WireGuard: Great protocol, but skip the Mac app
rachelbythebay.com
rachelbythebay.com
This is not unique to Wireguard. I’ve had this happen with the Lockdown app too. This is an Apple problem. Apple should notify you that the VPN app needs to close in order to upgrade then offer you a simple way of doing that.
> I don't know exactly, and I don't really care.
This about sums it up. This is a rant and it’s difficult not to just close tab half way through.
Or maybe an oversight by Wireguard, but with the way Apple limits API access in iOS for 3rd party I'm non-plussed.
Every single rachelbythebay article:
Here's a vague condition. I encountered it at vague companies that I may have worked at. Anyway, whatever, it vaguely caused problems.
Here's my vague workaround or suggestion. Whatever. Bye.
It is true that for updating WG you need to first disable the on-demand setting (probably only on Big Sur). But to me that is such a trivial hiccup considering it is free and generally bug free! On the rare occasions that I have had a non-trivial issue looking at the log file has provided clues.
My VPN cost is only about $5/month as I run my own instance of WG server in the cloud. Worth every penny! It is possible it could be lower if I use one of those #3.50/month AWS lightsail instances but I never tried.
Go WG!
no activity logs
does not ask for personal information
anonymous payments via cash or cryptocurrencies
no subscription
hides your device's activity.
(I'm biased, of course, being the author).
One command, and allows you to shut the server down when you don't need it. I might add support for lightsail too.
I use SSH so far since WireGuard isn't supported yet. I also configure SSH to only allow the type of connection I want to use: public key authentication only, ports 80 and 443, plus (on both local and remote sides):
Ciphers=chacha20-poly1305@openssh.com
KexAlgorithms=curve25519-sha256,curve25519-sha256@libssh.org
HostKeyAlgorithms=ssh-ed25519-cert-v01@openssh.com,ssh-ed25519
MACs=hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com
Install unattended-upgrades and edit /etc/apt/apt.conf.d/50unattended-upgrades as desired. For SSH proxy, locally set "ALL_PROXY=socks5://127.0.0.1:2000" (with DynamicForward localhost:2000 locally). Or change socks5 to socks5h if you want DNS to be handled on the remote system, however this will prevent uMatrix and other blockers from getting DNS info needed to avoid considering some 3rd party content as 1st party so it is better to set up encrypted DNS locally (I use stubby but with just the provider I want). Many applications check ALL_PROXY these days but not all and I think Firefox needs explicit settings to use the proxy.I use ramnode.com's $15/year OpenVZ and it works great like this for getting an encrypted connection past your local ISP and/or wifi (I think they ask for everyone's ID when you start). There are issues with some websites due to the IP address, but it is not nearly as many as using an annonymous VPN from what I've heard.
b. The other reason I went with a cloud provider like AWS is that their static IP seems to be whitelisted fairly well especially with their own service - Amazon Prime. So I have had not problem watching videos while traveling. Also in the past macOS and iOS updates were problematic via VPN. But that seems to have gone away. Maybe because they bypass VPN? I don't know for sure.
c. Many of my friends have been asking for help. I figured if I went with one of the big 3 cloud providers it would be easy for me to basically create an instance image preloaded with all the scripts and WG etc. that they can then run from their own accounts.
d. The big 3 cloud providers uptimes are far better than many of the VPN providers.
Relatives of mine got setup with a VPN in under 5 minutes just by:
1. download (vpn client)
2. pay (for a month or two)
3. switch it on and forget it.
In terms of on-boarding new users to use secure and recommended tools, I find this a massive achievement.
VPN providers are far more likely than AWS to do the kind of shady things that might matter to your relatives, like selling their personal data.
It's meaningless. VPN providers come in the same full spectrum of integrity as people or companies.
At some point you can’t, you can only make a best judgement based on what they’re telling you and what you’ve found elsewhere.
How do you know that AWS isn't spying on your systems? Are they transparent? Do AWS release detailed transparency reports on their servers? You are identified when you pay for AWS no?
I'd rather trust a specialist privacy VPN provider like Mullvad, than me rolling my own VPN on a provider that isn't even transparent and that is hard to use for consumers other than myself.
my 2c.
For instance, at work we are mostly remote, and use a VPN (OpenVPN here) to access the local network at the office with our on-premise build servers, and it also allows developers to work together sometimes (one running a debugging server on their dev laptop, another debugging the client from their own laptop as if they were sharing a local network, when actually they are hundreds of miles apart)
It didn't sound ad all like the OP was using his VPN to dial into work. He was dialing into a purpose-build VM which wasn't stated to do anything else - just tunneling his traffic for some unknown reason.
Which means shutting down the VPN, and exposing your hardware serial (the MAS app transmits this to Apple, along with your Apple ID) and true IP (which is equivalent to your city-level location) to Apple.
Not a great state of affairs.
I honestly see no problem with Apple knowing the IP address. It’s the same with Windows 10, since it will check for Windows updates frequently.
If you see these things as a problem it’s probably best to use Qubes OS instead.
Macs and iPhones also maintain a persistent connection to the Apple push notification service with a TLS client certificate obtained via registering with the hardware serial.
Just because you personally are okay with Apple and, by extension, the US military having your travel history doesn't mean that there's no problem with it.
Thank you Jason for your hard work and wonderful wares!!
This allows you enable/disable (or choose if you have multiple) the VPN without needing to be a member of the Administrators group. You also need to add a line to the registry.
Here's the powershell code to do that:
New-ItemProperty "hklm:\software\wireguard" -Name "LimitedOperatorUI" -Value 1 -PropertyType "DWord" -Force
Add-LocalGroupMember -Group "Network Configuration Operators" -Member "$username"control userpasswords2
A simple user account managing interface hidden in a myriad of crap dashboards.
But yeah Apple doesn't make it any easier with vpns on big Sur, they have to use a new type e of extension now and they exclude their own services automatically.
Not something that seems related to these issues but it make macOS one again less interesting for me as daily driver
Unless you have information otherwise, I don't think that the whitelist applied to the filtering features used by Little Snitch et al also applies to VPNs.
How could there be? Things would break and it would be a privacy nightmare.
I don't use the Mac App Store. I run my VPN on a second device, because I no longer find the macOS to sufficiently preserve my privacy.
It's insane to me that Apple thinks it's okay to demand hardware serial number, name, street address, email, and phone number to download free privacy apps. An organization that had privacy as a value simply would not do that.
Apple has banned apps that want to use the NetworkExtension API from being self-signed, OR by being Apple-approved-developer signed and distributed outside of the App Store. You can download the windows Wireguard client from the Wireguard website, but not the mac one.
They even recently censored the donations link in the Wireguard mac client, because App Store.
I think you can also use brew.
The wireguard-app-from-wireguard is only distributed via MAS, and you cannot build that GUI version that they distribute via MAS yourself, because that version uses the NetworkExtension API and that only works with the appropriate signed entitlement from Apple, which as of very recently didn't get issued outside of MAS apps.
I imagine it won't be an issue as much once traveling is possible again.
It’s people like this that make it so hard to stay motivated to do any kind of open source work. Choosing beggars.
I have been running the official Windows version for a while now, using it almost 8h/day and it's working flawlessly for me.
The current state of the world, where many VPN providers ship questionable apps of varying quality, is just sad for a solution that claims to prioritize security and privacy. The WireGuard app is somewhat useable, but it is by no means “easy to setup” unless you’re already familiar with how WireGuard works.
Compared to the Cisco client we use for work, wireguard seemed better in every way.
I became interested in how exactly it works and found an original code repo. It turned out that a delay between repo tag push and auto-update notification was about 15 minutes. This includes CI/CD pipeline time!
I've instantly converted into Wireguard beleiver.
Networking wise it implements a point to multipoint model which is just awful to deal with. I had hoped that moving on from frame relay and ATM had killed this model but wireguard brings it right back. Then you also have to deal with complications of wireguard interfaces always being up. The two combined means doing anything but the most basic setups means more complicationd with more chance for incorrect configuration than an ipsec or openvpn alternative.
Then there is the whole troubleshooting problem. When it doesn't work wireguard provides much less information to troubleshoot the issue than ipsec and openvpn.
Also there is the irritating lines of code comparison vs ipsec and openvpn when for the most part it is comparing apples to oranges since wireguard doesn't include many of the features of either which are required for an enterprise site to site or road warrior VPN solution. Once the solutions are in place to provide comparable functionality the attack surface is likely to be pretty comparable.
There's also just not that much to debug! You've got keys, allowed IP lists, and endpoint addresses. There aren't a lot of other knobs to turn!
I think a thing that gets people into trouble with WireGuard is not understanding how modest its design is. The goal of WireGuard is to drop into the networking stack as just another interface. It doesn't intend to implement an entire new networking model on top of itself. My experience has generally been, if it's straightforward to express in the Linux networking model, it's straightforward with WireGuard.
I think this is a very good thing. I really don't want to have to think about what the OpenVPN developers believe about networking in general. I want to bring up secure transports and route packets over them the way I'd route over any other tunnel I want orthogonal, predictable interfaces that I (or Tailscale, or whatever) can build more complicated things on top of.
Though troubleshooting packet loss is not fun and I haven’t been able to figure out how to avoid that and fragmentation, but I believe that’s more due to me than WG itself.
i.e. i could have peer A at 172.16.1.1 and peer B at 172.16.2.1. peer A would have AllowedIPs=172.16.1.1/32,172.16.0.0/24 and peer B would have AllowedIPs=172.16.2.1/32,172.16.0.0/24 and i could decide which peer gets traffic for 172.16.0.0/24 using the routing table by setting the via address to either 172.16.1.1 or 172.16.2.1 respectively. however, as stated this is not even allowed as only one peer would be able to have that subnet in its AllowedIPs setting present.
IPSec is just like that, it's just wireguard can be manually setup with the minimal wg command, while nobody uses IPSec barehanded.
If wg is a low layer that only attempts to do the tunneling job and leaves the routing and directory jobs to others, that seems just fine to me.
I prefer seperation of concernes.
Wireguard claims separation of concerns but then sticks itself in the routing and packet filtering process instead of leaving those wholly to the existing established solutions.
It's like everyone has abandoned MacOS but are too polite to admit it...
I generally agree with your observation though. I'm not really a macOS developer, but from the sidelines it appears it has become increasingly difficult to develop and ship open software for both Apple operating systems. See for example this discussion from a few months ago ("Can't you just right-click?"): https://news.ycombinator.com/item?id=24217116
If it helps, I have a shell-script to auto-setup an IPsec/IKEv2/MOBIKE and WireGuard VPN on top of an OpenBSD machine, including in the cloud:
Day and night difference in quality and ease of use.
AMA?
What is it about ZT that made you trust it with your traffic?