Re: Secure and convenient protocol
James Cameron <[email protected]>
| Newsgroups | gmane.network.poptop |
|---|---|
| Organization | Netrek Vanilla Server Dictator |
| Message-ID | <[email protected]> |
On Thu, Apr 21, 2011 at 04:21:05PM +0200, Gr?goire Leroy wrote: > Is bruteforce attack the only problem with MSCHAPV2 ? No, it can be transparently attacked by capture of the datastream, and since the MSCHAP tokens are used as MPPE keys, and it is only 128-bit encryption, and the same keys are used at each end, the data is easily obtained. PPTP has an unencrypted control channel (TCP port 1723), and an unencrypted link control protocol (ppp). The data stream is only partly encrypted; the sequence numbers are quite visible. On Thu, Apr 21, 2011 at 10:26:39AM +0200, Gregoire leroy wrote: > The purpose of VPN is to crypt communications, to make harmless MITM > attacks. As I can't struggle against MITM attack, the only solution is > to crypt communications. Choose something stronger than 128-bit, and use unique keys at each end, and form the keys from something other than the data in network packets. OpenVPN version 2.0 or later has username/password authentication, according to Wikipedia. -- James Cameron http://quozl.linux.org.au/ ------------------------------------------------------------------------------ WhatsUp Gold - Download Free Network Management Software The most intuitive, comprehensive, and cost-effective network management toolset available today. Delivers lowest initial acquisition cost and overall TCO of any competing solution. http://p.sf.net/sfu/whatsupgold-sd