What's the quality of openvpn? Should I just use IPSec?

What's the quality of openvpn? Should I just use IPSec?

Other urls found in this thread:

twitter.com/OSTIFofficial/status/848299479849721857
github.com/trailofbits/algo
ostif.org/the-openvpn-2-4-0-audit-by-ostif-and-quarkslab-results/
twitter.com/SFWRedditVideos

an audit of openvpn was actually finished today.

twitter.com/OSTIFofficial/status/848299479849721857

the openvpn codebase is tiny relative to the pos openssl libraries it uses

OpenVPN doesn't try to prevent leaks so you'll need to set up a kill switch / iptables. Make sure you use the option to drop from root privileges too.

OpenVPN is fine if configured properly.
IPSec is kill.

If you don't want to learn to make proper configuration then no VPN will save your ass.

If you want to run your own IPSec VPN with secure defaults

github.com/trailofbits/algo

it's not written in rust so shit

I can't wat until logic bugs are exploited in rust.

Was ipsec found to be fundamentally flawed in some way? I thought OpenBSDs implementation was pretty solid.

it has to be exceptionally stupid code to make it happen

We'll have to wait a bit for the results.

ok. i understand gov spying and flying under the radar to voice your opinion. but my question is, why would you need a vpn? what kind of thing requires completely masking your online location?

i dunno but that doesnt mean someone doesnt need it anyway

VPN's are just for masking your location. 99% of VPN traffic on the internet is for business/enterprise.

ISPs should not know too much about user traffic.

If you're not using libressl by now that's your problem.

this i understand. now that title II is being taken apart, there will be a need for everyone to use vpn unless you want walmart buying your network traffic

...

The thing is, it doesn't solve the problem. It just moves it somewhere else.
Instead of your ISP tracking you, it will be your VPN's ISP(s).
Sure, you can avoid snooping from anyone between you and the VPN, but the moment your traffic reaches it, it's the same as nothing.
Plus now you have to trust your VPN's word not to leak, harvest, or sell your data.

ikev2 (opeinked) is solid, in fact better as openvpn. the old ipsec is kill

Everything. Data is used to profile you. It could cripple your careers, your reputation, and can put you under the eye of government surveillance (which is a blatant invasion of privacy).

I can't shitpost here without a VPN to my own box because of state-level internet censorship.

The audit results are in.

ostif.org/the-openvpn-2-4-0-audit-by-ostif-and-quarkslab-results/

2 remote denial of service vulnerabilities were the most severe issue found. most of the attack surface is in the openssl libraries. ostif are planning to audit openssl next.

Playing video games with lower ping/bypassing ip restrictions

This

It was hilarious reading articles on Australian news papers suggesting VPNs should be used for privacy

...

self host


my country is about to start blocking non compliant porn sites and force isps to log all visited sites