Skip to main content

vula: automatic local network encryption

With zero configuration, vula automatically encrypts IP communication between hosts on a local area network in a forward-secret and transitionally post-quantum manner to protect against passive eavesdropping.

With manual key verification and/or automatic key pinning and manual resolution of IP or hostname conflicts, vula will additionally protect against interception by active adversaries.

When the local gateway to the internet is also vula peer, internet-destined traffic will also be encrypted on the LAN.

How does it work?

Automatically.

Vula combines WireGuard for forward-secret point-to-point tunnels with mDNS and DNS-SD for local service announcements, and enhances the confidentiality of WireGuard tunnels by using CTIDH implemented by highctidh, a post-quantum non-interactive key exchange primitive, to generate a peer-wise pre-shared key for each tunnel configuration.

Vula's advantages over some other solutions include:

  • design is absent of single points of failure (SPOFs)
  • uses existing IP addresses inside and outside of the tunnels, allowing seamless integration into existing LAN environments using DHCP and/or manual addressing
  • avoids needing to attempt handshakes with non-participating hosts
  • does not require any configuration to disrupt passive surveillance adversaries
  • simple verification with QR codes to disrupt active surveillance adversaries

See NOTES.md for some discussion of the threat model and other technical details, and COMPARISON.md for a comparison of Vula to some related projects.

Current status

status-badge

Vula is functional today, although it has some known issues documented in STATUS.md. It is ready for daily use by people who are proficient with Linux networking and the command line, but we do not yet recommend it for people who are not.

See INSTALL.md for installation and usage instructions.

See HACKING.md for some tips on opening the hood.

See DEPENDENCY.md for diagrams illustrating the different dependecy relationships between internal and external python modules.

Security contact

We consider this project to currently be alpha pre-release, experimental, research quality code. It is not yet suitable for widespread deployment. It has not yet been audited by an independent third party and it should be treated with caution.

If you or someone you know finds a security issue - please open an issue or feel free to send an email to security at vula dot link.

Our current bug bounty for security issues is humble. We will treat qualifying reporters to a beverage after the COVID-19 crisis has ended; ojalá. Locations limited to qualifying CCC events such as the yearly Congress.

Authors

The authors of vula are anonymous for now, while our paper is undergoing peer review.

Acknowledgements

OPERATION_VULA.md has some history about the name Vula.

Vula is not associated with or endorsed by the WireGuard project. WireGuard is a registered trademark of Jason A. Donenfeld.

This project is funded through the NGI Assure Fund, a fund established by NLnet with financial support from the European Commission's Next Generation Internet program. Learn more on the NLnet project page.

Metadata

Release files for vula 0.2.2023112400

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vula 0.2.2023112400
File Size Uploaded
vula-0.2.2023112400.tar.gz 168.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vula 0.2.2023112400
File Interpreter ABI Platform
vula-0.2.2023112400-py3-none-any.whl Python 3 none any Details

Total release size: 357.1 kB

Release files / vula-0.2.2023112400.tar.gz

Download URL vula-0.2.2023112400.tar.gz
Size 168.9 kB
Tags Source
SHA-256 checksum
How to use checksums
e399df0eebf6844f9490af3fb30b8dc62da0f203fbac7144f602aa35bdff6eb0
BLAKE2b-256 checksum
How to use checksums
bd384ffb9a0d8715a001e866ab02076ed448d71b3603802002737e5b4f3c37f4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.10.12

Release files / vula-0.2.2023112400-py3-none-any.whl

Download URL vula-0.2.2023112400-py3-none-any.whl
Size 188.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
31c13af923669d8062ca720bd3df17c6fa42ebf4c0d663297f6f1c17843f3908
BLAKE2b-256 checksum
How to use checksums
7c1d6d1ebd5b9f2c5d5a264c544266c225375fee71dfba2ab022e9fb52fad5f7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.10.12

Release history Release notifications | RSS feed

This release

0.2.2023112400 This release

2 release files

0.1.14

2 release files

0.1.13

2 release files

0.1.12

2 release files

0.1.9

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page