Topic
WireGuard

macOS User Investigates Claude Regional Block via Logs and Restores Work Site Access with Targeted WireGuard Routes
Other
Six Months After tun0 Leak: Which Android VPN Clients Fixed Server Address Exposure and Which Ignored It
Vulnerabilities & Exploits
Bypassing VPN Detection on iPhone: Detailed Methods to Avoid App Blocks
Privacy & SurveillanceHydrat Project Builds Automated WireGuard Gateway for Resilient VLESS and Tor Routing
A developer has released Hydrat, a self-hosted gateway that connects devices via WireGuard while automatically managing VLESS and Tor backends to survive server blocks and quality degradation. The system maintains a pool of tested proxies, performs continuous health checks, and switches routes without requiring client-side profile changes. Two Go processes handle control logic and network enforcement separately, using SQLite for state and nftables plus Xray for traffic routing. TCP and UDP can be assigned independent exits, with geoip.dat support and custom rules to keep marketplace apps functional. The project emphasizes stability over direct connections and is designed for deployment on servers in Russian jurisdiction.
WireGuard Kernel Module Silently Overwrites AllowedIPs in Trie, Breaking Peer Routing Without Errors
The WireGuard kernel module stores AllowedIPs in a single prefix trie per device rather than per peer, causing exact-match insertions of identical CIDR prefixes to reassign nodes and remove them from the previous peer's list. This behavior silently drops routing for affected peers while handshakes and inbound traffic continue, leading to one-way connectivity failures and frame errors. The issue affects road-warrior setups using 0.0.0.0/0, mesh networks, Kubernetes CNI plugins such as Cilium and Calico, and network operating systems including VyOS and OPNsense. No warning is emitted by wg, wg-quick, or the kernel on overwrite, and the longest-prefix-match lookup ensures only equal-length prefixes collide. The root cause resides in allowedips.c where rcu_assign_pointer redirects the trie node and list_move_tail detaches it from the original peer. The same logic appears across Linux, wireguard-go, wireguard-nt, FreeBSD, and OpenBSD implementations.
sing-box Fork Expands from Desktop VPN Launcher to Android and Router Deployments
The sing-box-lx fork has grown from a desktop-focused VPN engine into a cross-platform solution supporting Android and headless router deployments. Over 1,700 commits since June produced 24 stable 1.14 releases and dozens of specialized builds. New protocol support includes a full MASQUE CONNECT-IP outbound for Cloudflare WARP and a rigorously verified AmneziaWG 2.0 implementation matching 16 obfuscation parameters across three reference sources. Android adaptations introduced aggressive endpoint state management that reduced RSS by 31 percent and CPU load by 80 percent while fixing long-standing TCP dial timeouts inherited from gVisor. The new lxd headless daemon exposes gRPC observability and admin REST endpoints with mTLS, config validation, automatic rollback, and device-name mapping for OpenWrt deployments. All changes follow strict upstream discipline: minimal patches, regular rebases, reproducible builds, and real-device testing before stable tags.
VPN Services Stabilize in Russia? Expert Warns Users Not to Relax as New Blocks May Be Coming
Russian users have recently noticed that personal VPN services and anonymizers are operating more stably after months of aggressive disruptions. Technical director Sergey Shcherbakov of the company Stakhanovets explains that the current improvement is likely only a temporary pause while deep packet inspection systems recalibrate. Earlier this year, DPI equipment was blocking traffic based on crude digital fingerprints of protocols such as OpenVPN and WireGuard, causing widespread collateral damage and connection drops. Operators are now believed to be collecting detailed data on ports, reconnection patterns, and obfuscation techniques to build more precise filters. Shcherbakov predicts the next wave of restrictions will arrive by late summer or early autumn, possibly shifting from outright blocks to throttling speeds during peak hours and delaying large file transfers. Meanwhile, users have adapted by maintaining multiple VPN clients, switching protocols and ports, and enabling obfuscation when needed.