List of software and things that use or support WireGuard
ianix.com
ianix.com
yep, can confirm :)
currently running on this passively-cooled thing:
https://www.amazon.com/Firewall-Micro-Appliance-Gigabit-AES-...
OPNSense 20+ also support WireGuard just in case someone gets confused about that specific version reference.
https://www.aliexpress.com/item/32740319382.html
anyways, the price difference is not terribly relevant at this pricepoint for a qty of 1 upgraded every 5-10 years.
But it does indeed not matter, paying 50 or 100 more over 5 years is a rather small amount.
Linux 4.19 kernel. IPtables for packet filtering and IPv4 NAT. ~30% of my traffic is v6 without NAT overhead.
More seriously though, there are lots of tasks that can go on a home router that take it past a simple firewall. IPS/IDS systems, Advanced QoS, OpenVPN -- all these things can require fairly significant hardware resources to run anywhere close to the 100-1000Mbps speeds on internet connections that are reasonably widespread and affordable in many countries now.
either way, i'd rather over-provision for an extra $150 than discover i need all new hardware when my requirements change.
generating 4-5 character-prefixed keys seems to up the chances of collision by many orders of magnitude, right? but even so, is that enough of a concern to not use such a tool?
It would be different if it was to generate a private key that matches the prefix.
Have been using it for personal VPN deployments, very easy to use and each time I notice they have made moves to be more secure.
Basically they don't want to manage U/P. They are looking at other services as well (such as github).
I don't agree with his sentiment at all. With OpenVPN Viscosity is by far the best OpenVPN client and both the 'official' client (OpenVPN) and the open source alternative (Tunnelblick) are buggy and have crappy UI. I'm hoping Sparklabs either repurpose Viscosity to include WireGuard as well, or write a new client specifically for WireGuard (which I'd happily buy).
Edit: wow, what the hell. I guess HN hates improved clients with a violent passion.
It's often not the protocol that has the problem, as with OpenVPN, it's whatever gets layered around it usually causes the issues (as was with those 'SSL VPN' solutions and stuff like Citrix).
Unless you get value out of shifting blame to a vendor or some contract thing, there really isn't much use throwing money at it. In some sectors that's probably still a requirement. I hope I never get to the point where I have to go back to that.
In context of the linked text, it was not in fact obvious what you meant.