Hacker News new | past | comments | ask | show | jobs | submit login

Only out of abundant caution, it seems. I mean, Cloudflare is using it.



Cloudflare is also cautioning against using their own implementation in production.


The author has specifically said it'll be considered released when it's in the kernel, which makes the parents point kinda mute.



Cloudflare is not the golden standard for security.


Who is?


OpenBSD


I don't know a lot of serious systems security people who actually believe that. OpenBSD is fine, and smart people work on it, but it's been a long time since the early 2000's.


AFAIK it remains the single most selective platform out there. If a project is included in an OpenBSD release you know it has undergone serious whitebox scrutiny for security issues. I'm not aware of any platform that is quite so pedantic at the source code level.


I've said pretty much all I have to say about this, here:

https://news.ycombinator.com/item?id=7071219



What's the history there?


The protocol yes, but don't they use their own implementation? https://github.com/cloudflare/boringtun


Sure, but the underlying codebase hasn't had a public audit for boringtun or wireguard, so they're both in the same boat.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: