5 ms·
I wish they would improve wireguard-the-protocol as well: wireguard doesn't stand a chance against gov/isp blocks.
by imcritic 10mo ago
I wish they would improve wireguard-the-protocol as well: wireguard doesn't stand a chance against gov/isp blocks.
- razighter777 10mo agoThat's more of a job for an encapsulating protocol. (shadowsocks or similar) Wireguard isn't designed to be obfuscating alone. It's just a simple l3 udp tunnel with a minimal attack surface.
- Hendrikto 10mo ago> It's just a simple l3 udp tunnel Wait, isn’t UDP L4? Am I missing something?
- nrds 10mo agoThat's the traditional answer parroted in the Wireguard documentation but a few hours' serious thought and design is enough to reveal the fatal flaw: any encapsulating protocol will have to reinvent and duplicatively implement all of the routing logic. Perr-based routing is at least 50% of wireguard's value proposition. Having to reimplement it at the higher level defeats the purpose. No, obfuscation _has_ to be part of the same protocol as routing. (Btw, same sort of thing occurs with zfs combining raid and filesystem to close the parity raid write hole. Often strictly layered systems with separation of concerns are less than the sum of their parts.)
- gvkhna 10mo agoIn this case with the, I believe it’s called quantum tunneling by mullvad, it’s actually a good thing. Because the encapsulation protocol is just UDP/IP, a well established existing protocol that can masquerade as any kind of internet traffic easily. Makes it difficult to block by censors. Great video I saw here: https://youtu.be/pZiG8r-diTM?si=wy35elqMt1T6euq0 https://youtu.be/pZiG8r-diTM?si=wy35elqMt1T6euq0 This also means wg is just doing one thing instead of a dozen it doesn’t “need” to.
- tvshtr 10mo agoThere are forks of wg because of this. Like amnezia-wg
- DANmode 10mo agoThis is a neat project! https://docs.amnezia.org/documentation/amnezia-wg/ https://docs.amnezia.org/documentation/amnezia-wg/
- mintflow 10mo agoamnezia-wg is quite cool and they have built the kmod too, I did some test so far they can works even in my location which block wireguard server quickly.
- tetris11 10mo agoAnywhere I can read more about this?
- DANmode 10mo agoKnown Limitations WireGuard is a protocol that, like all protocols, makes necessary trade-offs. This page summarizes known limitations due to these trade-offs. Deep Packet Inspection WireGuard does not focus on obfuscation. Obfuscation, rather, should happen at a layer above WireGuard, with WireGuard focused on providing solid crypto with a simple implementation. It is quite possible to plug in various forms of obfuscation, however. tl;dr Read the docs.
- mycall 10mo agoMullvad does exactly this.
- coppsilgold 10mo agoWireGuard limitations hurt the attempt however. For example, multi-hop betrays the actual exit node to your ISP (or MITM) due to the port used.
- baobun 10mo agoTo clarify, this is refering to Mullvad multi-hop feature. Doing your own multihop setup doesn't have this issue, right?
- coppsilgold 10mo agoCorrect. Note that the MTU will be further reduced and that WireGuard DIY multi-hop may be inferred.
- holysoles 10mo agoThe mullvad apps do offer obfuscation options (shadowsocks, etc) but i agree it would be nice if something was baked into wireguard itself. I recently went through setting up shadowsocks over wg for my homelab and it was a good bit of effort
- WhyNotHugo 10mo agoMullvad does offers several obfuscation methods well geared towards the scenarios you mention.