github anton48/vk-turn-proxy-ios v1.0-build443
A console client for macOS, Linux and FreeBSD; a laptop's wake handshakes at once; the credential cache knows its mode; the captcha page's new argument

one hour ago

THE CONSOLE CLIENT (tools/vk-turn-proxy-console). The app's native SRTP
transport as a command-line program for macOS (Intel and Apple Silicon),
Linux (amd64, arm64) and FreeBSD (amd64), built by GitHub from this tag
and attached to this release beside the IPA. It reads the app's backup
(the settings and the servers), keeps the proxy's own traffic — the
relays, the VK API, the network's DNS — on the physical path by /32
routes pinned at dial time, moves the default route and the system DNS
into the tunnel, and takes everything back on Ctrl-C, on a signal, or at
the next start after a crash (a journal of every change beside the
credential cache). A network change is one path change to the pool. A
wake after sleep drops WireGuard's keys at once and asks for a handshake
as soon as a session can carry it: the stock Go runtime's clock stands
still in sleep, so WireGuard went on sending with a key the server had
expired — 14 s of silence after a wake in the field, 0.1 s now. One
console per machine (a locked pid file), a log file of its own, cookie
mode from a cookies.txt export. See docs/console.md.

THE CREDENTIAL CACHE KNOWS ITS MODE. The pool stamps creds-pool.json with
the mode its identities were minted in — anonymous, or the logged-in
account's — and ignores a file of the other mode, rewriting it at its
next save; the app's backup carries the stamp, and the pre-bootstrap seed
applies the same rule to a restored cache. Without it the console ran
forty connections on the previous run's anonymous identities in cookie
mode, and a restored backup could have seeded an account's credential
into an anonymous session. The app's own guard — the cache cleared on a
mode change — stays the first line.

THE CAPTCHA PAGE'S FOURTH ARGUMENT. On 2026-09-30 VK's proof-of-work
page added a fourth argument to its script's closing call — the list of
the telemetry probes the page runs — and the automatic solve found no
parameters on every page, on the console and on the phone alike. The
parser reads the three it needs and lets the call go on; the envelope
did not change. Proven on a stand: TURN credentials at the first attempt.

No server change. A client of this line still needs srtp-build306 or
newer; srtp-build440 gives it the keepalive and the group notice.

Don't miss a new vk-turn-proxy-ios release

NewReleases is sending notifications on new releases.