
Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [tlug] VPN
On Mon, Dec 06, 2004 at 08:37:35PM +0900, Jacques Deguest wrote:
> As far as I know, there are 3 main types of VPN: FreeS/Wan, OpenVPN (SSL
> VPN) and PPTP.
No. There are two types of VPN:
1) IPSEC,
2) everything else.
Option #1 is trustworthy _only_ if the following are true:
* XAUTH is not being used,
* both endpoints are controlled,
* the CA has not been compromised (x.509 only)
* the preshared secret is an ungodly long string generated by a monkey banging
on a keyboard for a bit.
Option #2 ain't even close to trustworthy. Go ahead -- set up a solution using
PPTP, go to defcon, use it, and see how fast your concentrator is cracked.
--
-- Chris
GPG key FEB9DE7F (91AF 4534 4529 4BCC 31A5 938E 023E EEFB FEB9 DE7F)
Home |
Main Index |
Thread Index