Whole-home VPN router with hardware kill switch (OpenWrt and WireGuard)
Details
- External ID
- 46073862
- Source
- HN
- Company
- —
- Product
- Whole-home VPN router with hardware kill switch (OpenWrt and WireGuard)
- Website domain
- github.com
- Launched
- Nov. 27, 2025
- Cohort
- —
- Upvotes
- 19
- Upvotes percentile
- 0.6834061135371179
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
With internet censorship and surveillance on the rise, ie; UK Online Safety Bill (July 2025) and Australia's social media legislation (Dec 2025) introducing mandatory age verification (read: initial step on the pathway to social credit), I wanted a privacy-first solution that protects browsing history from ISPs and third-party verification services, but not one that requires you to be an Einstein to deploy.This stack turns a Raspberry Pi (or any OpenWrt-compatible device) into a network-wide VPN gateway.Key features: - Firewall kill switch: VPN down = no internet (not a software rule that can leak) - AmneziaWG obfuscation for DPI-resistant connections - Optional AdGuard Home for DNS filtering - Works for all devices including smart TVs and IoT that can't run VPN appsNot a techie? The README is optimized for AI-assisted deployment. Feed it to your LLM of choice (Claude, GPT, etc.) and it can walk you through the entire setup for your specific hardware.Mullvad-focused but works with any WireGuard provider. MIT license.Docker deploy in testing (coming soon)
Enrichment
- Theme
- proxy, dns, and networking tools
- Vertical
- Security
- Function
- Hardware & robotics
- Audience
- B2C
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- vpn router with hardware kill switch
- Manually corrected
- False
Could you build this?
No This requires physical hardware router modification, electronics design for a physical kill switch, and custom embedded Linux/OpenWrt kernel network driver and firewall configuration.
What it would actually take: Building this requires custom router hardware or modifying an existing SoC (like MediaTek or Atheros) to wire a physical GPIO/hardware kill switch. The software stack involves compiling custom OpenWrt images, configuring kernel routing tables, WireGuard tunnels, and fail-safe iptables/nftables rules to prevent DNS/IP leaks upon connection drops. Deep networking, embedded Linux, and hardware tinkering skills are necessary.
Discussion
20 comments analyzed.
Competitors mentioned: Router VPN settings from ISP, Wireguard
Concerns raised: AI-generated content without proper review, Incorrect terminology (hardware kill switch vs fail-safe), Unclear differentiation from existing VPN solutions, Lack of human intent/editorial oversight in output, Limited commit history on repository
Feature requests: Network namespace for kill switch redundancy, Lower-level isolation mechanism instead of firewall rules
Competitors
Other products that read as similar to this one — 104 launches clear the similarity bar, closest 8 shown.
Attention rank: #43 of 105 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 29 days after the earliest competitor.
- SmokeVPN · hn · 2026-08-01 · 9 upvotes · similarity 0.58
- Netrinos · hn · 2025-12-19 · 93 upvotes · similarity 0.53
- SMTP Tunnel · hn · 2026-01-07 · 140 upvotes · similarity 0.48
- RouteBoss: Network Control · ph · 2026-09-29 · 2 upvotes · similarity 0.47
- 6 months free VPN · ph · 2026-09-26 · 1 upvotes · similarity 0.46
- dorm-vpn-bypass · github · 2026-09-11 · 13 upvotes · similarity 0.45
- Relay · ph · 2026-09-22 · 1 upvotes · similarity 0.44
- Nullwire · ph · 2026-09-10 · 2 upvotes · similarity 0.43
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a hardware & robotics tool for Horizontal yet.