It is as easy to use as WireGuard and has two advantages over wireguard. 1. It will automatically mess, and find the best path. 2. It has a far wider range of platforms supported than wireguard.
It is as easy to use as WireGuard and has two advantages over wireguard. 1. It will automatically mess, and find the best path. 2. It has a far wider range of platforms supported than wireguard.
https://www.tinc-vpn.org/documentation/Security.html#Securit...
The default cipher is from 1993 and its creator recommends everyone updates.
32 bit MACs are hilariously tiny.
Home rolled authentication based around RSA.
Their own documentation even states: ”tinc’s security is not as strong as TLS or IPsec."
DO NOT USE tinc!
https://www.tinc-vpn.org/documentation-1.1/Simple-Peer_002dt...
a) its not supported by the stable release
b) There are no claims about downgrade resistance. The manual specifies the new transport protocol is used if both clients support it and both have changed their configs to enable experimental mode. Can an attacker still force them to connect with legacy mode?
c) Users have to ensure every single config on every client has the correct setting.
d) It still doesn't have the identity hiding features of Wireguard. (Someone observing your network traffic can see which servers you are talking to from the transmitted signatures)
Compare this to something like IPSec, where the userland is typically only used for the control part; once a connection exists, the packets don't leave the kernel, so no context switch needed.
If tinc is crazy slow I suspect it's an implementation issue.