4 ms·
the source code is about two years old. does that mean that the code is so stable that there is no need for patches/improvements? or has the project been discon
by dagi3d 12y ago
the source code is about two years old. does that mean that the code is so stable that there is no need for patches/improvements? or has the project been discontinued?
- jedisct1 12y agoQuicktun is still maintained: https://github.com/UCIS/QuickTun https://github.com/UCIS/QuickTun
- pipeep 12y agoI'm very impressed with how short and clean the code. I did a very quick code review, and things appear to be implemented sanely (eg, they drop permissions and chroot properly). There aren't many comments, but most of the code is readable enough without it. I don't care much for their coding style (little whitespace, long lines) but that's just aesthetics. More importantly, QuickTun might have some usability issues. Port numbers are hard-coded, and most configuration options seem to be set as environment variables. This should be expected though, as a result of trying to keep the code as small as possible. I'd recommend it, but only to someone who's willing to read the source to figure out what's going on. If someone wanted to write their own VPN, it would be an excellent reference. It's definitely not for everyone.
- aryastark 12y agoQuicktun used to use C's rand() to generate keypairs (see keypair.c). They still include a blurb about /dev/urandom being insecure and apparently requiring the user to manually input random data. The nacl0 protocol is inherently insecure (null nonce, vulnerable to replay), not sure why they even include that. IIRC, you also pass the private key via environment variable. Lots of horrible flaws for such a small code base.
- zokier 12y agoSo is SigmaVPN a wrapper to QuickTun or what is the relation here? What do I miss if I use plain quicktun instead of sigmavpn?
- j_s 12y agoAlso, does not support Windows
- mrsaint 12y agoyeah, I am surprised by that, too. Haven't heard about this one until now... and I have had my fair share with various VPN implementations, from OpenVPN to Strongswan.