Hacker News new | ask | show | jobs
by aeries 2951 days ago
When both sides are OpenVPN 2.4+, AES-256-GCM will be negotiated by default.
1 comments

Emphasis on "negotiated".

The entire negotiation and key agreement stack is a larger codebase than all of Wireguard.

The difference between “it can be made to work securely” and “it works securely” is much more important than most people realize.