Fwd: Re: Secure and convenient protocol
"Gregoire leroy" <[email protected]>
| Newsgroups | gmane.network.poptop |
|---|---|
| Message-ID | <[email protected]> |
----- Original Message -----
From: "Gregoire leroy" [email protected]
To: "James Cameron" [email protected]
Sent: Thu 21/04/11 10:18
Subject: Fwd: Re: [Poptop-server] Secure and convenient protocol
<hi>> I'm curious though what the purpose of
> the VPN is, since that would assist with solution choice. I can imagine
> several purposes, and I'm not sure which you might have.
The purpose of VPN is to crypt communications, to make harmless MITM attacks. As
I can't struggle against MITM attack, the only solution is to crypt communications.
>
> > My first choice was MSCHAPV2, because it's well
> supported by most
> OS, but it seems unsecure.
>
> It was considered secure once, but times have changed. I consider it
> unsecure now.
>
> > So, is there a secure protocol, well supported by
> most OS, with which
> we don't need to touch to the client computer ?
> (with password, for
> example)
>
> I don't believe so, but I only really know about OpenVPN and PPTP.
> Others may know.
>
> Basing a security system on only a password (and not also a token)
> leads to a weak system, in the same way as building a house upon the sand
> near a river. A system that hashes passwords (MSCHAPV2) cannot be made
> more secure by a longer or more complex password; a brute force attack
> takes the same resources.
I guess I must find a way to use EAP-TLS in a simple way for the client, to avoid
useless support
Thanks,
Regards,
------------------------------------------------------------------------------
Benefiting from Server Virtualization: Beyond Initial Workload
Consolidation -- Increasing the use of server virtualization is a top
priority.Virtualization can reduce costs, simplify management, and improve
application availability and disaster protection. Learn more about boosting
the value of server virtualization. http://p.sf.net/sfu/vmware-sfdev2dev