Linus Torvalds on Wireguard
lists.openwall.net
lists.openwall.net
Not exactly the same thing as the title suggests. (FTR: the original title was something like "Linus Torvalds: Wireguard is a work of art")
This category of submissions is not very good for HN, unfortunately. There isn't enough information there to slow down the gears, which is what allows for reflective reactions. In fact, there almost isn't any information, just 'celebrity name' and 'thing mentioned'. That produces the instant reflexive reactions that are associated with low-quality threads, and the celebrity aspect is a fuel supplement.
Impress performance: https://www.wireguard.com/performance/
But can it traverse a NAT. IPSec for all of its benefits is a huge PITA to circumvent a NAT, often requiring either the NAT to have native support or for IPSec to be configured to use UDP encapsulation. Seems like the Wireguard people thought of this:
https://www.wireguard.com/quickstart/#nat-and-firewall-trave...
Reading their web site in general has made me nothing but impressed, they seem to be building a VPN tunneling protocol designed for the real world but with several improvements over existing solutions. It is incomplete, but definitely something I'm going to check in on.
(edit: rephrased for clarity)
The box in question implemented AES, RSA and DH. Does that mean AES, RSA and DH should be considered insecure too?