Re: MSCHAPv2 traffic should be considered unencrypted
Kosztyu AndrĂ¡s <[email protected]> Wed, 1 Aug 2012 11:18:18 +0200
| Newsgroups | gmane.network.poptop,gmane.comp.misc.pptpclient.devel |
|---|---|
| Message-ID | <CAHXPzJo723RqBGGF65g9BxZEGvxrVJQ3ubep85wOgkJyyO1O9Q@mail.gmail.com> |
2012/8/1 Tim Gustafson <[email protected]> > > > But I've always found OpenVPN to be easy to configure. There exist > > many clients pushed by the VPN provider market. A list here: > > > > http://en.wikipedia.org/wiki/OpenVPN#Client_software > > And, as far as mobile devices go, all of those options require rooting > your phone. > > The reason that PPTP is so nice is that pretty much EVERY device > supports it out-of-the-box. That's a big deal for me. My department > alone supports something like 500 active users, and the University as > a whole supports something like 30,000. There's no way we're going to > convince all those people to root their phones, and even if we could I > wouldn't want to support all those clients after the fact - as soon as > we do something like that, everything that ever goes wrong with that > device again is "our fault" in our client's eyes. > > As I understand it, most devices also support L2TP, but from what I > can tell that requires setting up a PKI and that is also just not > feasible. Users know how to authenticate with their login names and > passwords. The argument against this authentication model in the > documents I've read related to this MSCHAPv2 insecurity discussion is > that people pick easy-to-guess passwords. That may be so, but > requiring users to use certificates for VPN connections when we don't > require them to use certificates for HTTPS or SSH connections is > seriously missing the point. If an attacker can just bypass the VPN > and connect via HTTPS or SSH directly with a login name and password, > then there is no reason to require certificate authentication for VPN > connections. > > Also, I think we should change the title of this thread to "MSCHAPv2 > traffic should be considered unencrypted", so I have done so in this > reply. > > And, it's worth nothing that this strongly suggests that WPA and WPA2 > authentication models are also equally insecure, as those both rely on > MSCHAPv2 as well. > > -- > > Tim Gustafson > [email protected] > 831-459-5354 > Baskin Engineering, Room 313A > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > Poptop-server mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/poptop-server Actually on most android devices you can use openvpn without rooting it with featvpn which uses the builtin l2tp somehow to hack the tun connection. Also on 4.x android there is a builtin vpn api, which will be able to natively support openvpn. My company is providing public vpn service and we are finishing our pptp product as soon as we introduce the final version of our sstp server; still some testing ahead but most likely with mikrotik. ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/