Re: PPTP traffic should be considered unencrypted
Charlie Brady <[email protected]> Tue, 31 Jul 2012 20:42:28 -0400 (EDT)
| Newsgroups | gmane.network.poptop,gmane.comp.misc.pptpclient.devel |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 31 Jul 2012, Tim Gustafson wrote: > Actually, it occurs to me that I haven't seen this question asked or > answered so far either: > > The vulnerability described does not seem to be related to EAP, > correct? Is using EAP as an authentication method still viable? > > I'm thinking something like EAP-TTLS. As described on the Wikipedia > page, it seems like a viable option. I get that it doesn't do MPPE > encryption, but as I mentioned before, I don't particularly care about > that. EAP-TLS doesn't preclude MPPE. See: http://www.ietf.org/rfc/rfc3079.txt -- Charlie ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/