I'd think that Wireless folks should move away from MSCHAP entirely,
and move to something like EAP-TLS.

Which, BTW, I'm setting up for our network right now, but I'm not
finding the docs I need for the Cisco 1240AG units that we're using.
More searching and asking questions...

Kurt

On Tue, Jul 31, 2012 at 5:47 PM, Kennedy, Jim
<[email protected]> wrote:
> Apparently this MChap vulnerability has been around awhile. It's been broken 
> for some time, just wasn't practical to break the hash. What Moxie did was 
> add the ability to bust the hash in the cloud making it faster and easier. In 
> a PPTP situation grabbing that mchap hash enroute is not easily done. The 
> risk is there (always has been) and PPTP users should move away as soon as 
> practical, PPTP is legacy and now less secure than ever. But no need to panic 
> about this one, imho.
>
> Wireless MChap2 folks should make their clients validate the radius server 
> cert before passing the hash.
>
> Disclaimer:  The above is paraphrasing my source who was at Moxies talk on 
> this at Defcon.
> ________________________________________
> From: Ben Scott [[email protected]]
> Sent: Tuesday, July 31, 2012 11:51 AM
> To: NT System Admin Issues
> Subject: Re: MSCHAP V2 completely broken
>
> On Tue, Jul 31, 2012 at 11:40 AM, Matthew W. Ross
> <[email protected]> wrote:
>> I don't follow the crypto world, so is there an alternative crypto for PPTP 
>> available? Just curious.
>
>   It's not so much PPTP as Microsoft's various attempts at
> authentication/key exchange methods that are broken.  But for VPNs,
> the rest of the world seems to have gone in the direction of IPsec-
> and SSL-based solutions.  OpenVPN is SSL-based, and Win 2000 and later
> support an IPsec-based VPN.
>
>   This is prolly more significant for places that are using MS-CHAP
> for wireless/network authentication.
>
> -- Ben
>
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~
>
> ---
> To manage subscriptions click here: 
> http://lyris.sunbelt-software.com/read/my_forums/
> or send an email to [email protected]
> with the body: unsubscribe ntsysadmin
>
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~
>
> ---
> To manage subscriptions click here: 
> http://lyris.sunbelt-software.com/read/my_forums/
> or send an email to [email protected]
> with the body: unsubscribe ntsysadmin
>

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here: 
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe ntsysadmin

Reply via email to