Re: Microsoft PPTP (Was: Internet Services Manager)

From: Derek (derekm@rogers.com)
Date: 04/10/02


From: "Derek" <derekm@rogers.com>
To: <focus-ms@securityfocus.com>
Date: Tue, 9 Apr 2002 19:34:19 -0400

Hello Denis,
    I would be inclined to treat the protocol skeptically.
Bruce's review just plain scares me. However, looking at the
date on the press release
(http://www.counterpane.com/pptp-pressrel.html) and the date on a
security patch
(http://www.microsoft.com/TechNet/security/bulletin/ms98-012.asp)
dealing with the PPTP protocol, I assume they "fix the problems
identified" (as quoted by the bulletin) with the patch. I am by
no mean a cryptographic expert, and I also admit was unaware of
the patch until now.

Derek

----- Original Message -----
From: "Denis Darveau" <ddarveau@gbbk.com>
To: "'Derek'" <derekm@rogers.com>
Sent: Tuesday, April 09, 2002 5:40 PM
Subject: Microsoft PPTP (Was: Internet Services Manager)

> Derek,
>
> Can you tell me if that applies to W2K as well or only NT 4 as
mentioned in
> the paper? I am in the process of a large VPN implementation
using the MS
> PPTP client that comes by default with W2K Pro. I am concerned.
>
> Thanks, Denis
>
> Denis Darveau, CISSP, MCSE
> Senior Security Engineer



Relevant Pages

  • RE: Microsoft PPTP (Was: Internet Services Manager)
    ... Note that Counterpane has released an update to their PPTP press release ... review says that MS has addressed the issues they discussed in the paper. ... with the patch. ...
    (Focus-Microsoft)
  • Re: How to improve the quality of the kernel?
    ... IMO we should concentrate more on preventing regressions than on fixing them. ... Over two years ago I've reviewed some _cleanup_ patch and noticed three bugs ... Ignore reviewers - fix the bugs but don't credit reviewers (crediting them ... review the patch than to make it so getting near to zero credit for review ...
    (Linux-Kernel)
  • Re: [ofa-general] InfiniBand/RDMA merge plans for 2.6.24
    ... I was about to post v2 of my patch to avoid port space collisions with the native stack. ... I've tried to solicit review on it, but I think folks are reluctant... ... Pradeep's IPoIB CM support for devices that don't have SRQs. ... Certainly we want to fix this ...
    (Linux-Kernel)
  • Re: warning: massive change to conditional coding style in net?
    ... David Miller wrote: ... the patch will be cleaner. ... clean patches are easier to review. ... I've followed existing coding practices. ...
    (Linux-Kernel)
  • Re: How to improve the quality of the kernel?
    ... There are not so simple cases like big infrastructure patches with ... "If the patch introduces a new regression" ... review the patch than to make it so getting near to zero credit for review ...
    (Linux-Kernel)

Quantcast