Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] VPN



On Mon, Dec 06, 2004 at 08:37:35PM +0900, Jacques Deguest wrote:

> As far as I know, there are 3 main types of VPN: FreeS/Wan, OpenVPN (SSL
> VPN) and PPTP.

No.  There are two types of VPN:

1) IPSEC,
2) everything else.

Option #1 is trustworthy _only_ if the following are true:

* XAUTH is not being used,
* both endpoints are controlled,
* the CA has not been compromised (x.509 only)
* the preshared secret is an ungodly long string generated by a monkey banging
  on a keyboard for a bit.

Option #2 ain't even close to trustworthy.  Go ahead -- set up a solution using
PPTP, go to defcon, use it, and see how fast your concentrator is cracked.
-- 

-- Chris
	GPG key FEB9DE7F (91AF 4534 4529 4BCC 31A5  938E 023E EEFB FEB9 DE7F)


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links