What is WireGuard? The VPN term explained, and whether you need it (2024)

Editors' note, Feb. 9, 2022: The VPN industry has undergone significant change in the past few months, with all three of our top VPN choices announcing major changes in corporate ownership. In December, ExpressVPN announced that it had officially joined Kape Technologies, a company that already owns several other VPNs and has raised privacy concerns in the past. In February, NordVPN and Surfshark announced the two companies were merging, though they'll continue to operate autonomously. We're in the process of reevaluating all of our top picks in light of these changes. We will update our reviews and, if necessary, our rankings to account for this new competitive landscape.

Maybe you've seen virtual private networks advertise something called WireGuard protocol, and wondered what that means. What's the big deal? Is WireGuard protocol better than any other type? Is it more secure, or just more hype in a field with a lot of buzzwords? While there's a lot to understanding protocols, the broad strokes -- and what they mean for your online privacy -- can be explained in less than 5 minutes of reading. Here's what you need to know.

VPNs work by creating an encrypted tunnel between your device and a secure server, then sending your traffic through it. Those encrypted tunnels come in all kinds of metaphorical shapes and sizes, though. The driving force creating each encrypted tunnel, which determines that tunnel's shape and size, is called your protocol. WireGuard is just one of several different types of protocols used to create these tunnels.

Choosing an encryption protocol is a lot like choosing what kind of transportation you'll take on the road. Zipping around town in a isn't going to offer you as much protection as travelling in a presidential motorcade, but the latter is going to turn your trip to the grocery store into a 12-hour event requiring top-level clearance. On the highway and in encryption protocols, there's almost always a trade-off between speed and security. The trick is finding the option that suits the need.

Protocol choice is also about more than just speed and security. It's about compatibility. In their various settings and options menus, most VPNs offer you the ability to select a protocol from a list of those available within the app. Desktops, laptops, gaming consoles and mobile devices -- with all their myriad platforms and operating systems -- might work better or worse with one VPN protocol or another. Don't worry, though. Most commercial VPNs' default protocols are set to work with as many devices as possible, right out of the box.

WireGuard is a relative newcomer to the protocol scene, and has been lauded for enabling speeds that are as fast as some of the older and less secure protocols, while still offering some improved security over them. Because durable encryption protocols don't just pop up every day, WireGuard is also currently enjoying some added attention from advertisers for its novelty.

Currently, the most widely used protocol is OpenVPN. It's generally considered the best tradeoff between security and speed, it's compatible across devices and platforms, and it's the open-source protocol many independent developers use to create their own VPN services from scratch. All of the top-recommended VPNs in our directory offer an OpenVPN option.

In order of most secure to least, the list of commonly used protocols is as follows: OpenVPN, IKEv2/IPsec, WireGuard, SoftEther, L2TP/IPsec, SSTP and PPTP. Because of its infamous security flaws, we don't recommend anyone use the long-outdated PPTP, regardless of device or connection speed. In our VPN reviews, it likewise reflects poorly on any commercial VPN to offer the option at all. SSTP has similar issues.

WireGuard advantages: Security, speed, power consumption

Speed is the first major advantage of WireGuard. It has a light touch when consuming your device's CPU resources, and is a leaner protocol overall -- that usually means longer battery life and less lag when you're opening and using other apps on your device.

This speed boost also includes connection and reconnection speeds. So if you're using a VPN on your cell phone, for instance, and switch from mobile data to Wi-Fi, Wireguard should be fast enough in most cases that you don't notice a significant disruption in your connection.

On the security side, I like that WireGuard is open source (like OpenVPN). This lets developers not only see everything that it's doing for added security, but it also makes it more likely developers will try it out with new products. It has a smaller code base, and generally has a smaller surface area susceptible to outside attacks. Being open-source also means that WireGuard is getting more platform compatible all the time. It currently supports use with Windows, MacOS, Android, iOS and Linux.

What is WireGuard? The VPN term explained, and whether you need it (1)

WireGuard disadvantages: Privacy, weak on censorship

It's still early days for WireGuard. That means that while its compatibility with platforms is expanding, not all VPNs currently support it.

That could be because offering WireGuard while protecting user privacy requires some extra work on the part of a VPN. One major security concern is that -- if left to its default configuration -- WireGuard would store IP addresses on a server and not assign them dynamically. VPNs that offer WireGuard must therefore address that problem in their own software.

I'm also still skeptical about the fact that WireGuard doesn't use the internet's gold standard of encryption, AES-256, and instead uses another untested component in encryption called ChaCha20. Though both are symmetrical forms of encryption and share some of the same inherent weaknesses, more time is still needed for encryption aficionados to explore the latter.

Another issue with WireGuard is that it sometimes struggles to bypass internet firewalls used by countries where censorship is prevalent or VPNs are outlawed. This can also interfere with what types of sites you can access. Although this type of technology isn't immune to politics, WireGuard's problem appears to have more to do with its quest for speed than it does any political agenda. If you poke your head under the hood just a bit, you can see the problem right at the center of the engine: WireGuard's protocol suite transport layer is spitting out data using a method called UDP, or User Datagram Protocol.

UDP is faster than the more commonly used Transmission Control Protocol type, and it's better for streaming data-heavy content such as videos and music. It's also arguably more secure since it doesn't rely on OpenSSL libraries, which have been exploited in the past.

The problem is that security isn't the same as privacy. While WireGuard's small amount of code may make it less prone to direct security attacks, its use of UDP makes it stick out like a sore thumb to anyone looking for VPN use on a network -- your internet service provider, your school network administrator or the government entity that's surveilling the traffic in your country. UDP is also a little more prone to instability than TCP, so if you're going to use a VPN with WireGuard, make sure it's a VPN with a kill switch enabled.

What is WireGuard? The VPN term explained, and whether you need it (2)

The takeaway

For maximum privacy, stick with OpenVPN -- especially if you're in a jurisdiction where bypassing censorship is important. However, If you're running a VPN in an environment where speed improvements trump privacy (say, accessing international versions of a streaming video service while in a region with slower speeds) the option to flip the switch in your VPN app from OpenVPN to WireGuard might prove helpful.

If you're not specifically looking to experiment with protocols or speed, then a VPN isn't worth getting purely on the grounds that it offers WireGuard. Especially when OpenVPN is still the preferred protocol. If you're in a country where bypassing censorship is important, OpenVPN is still preferred.

VPNs that support WireGuard

If you want to try WireGuard out with one of the VPNs in our directory, the protocol is currently available to use in NordVPN (see our NordVPN review), Surfshark (see our Surfshark review) andCyberGhost (see our CyberGhost review). It's also available inMullvad, StrongVPN, TorGuard, VyprVPN, Hide.Me and PIA.

More VPN recommendations

  • What's the best cheapest VPN? We found three good options
  • Fastest VPNs of 2022
  • CyberGhost vs. Surfshark VPN: Speed, security and price compared
  • Best VPN for Mac in 2022
  • Best iPhone VPN of 2022
  • Best Android VPNs for 2022
  • Why the best free VPN doesn't exist
  • VPNs may be your best weapon against ISP throttling
  • Accessorize your Xbox Series X or Series S with these gaming add-ons
What is WireGuard? The VPN term explained, and whether you need it (2024)

FAQs

What is WireGuard? The VPN term explained, and whether you need it? ›

A WireGuard VPN usually involves a client (the app on your phone, for example) and a VPN server. Like other encryption protocols, WireGuard communicates with the server and establishes an encrypted tunnel between server and client.

What does a WireGuard VPN do? ›

WireGuard is an open-source communication protocol for setting up secure Virtual Private Networks (VPNs). Using advanced cryptographic primitives to secure exchanged data, it seals it within an encrypted tunnel.

Do I need WireGuard VPN? ›

WireGuard is faster, lighter, and more secure than previous VPN encryption standards, but it has some drawbacks, too. We help you decide if the new security protocol is right for you.

What is the difference between VPN and WireGuard? ›

The biggest notable differences between WireGuard and OpenVPN are speed and security. While WireGuard is generally faster, OpenVPN provides heavier security. The differences between these two protocols are also what make up their defining features.

What does the Brave VPN WireGuard service do? ›

This service was added to provide an OS level way to stop leaking of DNS due to a Windows feature called `Smart Multi-Homed Name Resolution` and is only used when a customer has purchased VPN and the VPN is connected.

Can I use WireGuard for free? ›

WireGuard is originally open source and can be used for free, absolutely. There are many free VPNs that support WireGuard, and it is also included by default in the Linux kernel, so those who are adept at programming can establish these types of encrypted connections simply by typing in the command line.

Can WireGuard be detected? ›

Can WireGuard be detected? Yes, WireGuard can be detected. It doesn't do VPN obfuscation, mostly because of the insistence on UDP transmission mode. Surfshark turned to a customized implementation of OpenVPN in TCP mode for an undetectable VPN.

Can WireGuard be trusted? ›

Is WireGuard secure? WireGuard is considered by many to be one of the safest, most secure VPN protocol options available today. Simplified design using less code equals fewer bugs and security vulnerabilities, while WireGuard's faster state-of-the-art cryptography employs superior default security settings.

Does WireGuard hide your IP? ›

As explained above WireGuard does not allocate a dynamic IP address to the VPN user. And, it indefinitely stores user IP addresses on the VPN server until the server reboots. So, there is no anonymity and privacy in WireGuard.

How much does WireGuard cost? ›

Since WireGuard and OpenVPN are free software, there is no expense associated with using them. Though there are some free solutions, you'll still need to pay for a VPN subscription. Since WireGuard and OpenVPN are free software, there is no expense associated with using them.

Is WireGuard private? ›

WireGuard has forward secrecy of data packets, thanks to its handshake, but the handshake itself encrypts the sender's public key using the static public key of the responder, which means that a compromise of the responder's private key and a traffic log of previous handshakes would enable an attacker to figure out who ...

Is WireGuard vulnerable? ›

One of the key advantages of WireGuard is its minimal attack surface. The protocol's codebase is remarkably small, consisting of only a few thousand lines of code. This lean design reduces the potential for vulnerabilities and makes it easier to audit and maintain the codebase.

Do you have to pay for brave VPN? ›

Brave VPN is a subscription service. It's available in the Brave Browser on desktop and mobile devices for $9.99 / month. Each subscription comes with a 7 day free trial. If you subscribe to Brave VPN from the App or Play stores, you can choose a yearly subscription for $99.99 / year.

What is WireGuard on my computer? ›

WireGuard is a modern VPN Protocol used by many VPN companies because it provides a more secure and faster browsing experience.

Is brave VPN private? ›

While Brave enhances privacy by blocking trackers and ads, a VPN encrypts your entire connection. Together, they provide a secure and private online experience. Setting up a VPN with Brave is simple – you can either install a VPN extension or app.

Is WireGuard good for privacy? ›

WireGuard employs modern cryptographic protocols. Without delving too deeply, this means it uses the latest encryption methods to ensure your data is scrambled in the most secure way possible. Even if someone manages to capture your data, deciphering it would be a monumental task.

Does WireGuard cost money? ›

Cost and Licensing

Since WireGuard and OpenVPN are free software, there is no expense associated with using them. Though there are some free solutions, you'll still need to pay for a VPN subscription. Since WireGuard and OpenVPN are free software, there is no expense associated with using them.

Does private internet access use WireGuard? ›

PIA is the best all-around VPN. We use powerful encryption to fortify your internet traffic against intrusion. Our no-logs policy is supported by RAM-only servers and entirely open-source apps, as well as protocol options like WireGuard® and OpenVPN.

Top Articles
Latest Posts
Article information

Author: Francesca Jacobs Ret

Last Updated:

Views: 5709

Rating: 4.8 / 5 (48 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Francesca Jacobs Ret

Birthday: 1996-12-09

Address: Apt. 141 1406 Mitch Summit, New Teganshire, UT 82655-0699

Phone: +2296092334654

Job: Technology Architect

Hobby: Snowboarding, Scouting, Foreign language learning, Dowsing, Baton twirling, Sculpting, Cabaret

Introduction: My name is Francesca Jacobs Ret, I am a innocent, super, beautiful, charming, lucky, gentle, clever person who loves writing and wants to share my knowledge and understanding with you.