I'd think that Wireless folks should move away from MSCHAP entirely, and move to something like EAP-TLS.
Which, BTW, I'm setting up for our network right now, but I'm not finding the docs I need for the Cisco 1240AG units that we're using. More searching and asking questions... Kurt On Tue, Jul 31, 2012 at 5:47 PM, Kennedy, Jim <[email protected]> wrote: > Apparently this MChap vulnerability has been around awhile. It's been broken > for some time, just wasn't practical to break the hash. What Moxie did was > add the ability to bust the hash in the cloud making it faster and easier. In > a PPTP situation grabbing that mchap hash enroute is not easily done. The > risk is there (always has been) and PPTP users should move away as soon as > practical, PPTP is legacy and now less secure than ever. But no need to panic > about this one, imho. > > Wireless MChap2 folks should make their clients validate the radius server > cert before passing the hash. > > Disclaimer: The above is paraphrasing my source who was at Moxies talk on > this at Defcon. > ________________________________________ > From: Ben Scott [[email protected]] > Sent: Tuesday, July 31, 2012 11:51 AM > To: NT System Admin Issues > Subject: Re: MSCHAP V2 completely broken > > On Tue, Jul 31, 2012 at 11:40 AM, Matthew W. Ross > <[email protected]> wrote: >> I don't follow the crypto world, so is there an alternative crypto for PPTP >> available? Just curious. > > It's not so much PPTP as Microsoft's various attempts at > authentication/key exchange methods that are broken. But for VPNs, > the rest of the world seems to have gone in the direction of IPsec- > and SSL-based solutions. OpenVPN is SSL-based, and Win 2000 and later > support an IPsec-based VPN. > > This is prolly more significant for places that are using MS-CHAP > for wireless/network authentication. > > -- Ben > > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ > ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ > > --- > To manage subscriptions click here: > http://lyris.sunbelt-software.com/read/my_forums/ > or send an email to [email protected] > with the body: unsubscribe ntsysadmin > > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ > ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ > > --- > To manage subscriptions click here: > http://lyris.sunbelt-software.com/read/my_forums/ > or send an email to [email protected] > with the body: unsubscribe ntsysadmin > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ --- To manage subscriptions click here: http://lyris.sunbelt-software.com/read/my_forums/ or send an email to [email protected] with the body: unsubscribe ntsysadmin
