24 pointsby mlhpdx5 hours ago3 comments
  • cube003 hours ago
    >the Listener rejects any handshake from an unknown key.

    It never responds, there's no indication of rejection.

    The client can't even be sure a service is actually there or they've hit a default drop firewall rule.

  • tosti34 minutes ago
    I think this would nerf wireguard similarly to how a "null" encryption effectively nerfed IPSec. Fine for a specific use case (debugging comes to mind) but should never be upstreamed imho.
  • pamcake3 hours ago
    Why stop there? Give use Wireguard certificate auth already!