Elizabeth (Plabayo): Welcome to netstack.fm. This is our protocol short series. Today I am gonna be your host. Now and then I hear positive comments about Wireguard and even excitement. Why? To understand why I have Glen here. Welcome, Glen
Elizabeth (Plabayo BV): Netstack.fm is brought to you by Rama, an open source framework for moving and transforming network packets. Rama is built and maintained by Plabayo a company focused on secure, open, and resilient infrastructure with rust, protocols, and purpose.
Glen (Plabayo): FM. This is our protocol short series. Today I am gonna be your host. Now and then I hear positive comments about WireGuard and even excitement. Why? To understand why I have Glen here. Welcome Glen. Hello Elizabeth. So what is WireGuard? So WireGuard is a type of VPN
Elizabeth (Plabayo): So what is WireGuard
Elizabeth (Plabayo BV): The theme music of this podcast was composed by DJ Mailbox.
Glen (Plabayo): and VPN stands for Virtual Private Network where you're basically connecting a client, so a device, phone, computer, it doesn't really matter, and a VPN server using a tunnel. And when we hear tunnel, what we really mean is encryption. And depending on the type of VPN, you live either on layer four or layer three, sometimes even on layer seven.
Elizabeth (Plabayo BV): For more conversations like this, subscribe so you don't miss what's coming next. And if you know someone who could benefit from this episode, share it with them. They might appreciate
Glen (Plabayo): But WireGuard is a lightweight, open source and very fast implementation of a VPN. And it's also a protocol. WireGuard is also a protocol. And it lives on layer 3, where traffic between the device and the VPN server and back to the device is encrypted by encrypting the IP packets.
Elizabeth (Plabayo BV): have experience in protocols, networking, or infrastructure, and want to share your work, your ideas, or experience, we would love to hear from you. Reach out at hello at netstack.fm. Thank you for being here. See you next time for the next handshake.
Elizabeth (Plabayo): short, what are the main properties that make WireGuard different from older VPN technologies?
Glen (Plabayo): what are the main properties that make Wirecard different from older VPN technologies? First of all, it's pretty modern and new. was initially released in 2015 or 2016. It is very lightweight in the sense that A. You don't really maintain state. B. The code base of the reference implementation such as the Linux version are very small. I believe around 4000 to 6000 lines of code which is very easy to audit. The logic is relatively simple. The hardest part to understand is the cryptography and the mathematics behind it but that's cryptography in general. But if you're an expert in that domain such as a security analyst or a developer working within that space, will be used to that, so that's no issue. So for those people, it's very easy to audit, which for example, if you compare it to something like OpenVPN, I think that's like a couple hundred thousand lines of code. And if you're not familiar with code, it would be like trying to ask you, find mistakes in this article of two pages versus finding a mistake in a book of 300 pages.
Elizabeth (Plabayo): find mistakes in this article of two pages versus finding a mistake in a book of 300 pages. I see.
Glen (Plabayo): it will be, you know, you can see where it will be the easiest to find mistakes, especially if it's a book with a lot of concepts which tie into each other. And so you have to try to figure out where is there a logic flow. It's a lot easier if there's a lot less content to look at.
Elizabeth (Plabayo): I see it it easy for My next question is, why does WireGuard matter and who is actually ⁓ using it in practice? Yeah, so...
Glen (Plabayo): I see it it easy for security My next question is, does Wirecard matter today ⁓ and who actually using it in practice? Yeah, so ⁓ those are two different questions I would like to focus on the first one first. Like why it matters is perhaps first asking what if we don't have VPN? And so I can think of two use cases. One is you have a little server in your home and it contains information such as your photos, maybe even your ID cards, all kinds of personal information. Now, sometimes you want this information also remotely available. because maybe you have to show your ID card somewhere and you want to show it. Another use case is, let's say you have a little doctor practice and you have the files of your patients on the server in your home office or your doctor's practice, but you also go on house visits and so you need this information both for reading but also to add extra information as you are with the patient in their home. And so in both cases, you are remote. If we don't have VPN, you are basically going to rely on authentication. So let's say you are connecting to your server over HTTPS and then you use some kind of username password or maybe use a passkey or use two factor authentication. Probably several layers of these things. And you would think that's okay. But if you look at all the vulnerabilities that people find and time and over like every month you keep seeing new reports of bugs in stacks of software, databases, server software, routers, doesn't really matter. And attackers find these mistakes, they chain them together and they find a way to get around authentication. And the problem is It's a lot worse than a physical attack. Let's say you have a house, you want to secure your house. You only have so many criminals in your neighborhood that will target your house. In the IT world, however, this server of this doctor, if it is not with the VPN, it will be publicly available. It's not just publicly to its city, it's publicly to the entire world. Of course, the doctor could do simple things like saying I only allow IP connections from within my own country, sure, but even then you have stuff like proxies so the attackers can get around that. If it's publicly available, it is by definition publicly available somehow to the entire world. Meaning anybody can hammer into your server and try to find these mistakes. They are not your mistake. They are just because of dependencies you use or because the software stack you have. And if you're a doctor, it's not like you're going to be the one developing that. So you use something that you found either open source or you pay for it. And so you're allowing authentication and authentication by definition doesn't work as history shows over and over again. So that's why you want the VPN. But like I also mentioned something like open VPN and there are some other ones like IPsec and you've a couple of other ones. They are either closed source or they might still be open source but they're like pretty complex. And so it's very hard to know if there's a mistake in there or not that can be abused. Especially now with LLM technology, which is pretty good in finding patterns, sometimes a lot better than like humans, because it is a lot of data and computers who are always good at finding data. And now LLM technology also allows us to do that on code and find those mistakes at scale. And so you want something very small because then you can go back to a very pure form of auditing where you almost mathematically can prove and also where you can prove completely is it secure or not. It will never be 100 % but it's as close as you get.
Elizabeth (Plabayo): It seems like it is an important tool and it seems like widespread. So where do usually people encounter WireGuard nowadays? Yeah, so that's a bit of thing. It is not used frequently enough. So I was mentioning authentication doesn't really work yet. It's often the biggest form of authentication, even worse.
Glen (Plabayo): It seems like it is an important tool and it seems like widespread. So where do usually people encounter Wirecard nowadays? Yeah, so that's a bit of thing. It is not used frequently enough. So I was mentioning authentication doesn't really work yet. It's often the biggest form of authentication. Even worse is that some resources are publicly available and they have no authentication at all. So sometimes you read about this database and then they find a mistake in it and suddenly attackers can abuse it. So, or sometimes you have these things like home routers and they get ⁓ installed in someone's house. and by default they have some kind of default passwords which you can just find in the manual. Yeah. Yeah. So it's not widespread enough. ⁓ So it's very ⁓ niche in sense like the will be using today and if they will be using it it's often as part of other products. So maybe some people heard of tailscale and they are a company which implements technology on top of WireGuard and...
Elizabeth (Plabayo): Yeah, that's a big issue. Yeah. So it's not widespread enough. ⁓ so it's very niche in a like the minority be using it today. And if they will be using it, it's often as part of other products. So maybe some people heard of tail scale and they are a company which implements technology on top of Weigard. And ⁓ sometimes ⁓ they might be developers or companies ⁓ using kind
Glen (Plabayo): Sometimes they might be developers or companies using some kind of cloud infrastructure which they can access through a VPN and those things might be driven by WireGuard. Either by an official implementation of WireGuard or by someone implementing the protocol which is WireGuard because you can also just of course read the white paper, you can also implement the protocol yourself and then also use it. So... Most people don't use something like this and for those that do use WireGuard or a derivative of it, they might not even realize. But if we go back to our example of our doctor or to our example of the person that want to have personal data access from a remote point with something like WireGuard or with WireGuard specific, what they can do is they can ensure that this remote resource, this server, is not even accessible. So no one in the world can even access it. The only way to access it is through a WireGuard tunnel. And the only way to do that is by having a private key which is attached to a public key known to that server. And that's pretty powerful. That means by definition, it's completely sealed off. And only if you have access to this private key, you can access the server. And so then at that point, the security relies on how securely can you store this private key. So those will be the main reason why...
Elizabeth (Plabayo): So those will be the main reason why from the implementation point of view makes sense it's very attractive for many developers and engineers, right? To adopt this WireGuard. Yeah, it's interesting because it means you can have...
Glen (Plabayo): From the implementation point of view, it makes sense it's very attractive for many developers and engineers, right? To adopt this WireGuard. Yeah, it's interesting because it means you can have... Things like developer infrastructure, can have servers, you can have all kinds of things, not just for developers, but yeah, certainly also for developers. You can have them remotely accessible without the insecurity of having to rely on authentication. so that's, and not just that, but as we mentioned at the start of the episode, WireGuard is a very simple implementation. So it's a lot hard to make mistakes. And the longer it will be used, the easier it will be. Like, let's say there is a mistake in it, you fix it once and it's also fixed for everybody. But I don't know so far from any mistake that was found in it. And it allows you to securely have these resources accessible.
Elizabeth (Plabayo): Since it's ⁓ an accessible resource, which one would you to have access for a Wirecard, the official website? Yeah, if you want to learn more about it, then can also head to the show notes. Like I would start with the official websites. They also gave some great talks about it on conference like BlackHeads. They also have reference and presentations ⁓ ⁓ other languages.
Glen (Plabayo): Since it's an accessible resource, which one would you to have access for a Wirecard, the official website? Yeah, if you want to learn more about it, then you can also add it to the show notes. Like I would start with the official websites. They also gave some great talks about it on conference like BlackHat. They also have reference implementations in several other languages including Rust for example and you can look at that. They have the white paper online, they have all kind of resources online to learn more about how it works. It also comes with a little tutorials like how to set it up yourself. If you're familiar to the comment line you can just set it up pretty quickly. We use for example to to secure some of our private servers so we can access it from our developer machines without having it publicly exposed to the internet. so we were talking about ⁓ having some server only accessible from specific machines that you trust. But another use case of it is it could be your personal VPN. So let's say you need for specific use cases, you need something like a static IP address. Because sometimes you might work with clients or companies or organizations that can only allow you into their resources while you do consultancy for them or work with them. for an IP address that they can whitelist or put on an allow list. And so what you can also do is you can set up a little server for very cheap in some clouds, like let's say Hetzner or one of these providers, and you connect to it using WireGuard. that server forward through traffic then to any destination. And at that point, your IP address for the public becomes the IP address of that server, which is by definition static. So at that point, doesn't matter if you're at home or in an internet cafe or remotely at some clients, you will always have the same IP address allowing you because it added to the allow list of IP addresses to access those resources. So that's another use case of something like WireGuard to get yourself some kind static IP address if you ever need those because in end that's another use case why some people use VPNs like most people come into contact because they want to have some IP address from some other company or something and so that's yeah another use case but it's something you totally own like you don't rely on some trust of some other company you you you just rely on the thing you own yourself for basically no money at all
Elizabeth (Plabayo): you just rely on the thing you own yourself for basically no money at all. Yeah, that's awesome. And it's so good that it's open source. So thank you very much, Glen. And thank you to our listeners for being with us and giving us your feedback. And also, I would like to ask you if you know someone or if you are someone with expertise on this theme please reach out to us. We will be so and happy to hear from you to keep unpacking this theme thank you very much until the next protocol shorts bye
Glen (Plabayo): Please reach out to us. We will be so gladly and happy to hear from you to keep unpacking this team. you very much. ⁓ the next protocol shorts. Bye. ⁓ Bye.
Elizabeth (Plabayo BV): Netstack.fm is brought to you by Rama, an open source framework for moving and transforming network packets. Rama is built and maintained by Plabayo a company focused on secure, open, and resilient infrastructure with rust, protocols, and purpose.
Glen (Plabayo): FM. This is our protocol short series. Today I am gonna be your host. Now and then I hear positive comments about WireGuard and even excitement. Why? To understand why I have Glen here. Welcome Glen. Hello Elizabeth. So what is WireGuard? So WireGuard is a type of VPN
Elizabeth (Plabayo): So what is WireGuard
Elizabeth (Plabayo BV): The theme music of this podcast was composed by DJ Mailbox.
Glen (Plabayo): and VPN stands for Virtual Private Network where you're basically connecting a client, so a device, phone, computer, it doesn't really matter, and a VPN server using a tunnel. And when we hear tunnel, what we really mean is encryption. And depending on the type of VPN, you live either on layer four or layer three, sometimes even on layer seven.
Elizabeth (Plabayo BV): For more conversations like this, subscribe so you don't miss what's coming next. And if you know someone who could benefit from this episode, share it with them. They might appreciate
Glen (Plabayo): But WireGuard is a lightweight, open source and very fast implementation of a VPN. And it's also a protocol. WireGuard is also a protocol. And it lives on layer 3, where traffic between the device and the VPN server and back to the device is encrypted by encrypting the IP packets.
Elizabeth (Plabayo BV): have experience in protocols, networking, or infrastructure, and want to share your work, your ideas, or experience, we would love to hear from you. Reach out at hello at netstack.fm. Thank you for being here. See you next time for the next handshake.
Elizabeth (Plabayo): short, what are the main properties that make WireGuard different from older VPN technologies?
Glen (Plabayo): what are the main properties that make Wirecard different from older VPN technologies? First of all, it's pretty modern and new. was initially released in 2015 or 2016. It is very lightweight in the sense that A. You don't really maintain state. B. The code base of the reference implementation such as the Linux version are very small. I believe around 4000 to 6000 lines of code which is very easy to audit. The logic is relatively simple. The hardest part to understand is the cryptography and the mathematics behind it but that's cryptography in general. But if you're an expert in that domain such as a security analyst or a developer working within that space, will be used to that, so that's no issue. So for those people, it's very easy to audit, which for example, if you compare it to something like OpenVPN, I think that's like a couple hundred thousand lines of code. And if you're not familiar with code, it would be like trying to ask you, find mistakes in this article of two pages versus finding a mistake in a book of 300 pages.
Elizabeth (Plabayo): find mistakes in this article of two pages versus finding a mistake in a book of 300 pages. I see.
Glen (Plabayo): it will be, you know, you can see where it will be the easiest to find mistakes, especially if it's a book with a lot of concepts which tie into each other. And so you have to try to figure out where is there a logic flow. It's a lot easier if there's a lot less content to look at.
Elizabeth (Plabayo): I see it it easy for My next question is, why does WireGuard matter and who is actually ⁓ using it in practice? Yeah, so...
Glen (Plabayo): I see it it easy for security My next question is, does Wirecard matter today ⁓ and who actually using it in practice? Yeah, so ⁓ those are two different questions I would like to focus on the first one first. Like why it matters is perhaps first asking what if we don't have VPN? And so I can think of two use cases. One is you have a little server in your home and it contains information such as your photos, maybe even your ID cards, all kinds of personal information. Now, sometimes you want this information also remotely available. because maybe you have to show your ID card somewhere and you want to show it. Another use case is, let's say you have a little doctor practice and you have the files of your patients on the server in your home office or your doctor's practice, but you also go on house visits and so you need this information both for reading but also to add extra information as you are with the patient in their home. And so in both cases, you are remote. If we don't have VPN, you are basically going to rely on authentication. So let's say you are connecting to your server over HTTPS and then you use some kind of username password or maybe use a passkey or use two factor authentication. Probably several layers of these things. And you would think that's okay. But if you look at all the vulnerabilities that people find and time and over like every month you keep seeing new reports of bugs in stacks of software, databases, server software, routers, doesn't really matter. And attackers find these mistakes, they chain them together and they find a way to get around authentication. And the problem is It's a lot worse than a physical attack. Let's say you have a house, you want to secure your house. You only have so many criminals in your neighborhood that will target your house. In the IT world, however, this server of this doctor, if it is not with the VPN, it will be publicly available. It's not just publicly to its city, it's publicly to the entire world. Of course, the doctor could do simple things like saying I only allow IP connections from within my own country, sure, but even then you have stuff like proxies so the attackers can get around that. If it's publicly available, it is by definition publicly available somehow to the entire world. Meaning anybody can hammer into your server and try to find these mistakes. They are not your mistake. They are just because of dependencies you use or because the software stack you have. And if you're a doctor, it's not like you're going to be the one developing that. So you use something that you found either open source or you pay for it. And so you're allowing authentication and authentication by definition doesn't work as history shows over and over again. So that's why you want the VPN. But like I also mentioned something like open VPN and there are some other ones like IPsec and you've a couple of other ones. They are either closed source or they might still be open source but they're like pretty complex. And so it's very hard to know if there's a mistake in there or not that can be abused. Especially now with LLM technology, which is pretty good in finding patterns, sometimes a lot better than like humans, because it is a lot of data and computers who are always good at finding data. And now LLM technology also allows us to do that on code and find those mistakes at scale. And so you want something very small because then you can go back to a very pure form of auditing where you almost mathematically can prove and also where you can prove completely is it secure or not. It will never be 100 % but it's as close as you get.
Elizabeth (Plabayo): It seems like it is an important tool and it seems like widespread. So where do usually people encounter WireGuard nowadays? Yeah, so that's a bit of thing. It is not used frequently enough. So I was mentioning authentication doesn't really work yet. It's often the biggest form of authentication, even worse.
Glen (Plabayo): It seems like it is an important tool and it seems like widespread. So where do usually people encounter Wirecard nowadays? Yeah, so that's a bit of thing. It is not used frequently enough. So I was mentioning authentication doesn't really work yet. It's often the biggest form of authentication. Even worse is that some resources are publicly available and they have no authentication at all. So sometimes you read about this database and then they find a mistake in it and suddenly attackers can abuse it. So, or sometimes you have these things like home routers and they get ⁓ installed in someone's house. and by default they have some kind of default passwords which you can just find in the manual. Yeah. Yeah. So it's not widespread enough. ⁓ So it's very ⁓ niche in sense like the will be using today and if they will be using it it's often as part of other products. So maybe some people heard of tailscale and they are a company which implements technology on top of WireGuard and...
Elizabeth (Plabayo): Yeah, that's a big issue. Yeah. So it's not widespread enough. ⁓ so it's very niche in a like the minority be using it today. And if they will be using it, it's often as part of other products. So maybe some people heard of tail scale and they are a company which implements technology on top of Weigard. And ⁓ sometimes ⁓ they might be developers or companies ⁓ using kind
Glen (Plabayo): Sometimes they might be developers or companies using some kind of cloud infrastructure which they can access through a VPN and those things might be driven by WireGuard. Either by an official implementation of WireGuard or by someone implementing the protocol which is WireGuard because you can also just of course read the white paper, you can also implement the protocol yourself and then also use it. So... Most people don't use something like this and for those that do use WireGuard or a derivative of it, they might not even realize. But if we go back to our example of our doctor or to our example of the person that want to have personal data access from a remote point with something like WireGuard or with WireGuard specific, what they can do is they can ensure that this remote resource, this server, is not even accessible. So no one in the world can even access it. The only way to access it is through a WireGuard tunnel. And the only way to do that is by having a private key which is attached to a public key known to that server. And that's pretty powerful. That means by definition, it's completely sealed off. And only if you have access to this private key, you can access the server. And so then at that point, the security relies on how securely can you store this private key. So those will be the main reason why...
Elizabeth (Plabayo): So those will be the main reason why from the implementation point of view makes sense it's very attractive for many developers and engineers, right? To adopt this WireGuard. Yeah, it's interesting because it means you can have...
Glen (Plabayo): From the implementation point of view, it makes sense it's very attractive for many developers and engineers, right? To adopt this WireGuard. Yeah, it's interesting because it means you can have... Things like developer infrastructure, can have servers, you can have all kinds of things, not just for developers, but yeah, certainly also for developers. You can have them remotely accessible without the insecurity of having to rely on authentication. so that's, and not just that, but as we mentioned at the start of the episode, WireGuard is a very simple implementation. So it's a lot hard to make mistakes. And the longer it will be used, the easier it will be. Like, let's say there is a mistake in it, you fix it once and it's also fixed for everybody. But I don't know so far from any mistake that was found in it. And it allows you to securely have these resources accessible.
Elizabeth (Plabayo): Since it's ⁓ an accessible resource, which one would you to have access for a Wirecard, the official website? Yeah, if you want to learn more about it, then can also head to the show notes. Like I would start with the official websites. They also gave some great talks about it on conference like BlackHeads. They also have reference and presentations ⁓ ⁓ other languages.
Glen (Plabayo): Since it's an accessible resource, which one would you to have access for a Wirecard, the official website? Yeah, if you want to learn more about it, then you can also add it to the show notes. Like I would start with the official websites. They also gave some great talks about it on conference like BlackHat. They also have reference implementations in several other languages including Rust for example and you can look at that. They have the white paper online, they have all kind of resources online to learn more about how it works. It also comes with a little tutorials like how to set it up yourself. If you're familiar to the comment line you can just set it up pretty quickly. We use for example to to secure some of our private servers so we can access it from our developer machines without having it publicly exposed to the internet. so we were talking about ⁓ having some server only accessible from specific machines that you trust. But another use case of it is it could be your personal VPN. So let's say you need for specific use cases, you need something like a static IP address. Because sometimes you might work with clients or companies or organizations that can only allow you into their resources while you do consultancy for them or work with them. for an IP address that they can whitelist or put on an allow list. And so what you can also do is you can set up a little server for very cheap in some clouds, like let's say Hetzner or one of these providers, and you connect to it using WireGuard. that server forward through traffic then to any destination. And at that point, your IP address for the public becomes the IP address of that server, which is by definition static. So at that point, doesn't matter if you're at home or in an internet cafe or remotely at some clients, you will always have the same IP address allowing you because it added to the allow list of IP addresses to access those resources. So that's another use case of something like WireGuard to get yourself some kind static IP address if you ever need those because in end that's another use case why some people use VPNs like most people come into contact because they want to have some IP address from some other company or something and so that's yeah another use case but it's something you totally own like you don't rely on some trust of some other company you you you just rely on the thing you own yourself for basically no money at all
Elizabeth (Plabayo): you just rely on the thing you own yourself for basically no money at all. Yeah, that's awesome. And it's so good that it's open source. So thank you very much, Glen. And thank you to our listeners for being with us and giving us your feedback. And also, I would like to ask you if you know someone or if you are someone with expertise on this theme please reach out to us. We will be so and happy to hear from you to keep unpacking this theme thank you very much until the next protocol shorts bye
Glen (Plabayo): Please reach out to us. We will be so gladly and happy to hear from you to keep unpacking this team. you very much. ⁓ the next protocol shorts. Bye. ⁓ Bye.