Comment by Ms-J

1 month ago

Posted this earlier from a throwaway since my account wasn't able to reply for some odd reason and it was marked as dead:

Hello Jason!

I want to first thank you for all of your hard work developing Wireguard.

If I can find someone who is willing to put their name on it to help I definitely will, the problem is the spy agencies don't want your project to exist. It makes it harder to put resources to this. I've worked in security departments of certain companies and saw everything you could imagine.

Same for Mounir over at Veracrypt.

Both of you are developing some of the most important software that exists today.

Keep doing what you are doing by keeping everything in the open. User trust almost doesn't exist for these type of projects. Any hint of an issue would wipe that out in seconds.

This leads me to one question I do have for you zx2c4:

Why does Wireguard attempt to contact your servers and auto update on Android with no toggle to turn this off? It's a threat to everyone. Maybe it also does this on other platforms but I haven't tested them all.

I can think of reasons as to why you did this, none nefarious, but still it would be nice if you included that option so I don't have to patch each update to turn this off.

Thanks.