Re: PPTP traffic should be considered unencrypted

Charlie Brady <[email protected]> Tue, 31 Jul 2012 20:44:26 -0400 (EDT)
Newsgroups gmane.network.poptop,gmane.comp.misc.pptpclient.devel
Message-ID <[email protected]>
On Tue, 31 Jul 2012, James Cameron wrote:

> > The vulnerability described does not seem to be related to EAP,
> > correct?  Is using EAP as an authentication method still viable?
> 
> I agree, the vulnerability is specific to MSCHAP-v2.  I know nothing
> useful about EAP, sorry.  I don't know if anybody has it working with
> PPTP. 

I posted a link to patches earlier.

> Yes, MPPE depends on MSCHAP-v2, I don't think it can be made to
> depend on anything else, but that's a matter for the pppd guys, in
> pptpd land we just ask pppd to do it.

MPPE session keys can be derived from EAP-TLS authentication. See the rfc 
(and presumably the patches, which I haven't studied).

--
Charlie


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/