Re: Secure and convenient protocol

James Cameron <[email protected]>
Newsgroups gmane.network.poptop
Organization Netrek Vanilla Server Dictator
Message-ID <[email protected]>
On Thu, Apr 21, 2011 at 04:21:05PM +0200, Gr?goire Leroy wrote:
> Is bruteforce attack the only problem with MSCHAPV2 ?

No, it can be transparently attacked by capture of the datastream, and
since the MSCHAP tokens are used as MPPE keys, and it is only 128-bit
encryption, and the same keys are used at each end, the data is easily
obtained.

PPTP has an unencrypted control channel (TCP port 1723), and an unencrypted
link control protocol (ppp).  The data stream is only partly encrypted;
the sequence numbers are quite visible.

On Thu, Apr 21, 2011 at 10:26:39AM +0200, Gregoire leroy wrote:
> The purpose of VPN is to crypt communications, to make harmless MITM
> attacks. As I can't struggle against MITM attack, the only solution is
> to crypt communications.

Choose something stronger than 128-bit, and use unique keys at each end,
and form the keys from something other than the data in network packets.

OpenVPN version 2.0 or later has username/password authentication,
according to Wikipedia.

-- 
James Cameron
http://quozl.linux.org.au/

------------------------------------------------------------------------------
WhatsUp Gold - Download Free Network Management Software
The most intuitive, comprehensive, and cost-effective network 
management toolset available today.  Delivers lowest initial 
acquisition cost and overall TCO of any competing solution.
http://p.sf.net/sfu/whatsupgold-sd
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.