Hacker News new | ask | show | jobs
by coldpie 2383 days ago
I don't think it's fair to say "better" here. Waiting for stable software releases is a perfectly valid approach. It may not be your approach, which is also fine, but neither approach is better than the other.
1 comments

The end goal here is security. Wireguard has an excellent track record, having a tiny, simple and clean codebase and having been reviewed by many skilled eyes.

Most of other solutions don't come close to that.

I actually do trust WG here, but it is explicitly pre-release software and I would really struggle to fault a provider from avoiding pre-release software. I mean, the WG main page still contains the following (https://www.wireguard.com/):

> WireGuard is currently working toward a stable 1.0 release. Current snapshots are generally versioned "0.0.YYYYMMDD" or "0.0.V", but these should not be considered real releases and they may contain security quirks (which would not be eligible for CVEs, since this is pre-release snapshot software). This text will be removed after a thorough audit.

Every security product has an excellent track record until vulnerabilities are found. Once it hits production and sees a 10000x increase in usage so it becomes a high value target for nation states, then it will be put to the real test.