Re: PPTP traffic should be considered unencrypted
James Cameron <[email protected]> Wed, 1 Aug 2012 08:26:02 +1000
| Newsgroups | gmane.network.poptop,gmane.comp.misc.pptpclient.devel |
|---|---|
| Organization | Netrek Vanilla Server Dictator |
| Message-ID | <[email protected]> |
On Tue, Jul 31, 2012 at 09:00:25AM -0700, Tim Gustafson wrote: > > http://www.theregister.co.uk/2012/07/31/ms_chapv2_crack/ > > > > "Marlinspike says that MS-CHAPv2 should be purged from the Internet, > > advising that PPTP traffic ???should be considered unencrypted???, and > > that MS-CHAPv2 enterprise users should begin migrating ??? now." > > I was just reading about this the other day, and I was hoping someone > could clarify something for me: > > Is the attack against the user's password, or the user's session > key? The user's password. That is to say, the attack would have to be repeated if the user changed their PPTP password. > > Because if it's against the session key, and the user's password is > still secure, then maybe we just rename "VPN" to "VN" and tell users > that they should use SSL or SSH to get access to resources. > > We use PPTP as a remote IP-granting service, so that users who are > currently off-campus (at home/traveling/whatever) can get on-campus IP > addresses, as some of our vendors gate access based on source IP. Is > PPTP + MSCHAv2 still an acceptable solution for that service? Whether it is acceptable to you or not is the question. The start of the PPTP traffic between a user and your server would have to be captured, such as by wireless monitoring or interception by ISP. Then the 23 hour delay to crack the password. Then the attacker can use your service as if they are your authenticated user. You could control for this by requiring a password change every 22 hours. ;-) Entirely impractical, but may be a useful way to get people to move to other technologies. Then reassess the 23 hour delay based on the advance of cracking hardware. You already face risk from compromise of the users' systems. -- James Cameron http://quozl.linux.org.au/ ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/