Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>I have a singular request - so Wireguard is unusable in any high security environments with compliance requirements - because it doesnt support any 2-factor auth out of the box.

>We get rejected on stuff like PCI-DSS because the standards mandate a 2-FA. I am not a security expert and wouldnt know about the pros and cons here. But the fact remains that most high-sec compliance needs 2-FA.

This is absolutely nuts. Why would 2FA be enforced at the network edge instead of on individual services?

What a completely suicidal security model.



> This is absolutely nuts.

You have never worked in regulated industries, haven't you?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: