bk99.de entertain the web since 1997

Microsoft patches PPTP security holes

Summary

In August 1998 Microsoft released final patches for security holes in its implementation of the Point-to-Point Tunneling Protocol. PPTP was mainly used to build VPNs over the internet; the problems had become known in early June. Security bulletin 98-012 recommended the updates for dial-up networking under Windows 95 and 98 and for RAS under Windows NT 4.0.

Ideas

  • PPTP was meant to connect distributed computers securely over TCP/IP.
  • Initial hotfixes were only followed by final patches weeks later.
  • Localised patches for Windows NT came later than the US versions.

Insights

  • A VPN protocol is only as secure as its concrete implementation.
  • Delayed localised updates extend the risk for users outside the USA.

Facts

  • Microsoft described the updates in security bulletin 98-012.

References

Critique

  • The report does not say what the weaknesses consisted of; Bruce Schneier and Mudge’s analysis of PPTP would have provided context.

Remarks

  • PPTP with MS-CHAPv2 is now considered broken and should no longer be used; common alternatives are WireGuard, IPsec/IKEv2 or OpenVPN.

Recommendations

  • Replace remaining PPTP access with WireGuard, IPsec/IKEv2 or OpenVPN.
  • With security-critical patches, do not wait for localised versions if the risk is high.

Read the original article

Search the Web Archive