Repository navigation
v1.13.0
Katacomb VPN 1.13.0
A desktop client for the Sentinel decentralized VPN network. Pick a node, pay for a
session on-chain, and tunnel through WireGuard, AmneziaWG, OpenVPN, V2Ray, XRAY or
Hysteria2.
1.13.0 is a security release. Newer node software signs its handshake reply, and the
app now checks that signature on every connection. A new setting, Signed Nodes Only,
refuses the nodes that do not sign.
Highlights
- The handshake reply is checked against the chain. The handshake reply carries the
keys, certificate pin and addresses your tunnel then uses. Until now nothing could be
checked against, so anyone on your network path could answer the handshake in a
node's place. dvpnd from 9.4 signs that reply with the key the chain knows the node
by, and Katacomb now checks the signature on every connection, for every protocol and
for both hops of a chain. - What happens to each reply:
- Signed by the node: accepted.
- Signed by another key: accepted only if the node's account has authorised that key
on chain (an authz grant, which operators use to run a node on a separate "hot"
key). - A signature that does not check out, or a key the account never authorised:
refused, and the session is refunded like any other failed handshake. - No signature (sentinel-dvpnx, and dvpnd before 9.4): accepted as before, unless you
turn on Signed Nodes Only.
- Signed Nodes Only (Settings, VPN Security, off by default) refuses nodes that do
not sign, before you pay wherever it can. The connect button asks the node first. A
chain's exit is checked against the node list before the entry is bought. Smart
connect skips nodes older than 9.4. A node that gets past those checks and then sends
an unsigned reply is refused after the handshake, with a refund. - Almost no node signs yet. On 3 October 2026, one active node out of 1,839 reported
dvpnd 9.4, and it is a Hysteria2 node. With Signed Nodes Only on you can connect to
that node and nothing else, and you cannot build a chain, because chains need V2Ray
or XRAY nodes. Leave the setting off until operators upgrade; the signature is
checked whenever a node sends one either way. - Signed or Unsigned in the connection bar. After a handshake the bar shows whether
the node signed it; hover over it for what that means. For a chain it shows Signed
only if both hops signed. A tunnel brought back from a saved config, with no new
handshake, shows neither. - A "Signed" filter on the Nodes tab lists the nodes whose reported version is 9.4
or later. It goes by the version in the node list, so treat it as a guide: the
signature itself is what gets checked when you connect. - Nothing else changes. The packaging is the same as in 1.12.0.
Fixes in 1.13.0
- Hot-key reply: a missing grant is "no grant", not a chain fault
- Handshake: check a dvpnd node's signature; "Signed nodes only"
Known limitations
- A chain has a hard life of about two hours. Measured on mainnet: exit hops report
no usage to the chain, so the exit's idle deadline is pinned at purchase and never
moves, even while the entry still has quota. This is node-side behaviour, not a client
bug, but it is yours to plan around. - Chains can only be built from V2Ray and XRAY nodes. The other protocols have no
equivalent of the relay mechanism a chain needs. - Expect roughly 2 to 3 MB/s and a large latency increase on a chain. Chains are for
privacy, not speed. - Without systemd-resolved, a missing
resolvconfstill shows up after you pay. The
app cannot safely install one on such a system, so a WireGuard or AmneziaWG connection
there pays first, then offers Retry without VPN DNS on the same session, which sends
your DNS queries outside the tunnel. To avoid it, set up a resolvconf provider such as
openresolvthe way your distribution documents. - Local-proxy mode tunnels only the apps you point at its SOCKS address. Everything else
leaks, by design, and the kill switch does not apply. - A node that does not sign its handshake reply can be impersonated, and today that
is nearly every node. The TLS and Reality wrapping does not authenticate the node, and
there is nothing on chain to check its certificate against, so an attacker on your
local network can answer the handshake in its place. Signed Nodes Only refuses such
nodes, at the cost of leaving almost none to pick from until operators run dvpnd 9.4
or later.
Platform support
Linux x86_64 only. Tested on Debian 11+, Ubuntu 20.04+, and derivatives (Mint,
Pop!_OS, Zorin). The packaging is unchanged since 1.11.2, whose .deb and AppImage were
checked on a clean Ubuntu 24.04 desktop, the .deb in containers on Debian 12 and 13 and
Ubuntu 22.04, 24.04 and 26.04, and the AppImage in containers on those and Fedora 44.
Installation
Recommended: .deb
sudo apt install ./katacomb-vpn_1.13.0_amd64.debInstalls a root daemon, so connect and disconnect never prompt for a password. It needs
one log out and log back in after the first install before that takes effect.
Alternative: AppImage
chmod +x katacomb-vpn-1.13.0.AppImage
./katacomb-vpn-1.13.0.AppImageNo install needed. The first connection that needs the VPN helper installs it, with one
password prompt. After that each privileged operation prompts for a password, cached for
a few minutes.
Verifying your download
sha256sum -c SHA256SUMS --ignore-missing
gpg --verify SHA256SUMS.asc SHA256SUMSSigned with key 740A F267 B0D8 162B E477 779D 7315 246A 6E67 F3C6. Import it first if
you have not already:
curl -sS https://github.com/trinitystake.gpg | gpg --importImportant
- Connecting spends real funds. Sessions are blockchain transactions priced in
udvpn, and a failed connection is refunded automatically, but an expired one is not. - The AppImage needs a
fusermountbefore it starts, which stock desktops already
have. Ifcommand -v fusermount3 fusermountprints nothing, installfuse3; on Arch,
nsstoo. AppImageLauncher 2.2.0 cannot start it: upgrade to 3.0 or remove it. The
APPIMAGE_EXTRACT_AND_RUN=1workaround avoids needing FUSE. See the README. - AppImage on Ubuntu 24.04+ runs with the Chromium sandbox disabled. An AppImage can
install neither an AppArmor profile nor a SUID sandbox helper, so prefer the .deb there.
Security model
Node operators are treated as adversaries. Everything a node sends is validated before it
reaches a privileged operation, because a VPN config can otherwise run shell commands as
root. See CLAUDE.md
for the full threat model and architecture.
License
GPL-3.0-or-later. Bundled binaries (v2ray, xray, hysteria) and the libraries compiled
into the app and its VPN helper are under their own licenses, whose texts ship in the
packages. See
THIRD-PARTY-LICENSES.md.