Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How would this compare to ZeroTier? (zerotier.com)


It seems that someone asks about ZeroTier on every thread about WireGuard. According to tptacek:

https://news.ycombinator.com/item?id=13601928

ZeroTier is cryptographically inferior to Wireguard, but also isn't really a VPN: it has centralized configuration and rendezvous. If you're running VPNs to get the US Netflix from your UK vacation, this is probably fine. If your VPN is how remote employees access your prod network, it is way less fine.

I think it's a bit unfair to judge ZeroTier in comparison to VPNs, because that's not strictly speaking what it's trying to be. I like overlay networks!

And here's some info from the ZeroTier developer:

https://news.ycombinator.com/item?id=11996687

You can think of ZeroTier as a virtual smart switch built on a P2P network

...

WireGuard does have some things in common with ZeroTier, such as the use of cryptography to identify endpoints and eliminate the hard-coding of endpoint addresses. ... I really like the WireGuard design in general and I think it has a somewhat different use case from ZeroTier, namely fast long-lived provisioned links across WANs and insecure LANs. You could use ZT for that but this being in-kernel makes it likely faster.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: