# WireGuard

> How WireGuard works in the privymail.eu VPN: methods, port, key renewal, what the server remembers and how it differs from OpenVPN.

> **Status:** The VPN service is planned for December 2026; details may change before then.

## Little code. Fixed methods.

WireGuard is a VPN protocol that makes do with little code and a fixed set of modern cryptographic methods. It is open source and has been part of the Linux kernel since 2020. The privymail.eu VPN speaks it alongside [OpenVPN](https://privymail.eu/en/vpn-openvpn.md).

## Encryption: fixed rather than negotiated

With many older protocols, the two sides negotiate which methods they use. WireGuard prescribes them. A weak setting that someone picks by mistake or forces on a device therefore does not exist. The price: if one of the methods shows a weakness, a new version of the protocol is needed on every device.

| Task | Method |
|---|---|
| Encrypting the data | ChaCha20 |
| Detecting changes to the data | Poly1305 |
| Agreeing keys | Curve25519 |
| Hash function | BLAKE2s |
| Deriving keys | HKDF |
| Securing internal lookup tables | SipHash24 |

Each device identifies itself with a key pair. The keys for the actual data are created afresh each time a connection is set up and are replaced automatically while it runs (perfect forward secrecy). Anyone who later gets hold of a long-term key cannot read previously captured traffic with it.

The source code is small. Less code means fewer places for errors to hide and less effort for everyone who reviews it.

## Speed

WireGuard needs little computing time per packet, spreads the work across several processor cores and sets up a connection with a single exchange, practically without waiting. ChaCha20 is also fast on devices whose processor does not specifically accelerate encryption. On a phone, that is easy on the battery.

How fast a connection actually is also depends on your own line, the route to the VPN server and the upper limit of your plan: at most 10 Mbit/s in the Free plan, at most 1 Gbit/s in the paid plans.

## Stability and changing networks

WireGuard works over UDP only; the VPN servers accept it on port 9929. The VPN server recognises your device by its key, not by its address. When your phone switches from Wi-Fi to mobile data, the tunnel therefore carries on without a new connection set-up.

The downside: networks that block UDP or let only web traffic through block WireGuard as well. Obfuscation that disguises the tunnel as other traffic is not part of it. On such networks, [OpenVPN](https://privymail.eu/en/vpn-openvpn.md) over TCP often gets through.

## Ease of use

A WireGuard configuration is short: your own key, the VPN server's key and address, plus the address ranges that go through the tunnel. On a computer you import it as a file; on a phone it can also be read in as a QR code. WireGuard apps exist for Windows, macOS, Linux, Android and iOS; some routers support the protocol too. The steps are under [Setting up the VPN](https://privymail.eu/en/vpn-setup.md).

## Privacy: what the server remembers

WireGuard encrypts, but it does not conceal who is connected. It is part of the protocol that the VPN server keeps, for each key, which addresses inside the tunnel belong to it, which internet address the last valid packet came from and when keys were last exchanged.

How long such information stays is decided by how the service is run, not by the protocol. In the VPN service, the IP address you connect from sits in volatile memory and is deleted when the session ends. A key management service removes every device from the VPN server's memory that has gone three minutes without a handshake. More under [VPN and privacy](https://privymail.eu/en/vpn-privacy.md).

## WireGuard or OpenVPN?

| Feature | WireGuard | OpenVPN |
|---|---|---|
| Origin | young, in the Linux kernel since 2020 | in use since 2001 |
| Encryption | fixed set: ChaCha20, Poly1305, Curve25519 | negotiated over TLS, depending on the version: ChaCha20-Poly1305 or AES-256-GCM, with old apps AES-256-CBC |
| Transport | UDP only, port 9929 | UDP or TCP, ports 1194, 1195 and 443 |
| New keys while running | automatic | every 45 to 75 minutes |
| Connection set-up | one exchange, practically instant | several steps, can take a few seconds |
| Changing networks | tunnel carries on | connection is usually set up again |
| Networks that block UDP | does not get through | often gets through over TCP |
| Processor cores | uses several | uses one |
| Size of the source code | small | many times larger |

WireGuard fits if you use a phone or laptop on changing networks and want things to be fast. OpenVPN fits if a network does not let WireGuard through. What neither of them does is listed under [VPN security](https://privymail.eu/en/vpn-security.md).

WireGuard is a registered trademark of Jason A. Donenfeld.

---

- privymail.eu: patchletter UG (haftungsbeschränkt) · Germany
- This page as HTML: https://privymail.eu/en/vpn-wireguard/
- Deutsche Fassung: https://privymail.eu/vpn-wireguard.md
