Microsoft patches PPTP security holes
Summary
In August 1998 Microsoft released final patches for security holes in its implementation of the Point-to-Point Tunneling Protocol. PPTP was mainly used to build VPNs over the internet; the problems had become known in early June. Security bulletin 98-012 recommended the updates for dial-up networking under Windows 95 and 98 and for RAS under Windows NT 4.0.
Ideas
- PPTP was meant to connect distributed computers securely over TCP/IP.
- Initial hotfixes were only followed by final patches weeks later.
- Localised patches for Windows NT came later than the US versions.
Insights
- A VPN protocol is only as secure as its concrete implementation.
- Delayed localised updates extend the risk for users outside the USA.
Facts
- Microsoft described the updates in security bulletin 98-012.
References
Critique
- The report does not say what the weaknesses consisted of; Bruce Schneier and Mudge’s analysis of PPTP would have provided context.
Remarks
- PPTP with MS-CHAPv2 is now considered broken and should no longer be used; common alternatives are WireGuard, IPsec/IKEv2 or OpenVPN.
Recommendations
- Replace remaining PPTP access with WireGuard, IPsec/IKEv2 or OpenVPN.
- With security-critical patches, do not wait for localised versions if the risk is high.
Links to the original source and the Web Archive open in a new tab.