Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Whole-home VPN router with hardware kill switch (OpenWrt and WireGuard)

Details

External ID
46073862
Source
HN
Company
—
Product
Whole-home VPN router with hardware kill switch (OpenWrt and WireGuard)
Website domain
github.com
Launched
Nov. 27, 2025
Cohort
—
Upvotes
19
Upvotes percentile
0.6834061135371179
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

With internet censorship and surveillance on the rise, ie; UK Online Safety Bill (July 2025) and Australia's social media legislation (Dec 2025) introducing mandatory age verification (read: initial step on the pathway to social credit), I wanted a privacy-first solution that protects browsing history from ISPs and third-party verification services, but not one that requires you to be an Einstein to deploy.This stack turns a Raspberry Pi (or any OpenWrt-compatible device) into a network-wide VPN gateway.Key features: - Firewall kill switch: VPN down = no internet (not a software rule that can leak) - AmneziaWG obfuscation for DPI-resistant connections - Optional AdGuard Home for DNS filtering - Works for all devices including smart TVs and IoT that can't run VPN appsNot a techie? The README is optimized for AI-assisted deployment. Feed it to your LLM of choice (Claude, GPT, etc.) and it can walk you through the entire setup for your specific hardware.Mullvad-focused but works with any WireGuard provider. MIT license.Docker deploy in testing (coming soon)

Enrichment

Theme
proxy, dns, and networking tools
Vertical
Security
Function
Hardware & robotics
Audience
B2C
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
vpn router with hardware kill switch
Manually corrected
False

Could you build this?

No This requires physical hardware router modification, electronics design for a physical kill switch, and custom embedded Linux/OpenWrt kernel network driver and firewall configuration.

What it would actually take: Building this requires custom router hardware or modifying an existing SoC (like MediaTek or Atheros) to wire a physical GPIO/hardware kill switch. The software stack involves compiling custom OpenWrt images, configuring kernel routing tables, WireGuard tunnels, and fail-safe iptables/nftables rules to prevent DNS/IP leaks upon connection drops. Deep networking, embedded Linux, and hardware tinkering skills are necessary.

Discussion

20 comments analyzed.

Competitors mentioned: Router VPN settings from ISP, Wireguard

Concerns raised: AI-generated content without proper review, Incorrect terminology (hardware kill switch vs fail-safe), Unclear differentiation from existing VPN solutions, Lack of human intent/editorial oversight in output, Limited commit history on repository

Feature requests: Network namespace for kill switch redundancy, Lower-level isolation mechanism instead of firewall rules

Competitors

Other products that read as similar to this one — 104 launches clear the similarity bar, closest 8 shown.

Attention rank: #43 of 105 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 29 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a hardware & robotics tool for Horizontal yet.