https://lists.zx2c4.com/pipermail/wireguard/2020-January/004...
> Please note that until Linux 5.6 is released, this snapshot is a snapshot rather than a secure final release.
In other words, over the next ~10 weeks, Linus' kernel tree and Dave Miller's net.git tree will fill up with nice stabilization patches. At the end of that process, 5.6 will be released. At that time, our backports to older kernels (wireguard-linux-compat) will also become a "1.0". This also lines up with the 20.04 LTS release and such.
The fact that Ubuntu is including it, means that it's probably passed a critical mass of early adopters and then is probably seeping into the startup mainstream (as opposed to enterprise that wants 20 valid bells and whistles like authentication, auditing, etc).
> should not be considered real releases and they may contain security quirks (which would not be eligible for CVEs, since this is pre-release snapshot software)
I figure they know better than I do.
Security people are also subject to fads and fashion just like web developers or indeed any other technical group. Many will endorse the primitives developed for example by Dan Bernstein without understanding anything about how they actually work, or having read and understood papers describing their security. Just because he has some hacker "street cred" (arguably well deserved) as the developer of qmail, etc.
So my genuine question is: does he really have an unusual academic standing as a cryptographer?
This ranking by citation (which appears to be up-to-date/live) puts him in position 62: https://kodu.ut.ee/~lipmaa/cites/cites.php?data=crypto
Granted, it's just a ranking by citation, and this definitely puts him in the top 100, which is nothing to scoff at, but I'm still wondering if there is a similar effect, and if in ten years we won't be using algos all written by some other guy because he's the new cool kid.
I do have issues with wireguard's security - things like silently accepting invalid configuration, changing one peer can silently affect another (only avoided via external means), roaming is default enabled and can't be disabled nor can you bind the tunnel to an interface or an ip, nor does it pad packets even the slightest to reduce "meta"data leakage.
Just because the cryptography is (probably) sane, doesn't mean wireguard as a whole is good for all or most use-cases.