First of all, thank you for all your work on mitmproxy! :)
Could you elaborate on how exactly the WireGuard mode works compared to e.g. TLS interception? After all, WG doesn't come with certificate authorities or anything like that.
Could you elaborate on how exactly the WireGuard mode works compared to e.g. TLS interception? After all, WG doesn't come with certificate authorities or anything like that.
1. configuring an explicit HTTP proxy in your system settings, or
2. fiddling with iptables on your router and/or your mitmproxy device.
The downside of 1) is that it does not work for UDP-based traffic such as DNS and can often be easily bypassed by applications. The downside of 2) is that it's generally fiddly and does not work very well for users with consumer routers (no iptables). In all cases you still need to install a trusted mitmproxy CA for TLS interception, that part does not change with WireGuard mode. :)Now, let's say I've set up WireGuard with three peers, i.e. each of these peer's public key appears in my WireGuard config along with an IP address. Now I start sending traffic to one of these IP addresses which WG would normally encrypt and then route directly to the peer in question. How can mitmproxy's WG mode help me here with "getting [the encrypted] traffic into mitmproxy", as you say, and reading the plaintext?
- You can intercept/modify UDP, in particular DNS.
- You avoid the "apps ignore proxy settings" problem.
- On Android specifically, the WireGuard app allows you to only proxy specific apps (not possible with a global proxy config)
Does that make more sense now? We also have a bit more documentation at https://docs.mitmproxy.org/stable/concepts-modes/#wireguard-....