6 ms·
I have had the opposite experience to OP. I have the macOS app installed on several Macs (laptops and desktops). They have all worked so well to the point that
by pthreads 6y ago
I have had the opposite experience to OP. I have the macOS app installed on several Macs (laptops and desktops). They have all worked so well to the point that I even forget Wireguard is running. On top of that I upgrade macOS almost as soon as Apple releases a new version.
It is true that for updating WG you need to first disable the on-demand setting (probably only on Big Sur). But to me that is such a trivial hiccup considering it is free and generally bug free! On the rare occasions that I have had a non-trivial issue looking at the log file has provided clues.
My VPN cost is only about $5/month as I run my own instance of WG server in the cloud. Worth every penny! It is possible it could be lower if I use one of those #3.50/month AWS lightsail instances but I never tried.
Go WG!
- syntaxing 6y agoAny tips on how to run your own server safely? I get all paranoid because I’m terrible with security.
- mfcl 6y agoBy practicing. Run it anyway and get good at it.
- justusthane 6y ago“By practicing” is not a good way to get good at security, unless you want to make potentially devastating mistakes along the way.
- colesantiago 6y agoor you can use mullvad.net (supports wireguard protocol) no activity logs does not ask for personal information anonymous payments via cash or cryptocurrencies no subscription hides your device's activity.
- _-___________-_ 6y ago“No activity logs” is impossible to verify, and “hides your device’s activity” is basically untrue unless you do some gymnastics with the definitions of words.
- 3np 6y agoAbsolutely true. I still vouch for Mullvad though, it’s the one VPN provider I feel I can trust to reasonable extents.
- colesantiago 6y agohttps://mullvad.net/en/help/no-logging-data-policy https://mullvad.net/en/help/no-logging-data-policy
- _-___________-_ 6y agoHow do you verify this?
- pthreads 6y agoJust replied to another comment. Hope that helps.
- scaladev 6y agohttps://github.com/trailofbits/algo https://github.com/trailofbits/algo https://github.com/StreisandEffect/streisand https://github.com/StreisandEffect/streisand
- jfim 6y agoJust as a thing to keep in mind, if you're using Algo (or any other vpn software) with a commercial cloud provider, you'll hit more captchas and blocks than usual. For example, going to walmart.com will give a captcha page before being allowed on their website. Some websites will return HTTP 403, and some will just timeout.
- fmajid 6y agohttps://github.com/fazalmajid/edgewalker/ https://github.com/fazalmajid/edgewalker/ (I'm biased, of course, being the author).
- ncmncm 6y agoWireguard Bounce Server setup: <https://news.ycombinator.com/item?id=25447805 https://news.ycombinator.com/item?id=25447805>
- daboosh 6y agohttps://github.com/boosh/dawg https://github.com/boosh/dawg One command, and allows you to shut the server down when you don't need it. I might add support for lightsail too.
- joveian 6y agoI use a Debian OpenVZ based VPS for this and uninstall or disable any services except the one I want (surprisingly this isn't the default :(, check what is listening with "ss -l46n"). The advantage of OpenVZ is that kernel patching is the job of the provider, so if you only have one service listening remotely then you should be ok as long as that service is ok. I use SSH so far since WireGuard isn't supported yet. I also configure SSH to only allow the type of connection I want to use: public key authentication only, ports 80 and 443, plus (on both local and remote sides): Ciphers=chacha20-poly1305@openssh.com KexAlgorithms=curve25519-sha256,curve25519-sha256@libssh.org HostKeyAlgorithms=ssh-ed25519-cert-v01@openssh.com,ssh-ed25519 MACs=hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com Install unattended-upgrades and edit /etc/apt/apt.conf.d/50unattended-upgrades as desired. For SSH proxy, locally set "ALL_PROXY=socks5://127.0.0.1:2000" (with DynamicForward localhost:2000 locally). Or change socks5 to socks5h if you want DNS to be handled on the remote system, however this will prevent uMatrix and other blockers from getting DNS info needed to avoid considering some 3rd party content as 1st party so it is better to set up encrypted DNS locally (I use stubby but with just the provider I want). Many applications check ALL_PROXY these days but not all and I think Firefox needs explicit settings to use the proxy. I use ramnode.com's $15/year OpenVZ and it works great like this for getting an encrypted connection past your local ISP and/or wifi (I think they ask for everyone's ID when you start). There are issues with some websites due to the IP address, but it is not nearly as many as using an annonymous VPN from what I've heard.
- m3nu 6y agoSame here. Using the Mac app every other day and works well.
- 867-5309 6y agowhat made you choose trusting a cloud provider with your ingress/egress rather than a VPN provider?
- pthreads 6y agoa. I don't trust any VPN provider's claims. Plus I wanted more control including ability to turn on/off logs if needed. As an experiment I started with an AWS lightsail instance. It worked so well that I now I don't feel I need anything with more resources (up to about 10 clients). That doesn't mean I trust AWS entirely but for now I will live with it. I like using a CLI and AWS's browser based CLI is pretty good (but be wary of copy-paste snafus). b. The other reason I went with a cloud provider like AWS is that their static IP seems to be whitelisted fairly well especially with their own service - Amazon Prime. So I have had not problem watching videos while traveling. Also in the past macOS and iOS updates were problematic via VPN. But that seems to have gone away. Maybe because they bypass VPN? I don't know for sure. c. Many of my friends have been asking for help. I figured if I went with one of the big 3 cloud providers it would be easy for me to basically create an instance image preloaded with all the scripts and WG etc. that they can then run from their own accounts. d. The big 3 cloud providers uptimes are far better than many of the VPN providers.
- colesantiago 6y agoThis is good if you're experienced with this sort of stuff, but I like to save time with the "set it and forget it" approach. Relatives of mine got setup with a VPN in under 5 minutes just by: 1. download (vpn client) 2. pay (for a month or two) 3. switch it on and forget it. In terms of on-boarding new users to use secure and recommended tools, I find this a massive achievement.
- _-___________-_ 6y agoTrusting a VPN provider is an entirely different thing than trusting AWS et al though. VPN providers are far more likely than AWS to do the kind of shady things that might matter to your relatives, like selling their personal data.
- sneak 6y ago> It is true that for updating WG you need to first disable the on-demand setting (probably only on Big Sur). Which means shutting down the VPN, and exposing your hardware serial (the MAS app transmits this to Apple, along with your Apple ID) and true IP (which is equivalent to your city-level location) to Apple. Not a great state of affairs.
- cpach 6y agoIf one does not want the serial transmitted to Apple, a better solution is probably to switch to another OS. I honestly see no problem with Apple knowing the IP address. It’s the same with Windows 10, since it will check for Windows updates frequently. If you see these things as a problem it’s probably best to use Qubes OS instead.
- sneak 6y agoTransmitting your hardware serial to Apple along with your direct IP permits Apple and anyone with access to Apple's databases/logs a record of your travel history, because IPs are city-level geolocation. Macs and iPhones also maintain a persistent connection to the Apple push notification service with a TLS client certificate obtained via registering with the hardware serial. Just because you personally are okay with Apple and, by extension, the US military having your travel history doesn't mean that there's no problem with it.