The White Paper of Warren
All my choices for Warren: why not WireGuard? why QUIC? why is port forwarding back? ... and also what Warren does not protect.
A nice PDF, bare, no form and no email caught along the way. It is a gift.
A very faint hint of a credo, I show it mostly through actions. I put all my seriousness into it, and all my love.
Contents
Few people read white papers, and that is fair, they are a bit of a bore. But I tried to keep it short, and to make it tastier.
I ask for no trust and make no promise, I offer you to trust an architecture, so I hand it to you, bare and stripped down: the decisions, the mechanisms that hold them up, what they cost, and the list of what Warren does not protect.
#Preliminaries
- Why I built Warren, when the market is already crowded with VPNs making the exact same promises.
- Why not WireGuard, even though it was the starting point.
- Why QUIC as the foundation of the whole stack, and what that move costs in engineering.
- Why port forwarding comes back here, when Mullvad and IVPN dropped it in 2023.
- Why there is no account and no email, and what that means the day you lose your recovery phrase.
- Why the servers keep nothing, down to the choice of filesystem and boot image.
- Why I swim against the current: paid tiers, features reserved for those who pay more, a world map inflated with virtual servers, pseudo-decentralisation that cannot be verified... it wears you down.
- What Warren does not protect. A whole chapter, because a VPN claiming to protect against everything is talking nonsense.
The document is written in French, English and Romanian; because I am Bulă, the voice of the warren, and Bulă is Romanian. The PDF opens in a new tab and reads offline: no account, no email, no tracker.
#What is inside
Six parts, 33 chapters. The first two read without any technical background; the rest go deeper into the warren. The full table of contents sits at the front of the PDF, here is the map.
#Part I. Why Warren
The reasons before the architecture. What a no-log promise is actually worth, what the 2023 sacrifice of port forwarding says about the industry, and why a tunnel that can be spotted gets blocked long before it arrives.
- No-log, and why a promise is not enough
- May 2023: when port forwarding became unwanted
- Obfuscation as a condition of existence
- Three properties, one conviction
#Part II. How the stack came to be
The history of the choices, detours included. Why WireGuard was set aside, why the desktop app is a fork of Mullvad's, and what the QUIC bet cost us.
- Why not WireGuard
- The Iroh detour, the pivot to QUIC
- Why fork Mullvad
- The QUIC bet, and its price
#Part III. WarrenGuard, the engine
The most technical part: the single core running on every platform, the packet path, obfuscation, multi-hop, hardened port forwarding, behaviour under failure. This is where the WarrenGuard promises are checked.
- WarrenGuard: one core, every platform
- The QUIC datapath, and the Quinn fork
- Native obfuscation
- Multi-hop and the blind relay
- Traffic analysis defence
- Port forwarding, hardened
- Kill switch and fail-closed
- Memory safety and secret hygiene
#Part IV. The network
What sits inside an exit server, and above all what does not. Immutable image, runtime state in RAM only, no data partition: a physical seizure returns nothing. The plain-language counterpart is no logs and the network documented machine by machine.
- Exit servers: nothing to seize
- Anatomy of an exit server
- The blind relay and the signed directory
- The control plane
- No-log, verified by the machine
- Operating the fleet without breaking no-log
- DNS blocking: opt-in, uniform, public, no hijacking
#Part V. Identity, payment and apps
How I can grant you access without knowing who you are. The key lives on your device, payment is decorrelated from usage, sessions open with anonymous tokens, and even the forum works without an email or an IP address.
- Identity: a wallet, not an account
- Proving your subscription without an account
- Payment, decorrelated from usage
- Anonymous session credentials
- The apps: two paths, one standard of truth
- The forum, without email or IP address
#Part VI. Security and limits
The chapter you rarely find: what is guaranteed, what is only partly guaranteed, what is out of reach by nature, and who controls what. Then the trajectory, with the work that is not finished.
- Synthetic threat model
- Trajectory
- Conclusion, glossary and references
#Three excerpts
On port forwarding, dropped by competitors and restored in Warren:
A VPN must serve its users rather than protect itself from them, and the right answer to abuse combines technical and legal measures instead of amputating a feature.
On the limits, in the threat model:
It does not guarantee absolute anonymity against an adversary observing both your Internet access and the network exit and correlating the two, nor against software that controls your device. No VPN can, and a VPN that claims otherwise, lies.
On what settles the argument, in the conclusion:
The code is the record. The engine and the client kit are open and auditable, and the properties described here can be verified directly in them.
#Who wrote it, and what it is worth
The document is signed by the Warren team, published as version 1.0.20, dated 14 July 2026. It is public and versioned: when the architecture moves, the white paper moves with it and the version number changes. Nothing in it is embargoed, nothing is reserved for a prospect.
It is still a document, which means text. What settles things is the code: the engine and the client kit are open, and every property described in the document can be checked there line by line. If you find a gap between the two, write to bula@warren.ro and I will fix the document or the code.
Enjoy the read. I hope it is a treat.
