this post was submitted on 18 Aug 2025
482 points (99.0% liked)
Technology
74324 readers
3518 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
There can only be so many different server config combinations for algorithm, crypto mode, key size etc, so it would be trivial to have a bot try several combinations and nail your setup on the 5th try or whatever, especially if you selected "standard good" setups, which you should if you're opening a port.
But overall it will weaken the protocol and there is a risk, even if it's small, of a downgrade attack being discovered. Simply by having options means that it's possible to trick the server or force it into a more vulnerable state. You can't get rid of that except by completely removing the options in the first place because there will be literally nothing to downgrade to.
WG just isn't into that risk. It's cool if you want it and I won't say you're wrong in general because everyone has their preferences and makes trade-offs to set things up the way that they want, but in this particular context it goes against the design principles of WG by introducing complexity and risk, which is not what it's about. There's many other options if that's what you're looking for, and a lot of them are just as great/secure.