Skip to content

v1.11.2

Choose a tag to compare

@proofoftrinity proofoftrinity released this 01 Oct 03:51
· 72 commits to main since this release
v1.11.2
29956cb

Katacomb VPN 1.11.2

A desktop client for the Sentinel decentralized VPN network. Pick a node, pay for a
session on-chain, and tunnel through WireGuard, AmneziaWG, OpenVPN, V2Ray, XRAY or
Hysteria2.

1.11.2 is a licensing fix. The packages now include the licence texts of the
open-source libraries compiled into the app, which earlier releases left out. The app
itself is unchanged from 1.11.1.

Highlights

  • Licence texts for the libraries inside the app. The app compiles more than 80
    open-source npm libraries into its own code, among them CosmJS and the Sentinel JS
    SDK. Their licences require their text, and for CosmJS its NOTICE file, to travel
    with every copy, and up to 1.11.1 the packages carried none of those texts. They are
    now in THIRD-PARTY-NOTICES-npm.md beside the app's other licence files (in
    /opt/Katacomb VPN/ for the .deb).
  • Nothing else changes. The app's code is byte-identical to 1.11.1. The only other
    difference is two TypeScript build-cache files, about 170 KB the app never read, that
    are no longer packaged.

Fixes in 1.11.2

  • Keep the TypeScript build cache out of the asar
  • Check that the npm notices ship
  • Ship the licence texts of the bundled npm packages

Known limitations

  • A chain has a hard life of about two hours. Measured on mainnet: exit hops report
    no usage to the chain, so the exit's idle deadline is pinned at purchase and never
    moves, even while the entry still has quota. This is node-side behaviour, not a client
    bug, but it is yours to plan around.
  • Chains can only be built from V2Ray and XRAY nodes. The other protocols have no
    equivalent of the relay mechanism a chain needs.
  • Expect roughly 2 to 3 MB/s and a large latency increase on a chain. Chains are for
    privacy, not speed.
  • Without systemd-resolved, a missing resolvconf still shows up after you pay. The
    app cannot safely install one on such a system, so a WireGuard or AmneziaWG connection
    there pays first, then offers Retry without VPN DNS on the same session, which sends
    your DNS queries outside the tunnel. To avoid it, set up a resolvconf provider such as
    openresolv the way your distribution documents.
  • Local-proxy mode tunnels only the apps you point at its SOCKS address. Everything else
    leaks, by design, and the kill switch does not apply.
  • The TLS and Reality wrapping does not authenticate the node. There is nothing on chain
    to verify a node's certificate against, so an attacker on your local network can answer
    a handshake in a node's place.

Platform support

Linux x86_64 only. Tested on Debian 11+, Ubuntu 20.04+, and derivatives (Mint,
Pop!_OS, Zorin). For this release the .deb and the AppImage were checked on a clean
Ubuntu 24.04 desktop, the .deb in containers on Debian 12 and 13 and Ubuntu 22.04, 24.04
and 26.04, and the AppImage in containers on those and Fedora 44.

Installation

Recommended: .deb

sudo apt install ./katacomb-vpn_1.11.2_amd64.deb

Installs a root daemon, so connect and disconnect never prompt for a password. It needs
one log out and log back in after the first install before that takes effect.

Alternative: AppImage

chmod +x katacomb-vpn-1.11.2.AppImage
./katacomb-vpn-1.11.2.AppImage

No install needed. The first connection that needs the VPN helper installs it, with one
password prompt. After that each privileged operation prompts for a password, cached for
a few minutes.

Verifying your download

sha256sum -c SHA256SUMS --ignore-missing
gpg --verify SHA256SUMS.asc SHA256SUMS

Signed with key 740A F267 B0D8 162B E477 779D 7315 246A 6E67 F3C6. Import it first if
you have not already:

curl -sS https://github.com/trinitystake.gpg | gpg --import

Important

  • Connecting spends real funds. Sessions are blockchain transactions priced in
    udvpn, and a failed connection is refunded automatically, but an expired one is not.
  • The AppImage needs a fusermount before it starts, which stock desktops already
    have. If command -v fusermount3 fusermount prints nothing, install fuse3; on Arch,
    nss too. AppImageLauncher 2.2.0 cannot start it: upgrade to 3.0 or remove it. The
    APPIMAGE_EXTRACT_AND_RUN=1 workaround avoids needing FUSE. See the README.
  • AppImage on Ubuntu 24.04+ runs with the Chromium sandbox disabled. An AppImage can
    install neither an AppArmor profile nor a SUID sandbox helper, so prefer the .deb there.

Security model

Node operators are treated as adversaries. Everything a node sends is validated before it
reaches a privileged operation, because a VPN config can otherwise run shell commands as
root. See CLAUDE.md
for the full threat model and architecture.

License

GPL-3.0-or-later. Bundled binaries (v2ray, xray, hysteria) and the libraries compiled
into the app and its VPN helper are under their own licenses, whose texts ship in the
packages. See
THIRD-PARTY-LICENSES.md.