sshuttle: a new kind of userspace VPN
apenwarr.ca
apenwarr.ca
Or am I missing something obvious here...?
Plus, socks requires you to reconfigure every single bit of client software to use it. sshuttle just magically works because it uses the kernel-level transproxying.
You would also need to decide, in each client application, which IP addresses should use socks and which shouldn't; otherwise you'd end up forwarding everything, which is no good either. You can configure sshuttle on a per-ip-subnet or even per-ip-address basis and it affects all your client software.
* Socks on Mac is a tickbox which is pretty much system-wide. I can turn on or off in two clicks anywhere in my system. UNIX socket programming isn't wrapped, so curl and wget don't follow the rules, but all mac apps do. If that wasn't enough, Socks rules are both per-host and per-subnet configurable.
* I've never done UDP over ssh -D, but I do use ssh for the majority of my traffic and haven't had any trouble.
That said, this does look useful for those rare cases when I can't muck about with the GatewayPorts sshd config on a system. That's a really rare case though, as typically I will just pay Amazon $.08/hr to bring up something with root access.
All that sshuttle requires is that you have plain old ssh access to the other side.