Remix.run Logo
imcritic 4 hours ago

I wish they would improve wireguard-the-protocol as well: wireguard doesn't stand a chance against gov/isp blocks.

razighter777 4 hours ago | parent | next [-]

That's more of a job for an encapsulating protocol. (shadowsocks or similar) Wireguard isn't designed to be obfuscating alone. It's just a simple l3 udp tunnel with a minimal attack surface.

nrds 33 minutes ago | parent | next [-]

That's the traditional answer parroted in the Wireguard documentation but a few hours' serious thought and design is enough to reveal the fatal flaw: any encapsulating protocol will have to reinvent and duplicatively implement all of the routing logic. Perr-based routing is at least 50% of wireguard's value proposition. Having to reimplement it at the higher level defeats the purpose. No, obfuscation _has_ to be part of the same protocol as routing.

(Btw, same sort of thing occurs with zfs combining raid and filesystem to close the parity raid write hole. Often strictly layered systems with separation of concerns are less than the sum of their parts.)

Hendrikto 3 hours ago | parent | prev [-]

> It's just a simple l3 udp tunnel

Wait, isn’t UDP L4? Am I missing something?

gwehrli 2 hours ago | parent | next [-]

Wireguard is a L3 VPN that uses UDP (L4) for tunneling. Thats probably what was meant.

eurg 2 hours ago | parent | prev [-]

Yes, but it tunnels arbitrary IP packets encapsulated in UDP.

holysoles an hour ago | parent | prev | next [-]

The mullvad apps do offer obfuscation options (shadowsocks, etc) but i agree it would be nice if something was baked into wireguard itself. I recently went through setting up shadowsocks over wg for my homelab and it was a good bit of effort

tvshtr 3 hours ago | parent | prev | next [-]

There are forks of wg because of this. Like amnezia-wg

DANmode 2 hours ago | parent | next [-]

This is a neat project!

https://docs.amnezia.org/documentation/amnezia-wg/

mintflow an hour ago | parent | prev [-]

amnezia-wg is quite cool and they have built the kmod too, I did some test so far they can works even in my location which block wireguard server quickly.

DANmode 3 hours ago | parent | prev | next [-]

Known Limitations

WireGuard is a protocol that, like all protocols, makes necessary trade-offs. This page summarizes known limitations due to these trade-offs.

Deep Packet Inspection

WireGuard does not focus on obfuscation. Obfuscation, rather, should happen at a layer above WireGuard, with WireGuard focused on providing solid crypto with a simple implementation. It is quite possible to plug in various forms of obfuscation, however.

tl;dr Read the docs.

mycall 2 hours ago | parent [-]

Mullvad does exactly this.

tetris11 3 hours ago | parent | prev [-]

Anywhere I can read more about this?