Skip to content

A VPN Out of Parts: PPP, Tap Devices and Netcat

A VPN is two jobs: something that makes a virtual link, and something that carries the bytes. PPP has done the first since 1994 and does not care what the second is β€” which is why PPTP, L2TP and every dial-up line you ever used are the same protocol over different carriers. Netcat is a carrier. This builds it both ways. First pppd: the pty option and what it does with a pseudo-terminal, the TCP version everyone tries first, why running a stream protocol inside TCP melts under loss, the UDP version that is the one to use, the async HDLC framing and the ACCM that decides how much bandwidth goes on escaping control characters, addressing and routing and IPV6CP, and keeping the link up when the carrier dies without telling you. Then the same tunnel with no PPP at all β€” a tap device, one datagram per frame over UDP, the length prefix you have to invent yourself over TCP, tun against tap, and bridging. Then the part netcat has no answer for: wrapping the carrier in TLS with ncat, stunnel and openssl, and in DTLS with socat, which is the shape you actually want. It is never really the right tool, and that is the point: it shows how egress behaves once an attacker has root inside your network and outbound access was not blocked by default, and why default-deny at the border is the only control that was ever real.

14th September 2026 Β· 60 min Β· 13122 words Β· Damien Dye

IPsec Was a Good Idea. It Is Time to Turn It Off.

IPsec was right in 1995: encrypt below the application, bind the security association to the IP address, let every protocol inherit it. Then NAT arrived, carrier-grade NAT finished the job, and the fix was to wrap the whole thing in UDP and keep a timer running so a translation table would not forget you. This post shows how it falls down, diagram by diagram β€” the security association that cannot survive a rewritten header, the two translators every CGNAT line now has, the NAT64 standard that names IPsec as out of scope, the tunnel that cannot use a second link because ESP has no ports, the MTU nobody owns, and L2TP and PPTP as the two protocols that were never fit to be here. It carries the vendor documentation from Cisco, Juniper and Microsoft that admits every one of those, the eighteen pieces that call themselves an IPsec VPN including the two that were never standards at all, why the Fisher-Price OS has never truly interoperated with an open stack, a working method for diagnosing IPsec while you still run it, and the case for retiring the lot with dates.

13th September 2026 Β· 68 min Β· 16979 words Β· Damien Dye

Ping: The Diagnostic Tool That Opens a Whole Lot More

Ping, not the rest of ICMP, is the liability: echo is a channel every host must answer with your own bytes, so a network that β€˜only allows ping’ already has a full VPN out. This walks the threat first β€” what it costs your egress, and how a visitor on your WiFi or an unlocked ethernet port can open one β€” then three working tunnels built on ping alone (Hans, icmptunnel, and a short Python one with AES-128), the MTU and IPv6 catches, and the rule that shuts it: drop echo, keep the errors, in nftables, pf, Cisco, Junos, MikroTik and Windows.

1st September 2026 Β· 36 min Β· 7657 words Β· Damien Dye