On Wed, Nov 21, 2018 at 01:25:29PM -0500, Michael Richardson wrote:
>
> > Almost all VPN providers for apple (OSX and iOS) use IKEv2 with
> > CP. Based on numbers of concurrent users I have seen from some vendors
> > using libreswan, we are talking in the orders of 100’s of thousands of
> > users.
>
> That's awesome news to learn!!!
> I haven't seen this in the wild myself, and it's not the case in Android as
> you point out.
FWIW, I use Private Interent Access (privateinternetaccess.com), and
while it's "user friendly Linux install is effectively "curl | sudo
/bin/sh" it did have a manual install procedure, and all the manual
install procedure did was install the package
network-manager-openvpn-gnome and then make configuration changes to
Network Manager so it new where to find the PIA servers.
So yes, no VPN software was downloaded, and while you could argue that
if most users are trusting a "curl .... | sudo /bin/sh" install, there
are plenty of ways for a VPN provider to completely take over your
machine (never mind your DNS!), at least a security expert can audit
the script, and someone who is sufficiently paranoid can run the
commands and/or edit the config files by hand.
Cheers,
- Ted
_______________________________________________
IPsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipsec