Skip to content

v1.14.1

Latest

Choose a tag to compare

@proofoftrinity proofoftrinity released this 06 Oct 03:43
v1.14.1
dfe2ff8

Katacomb VPN 1.14.1

A desktop client for the Sentinel decentralized VPN network. Pick a node, pay for a
session on-chain, and tunnel through WireGuard, AmneziaWG, OpenVPN, V2Ray, XRAY or
Hysteria2.

1.14.1 is a fixes release. The headline is what happens when a two-hop chain loses one
of its hops: the app now sees it coming, tells you which hop ended, and lets you close
the one that is still open. Also new: a tidier Sessions tab and a speed test that no
longer contacts Google.

Highlights

  • A chain no longer dies silently. The exit hop of a chain reports no usage, so the
    blockchain closes it about two hours after you buy it, while the entry carries on. Until
    now the app did not notice: it kept saying Connected while nothing got through, and the
    notice it eventually showed named the entry node and suggested a reconnect that could
    not work. Now:
    • about 10 minutes before the exit closes, a desktop notification says the chain is
      about to stop;
    • once the exit's time is up, the app tests the tunnel, and if nothing gets through it
      disconnects and says the blockchain closed the exit hop, names that node, and says the
      entry hop is still open, with a button to the Sessions tab. If the tunnel still works,
      it stays connected and tests again a minute later;
    • in local-proxy mode you get the warning, but the app does not test or disconnect,
      because there is no tunnel to test.
  • A chain that has lost a hop gets its own card. It used to be drawn as Ended, with no
    buttons, while its other hop was still open. The Sessions tab now marks it Chain
    broken
    , shows which hop ended and when the blockchain will close the other one on its
    own, and offers End for the open hop and New chain. It no longer offers
    Reconnect, and the tray's Connect no longer tries to rebuild such a chain.
  • Ending a chain yourself no longer looks like a failure. End on a chain cancels two
    sessions, one after the other, and between the two the card briefly read as if a hop had
    broken. It now stays as it was until both are cancelled. If the second cancel fails, the
    card says you ended the first hop and offers End for the rest.
  • The Sessions tab hides ended sessions. An ended session stays on chain for up to two
    hours while it settles, and there is nothing to do with it. It is now hidden behind a
    Show ended box, unchecked by default, with a count of what it hides beside it.
    A chain with an open hop is never hidden.
  • An open chain shows when it will stop. Its card used to read "Expires in X unless the
    nodes report usage", which suggested that using the chain would extend it. It now reads
    "Chain stops in about X, when the blockchain closes the exit hop".
  • The speed test no longer contacts Google. Latency is now timed against
    speed.cloudflare.com, the server the download test tries first, and the status bar
    reads "Latency: N ms" instead of "Google: N ms". It also times a request on a connection
    that is already open, so the figure no longer includes connection setup through a fresh
    tunnel.
  • Nothing else changes. The packaging is the same as in 1.14.0.

Fixes in 1.14.1

  • Multihop: a chain the user ended is not a broken chain
  • Multihop: handle a chain that loses one hop
  • Sessions: hide ended cards behind a Show ended box
  • Speed test: time latency against Cloudflare, not Google

Known limitations

  • A chain has a hard life of about two hours. Measured on mainnet: exit hops report
    no usage to the chain, so the exit's idle deadline is pinned at purchase and never
    moves, even while the entry still has quota. This is node-side behaviour, not a client
    bug, but it is yours to plan around. The app warns you about 10 minutes before the
    exit closes.
  • Chains can only be built from V2Ray and XRAY nodes. The other protocols have no
    equivalent of the relay mechanism a chain needs.
  • Expect roughly 2 to 3 MB/s and a large latency increase on a chain. Chains are for
    privacy, not speed.
  • Without systemd-resolved, a missing resolvconf still shows up after you pay. The
    app cannot safely install one on such a system, so a WireGuard or AmneziaWG connection
    there pays first, then offers Retry without VPN DNS on the same session, which sends
    your DNS queries outside the tunnel. To avoid it, set up a resolvconf provider such as
    openresolv the way your distribution documents.
  • Local-proxy mode tunnels only the apps you point at its SOCKS address. Everything else
    leaks, by design, and the kill switch does not apply.
  • A node that does not sign its handshake reply can be impersonated, and today that
    is nearly every node. The TLS and Reality wrapping does not authenticate the node, and
    there is nothing on chain to check its certificate against, so an attacker on your
    local network can answer the handshake in its place. A node reported at dvpnd 9.4 or
    later is required to sign, which closes this for it, but almost no node runs that
    version yet.
  • The wallet link check sees direct transfers only. Two wallets funded from the same
    third account of yours are still linked on chain, and the review cannot tell.

Platform support

Linux x86_64 only. Tested on Debian 11+, Ubuntu 20.04+, and derivatives (Mint,
Pop!_OS, Zorin). The packaging is unchanged since 1.11.2, whose .deb and AppImage were
checked on a clean Ubuntu 24.04 desktop, the .deb in containers on Debian 12 and 13 and
Ubuntu 22.04, 24.04 and 26.04, and the AppImage in containers on those and Fedora 44.

Installation

Recommended: .deb

sudo apt install ./katacomb-vpn_1.14.1_amd64.deb

Installs a root daemon, so connect and disconnect never prompt for a password. It needs
one log out and log back in after the first install before that takes effect.

Alternative: AppImage

chmod +x katacomb-vpn-1.14.1.AppImage
./katacomb-vpn-1.14.1.AppImage

No install needed. The first connection that needs the VPN helper installs it, with one
password prompt. After that each privileged operation prompts for a password, cached for
a few minutes.

Verifying your download

sha256sum -c SHA256SUMS --ignore-missing
gpg --verify SHA256SUMS.asc SHA256SUMS

Signed with key 740A F267 B0D8 162B E477 779D 7315 246A 6E67 F3C6. Import it first if
you have not already:

curl -sS https://github.com/trinitystake.gpg | gpg --import

Important

  • Connecting spends real funds. Sessions are blockchain transactions priced in
    udvpn, and a failed connection is refunded automatically, but an expired one is not.
  • The AppImage needs a fusermount before it starts, which stock desktops already
    have. If command -v fusermount3 fusermount prints nothing, install fuse3; on Arch,
    nss too. AppImageLauncher 2.2.0 cannot start it: upgrade to 3.0 or remove it. The
    APPIMAGE_EXTRACT_AND_RUN=1 workaround avoids needing FUSE. See the README.
  • AppImage on Ubuntu 24.04+ runs with the Chromium sandbox disabled. An AppImage can
    install neither an AppArmor profile nor a SUID sandbox helper, so prefer the .deb there.

Security model

Node operators are treated as adversaries. Everything a node sends is validated before it
reaches a privileged operation, because a VPN config can otherwise run shell commands as
root. See CLAUDE.md
for the full threat model and architecture.

License

GPL-3.0-or-later. Bundled binaries (v2ray, xray, hysteria) and the libraries compiled
into the app and its VPN helper are under their own licenses, whose texts ship in the
packages. See
THIRD-PARTY-LICENSES.md.