... is pretty informative. There is a PSK mode, which really should be essentially indistinguishable from random UDP packets. But I haven't read deeply enough. I do PSK on all my networks, but that has its own disadvantages. I honestly thought that was the only way to do wireguard.
https://lists.zx2c4.com/pipermail/wireguard/2016-July/000184...