Google Secure Access, Insecure?

Posted by nullbit on September 21, 2005, 11:55 pm

Google Secure Access which we covered yesterday might not be that secure after all according to WiTopia (who make a competing solution, it should be noted). Mike at TechDirt elaborates on the technical details:

Assuming the basic claims they're making are true (and it would be pretty easy for someone with the VPN client to check), then this solution really isn't particularly secure -- which is surprising, because it wouldn't have been hard to lock this down much tighter. The basic summary sent in by Feed Mesh is that the VPN uses PPTP instead of SSL. That's not entirely horrible if the PPTP offering is better locked down, but it doesn't appear to be (and SSL would have been a better overall solution no matter what). They're allowing both CHAP and MS-CHAP (v1) which have well known issues (as the Full Mesh guys point out, just check Google for lots of info on the problems with CHAP and MS-CHAP). Finally, they let pretty much everything pass through the VPN, rather than just TCP/IP.

Add to del.icio.us | Post Comment



Discuss

No comments


Submit Comment