Re: Wireguard for Windows - local administrator necessary?

2019-12-12 Thread zrm
On 11/27/19 06:27, Simon Rozman wrote: Hi Chris! This is WireGuard design. Reconfiguring network - which (dis)connecting VPN is – is administrative task. If your organization issues laptops to their employees, the corporate VPN should be up at all times. You don't want them to disconnect fro

Re: Regarding "Inferring and hijacking VPN-tunneled TCP connections"

2019-12-05 Thread zrm
On 12/5/19 14:13, Jason A. Donenfeld wrote: Hey folks, William unembargoed his nice vuln this week: https://seclists.org/oss-sec/2019/q4/122 It appears to affect basically most common unix network stacks. This isn't a WireGuard vulnerability, but rather something in the routing table code and/

Re: idle traffic considerations

2019-11-29 Thread zrm
On 10/17/19 06:29, Knuth wrote: Hey, we are planning to deploy certain devices with an embedded sim cards in different countries across the globe, for maintenance we need to be able to connect to the devices with ssh. Since the sim cards only provide us with a private IPv4 behind NAT (becau

Re: Deterministic Cryptographically Authenticated Network Signatures on Windows NLA

2019-06-28 Thread zrm
On 6/27/19 10:26, Jason A. Donenfeld wrote: So, now that we can control the GUID and hence the NetworkSignature, we have to decide what determines a network. It turns out that in WireGuard, we can do this with much higher cryptographic assurance than any of the crazy "authenticated dhcp" proposal

Re: WG can now be fragmented -- great!

2019-05-24 Thread zrm
On 5/24/19 04:48, Roman Mamedov wrote: Hello, Just wanted to share my excitement about https://git.zx2c4.com/WireGuard/diff/?id=57a8ca7f49b5e70aae18b8b5a70cde8f9e4a9346&id2=7cf2dae97635c8c20a8943522bab2b56c6885c8d This means WG packets can now be fragmented, and as such we can use arbitrary lar

WireGuard and distributed hashtables

2019-03-01 Thread zrm
Distributed hashtables use overlay routing networks that typically have between dozens and thousands of peers per node. Suppose it's 480 peers. Then a node might forward a message between two peers once a minute or so (using of 2/480), but the mean time between use of a given peer link could be

Re: DNS name resolution should not be done during configuration parsing.

2019-02-18 Thread zrm
On 2/16/19 23:08, Jeffrey Walton wrote: On Sat, Feb 16, 2019 at 10:35 PM David Kerr wrote: Erik, see here for a proposed fix. No response from the WireGuard team yet. https://lists.zx2c4.com/pipermail/wireguard/2019-January/003842.html Recently I had a power outage and both my gateway and c