutines? https://github.com/mullvad/mullvadvpn-app/pull/7728 https://github.com/mullvad/mullvadvpn-app/pull/7728 I understand that go routines have a smaller stack size (the whole green thread problem) but there's no way to fix this?
- Rawa 10mo agoIt was solved in another PR by using an alternate stack by setting the flag SA_ONSTACK.
- ballpug 10mo ago[dead]
- electromech 10mo agoIt looks like GH Issues are disabled. https://github.com/mullvad/gotatun https://github.com/mullvad/gotatun It's unclear where to report problems, suggestions, etc.
- yablak 10mo agoHope tailscale adopts this
- manuchojose76 9mo ago[dead]