3 ms·
Wireguard exemplifies the superiority of a qualified independent developer over the fractal layers of ossified cruft that you get from industry efforts and comp
by elevation 7mo ago
Wireguard exemplifies the superiority of a qualified independent developer over the fractal layers of ossified cruft that you get from industry efforts and compliance STIGS.
So it feels wrong to see wireguard adapted for compliance purposes. If compliance orgs want superior technology, let their standards bodies approve/adopt wireguard without modifying it.
- LtWorf 7mo agobut wolfssl is in the business of selling FIPS compliance so…
- alfanick 7mo agoAnd they do it fast, thankfully Compliant Static Code Analyser catches issues like https://github.com/wolfSSL/wolfGuard/commit/fa21e06f26de201bf9139bf742f514ef9ddf4f28#diff-d0f0f5117b6e6bc7d9b9c8ae7197cf26cf0f972c6f056b689960c0b7f778ce36R253 https://github.com/wolfSSL/wolfGuard/commit/fa21e06f26de201b...
- johnisgood 7mo agoHoly shit. Those are rookie mistakes[1], that could end up being SEVERE. [1] Not referring to the fixes.
- dietsche 7mo agolooks like AI to me. It’s always making rookie mistakes that look plausible!
- johnisgood 7mo agoNo, I mean, for example uninitialized pointers are a huge red flag, so seeing one not set to NULL is honestly shocking, especially in crypto code where a stray pointer can lead to crashes or subtle security issues.
- jmclnx 7mo agoYes, but be aware, openvpn is much better if you live in a Country like China, Russia and a few others. That is due to a known design issue with wireguard. For most people, wireguard is fine. Edit: I should have said "choice" instead of "issue", but Firefox 140 is failing on this site so I could not correct the txt. I was able to edit this after reverting back to Firefox 128.
- LunaSea 7mo agoCould you expand on the design flaw in question?
- jmclnx 7mo agoIt is not a design flaw, but a design choice. >OpenVPN does not store any of your private data, including IP addresses, on VPN servers, which is ideal. https://www.pcmag.com/comparisons/openvpn-vs-wireguard-which-protocol-is-best-for-your-vpn https://www.pcmag.com/comparisons/openvpn-vs-wireguard-which...
- eptcyka 7mo agoOpenVPN looks like a regular tls stream - difficult to distinguish between that and a HTTPS connection. WireGuard looks like WireGuard. But you can wrap WireGuard in whatever headers you might want to obfuscate it and the perf will still be better.
- tptacek 7mo agoIt's trivial to make WireGuard look like a regular TLS stream. It's probably not worth a 15 year regression in security characteristics just to get that attribute; just write the proxy for it and be done with it. It was a 1 day project for us (we learned the hard way that a double digit percentage of our users simply couldn't speak UDP and had to fix that).
- eptcyka 7mo agoIt is, we did the same. It is a shame that only Linux supports proper fake TCP though.
- dmbche 7mo ago> fractal layers of ossified cruft Someone got a thesaurus in their coffee today! (Not a jab)