IPsec Vulnerabilities and Software Security Prediction
altsci.com
altsci.com
And the difference between FreeSWAN, LibreSWAN, and StrongSWAN was very confusing to me unitl I read this.
http://serverfault.com/questions/173158/strongswan-vs-opensw...
I mean setting up VPN is no trivial pursuit, but the amount of effort to set any of these up to use native VPN clients for my mobile (Android devices) encouraged me to potentially consider StrongSWAN once I really review the documentation and learn as much as I can.
What are others doing?
Thanks for the cool article either way.
I'm in a meeting and drawing a blank on what the primary reason was for avoiding password-only... I'll update if I can remember the reason besides "passwords are easier to crack"
Maybe the certificates could be stored in LDAP.
I use ipsec-tools, as circa 2012 when I was originally setting this up, it was the only free software IPsec solution I could get to work with iOS clients, but based on this vulnerability I've now disabled it and will try StrongSWAN again.
https://www.bestvpn.com/blog/5919/how-to-hide-openvpn-traffi...
Plus, I wanted to better secure my home network AND make it accessible remotely (in a dorm-like accomodation with enterprise-grade NAT with Cisco gear), I thought an IPSec tunnel would be optimal as well.
Heck, Cisco's "Small Business" RV router series (RV042/RV082/RV016/RV042G and possibly others) are still being sold after several hardware revisions (still kind of long in the tooth), and they support all of two VPN types: IPSec and PPTP.
So definitely write about that. There is so much bullshit and misinformation I have read this week alone on VPN config in *nix environments, it's astounding. My shakiness was only confirmed by this article.
IPSec is still the enterprise defacto standard. Its pretty much everywhere.
Yeah, it a little different for the FOSS home hobbyist, but for companies with a budget, its a trivial addition to their infrastructure (Cisco, Sonicwall, etc). FOSS IPSec implementations seem to be pretty non-existant in practice from my own experience and I only see FOSS-only shops using OpenVPN, which is OpenSSL based (which, of course, suffered from heartbleed).
Exactly. I'd love to see a simple, auditable and secure open source VPN software. (not OpenVPN)
https://github.com/jlund/streisand
EDIT: Forgot the link, like a proper idiot.
The article mentions Vista and Window Server 2008, but it applies to Windows 7 and Windows 8 as well. There are some Stack Overflow threads as well.
For the VPN setup, I largely followed these instructions:
http://www.stormacq.com/build-a-private-vpn-server-on-amazon...
There are a few typos in the scripts cited in the article especially around saving the iptables rules.
OS X's native VPN client worked out of the box
I mean, it was educational and somewhat entertaining, but the lack of professionalism bothers even me, and that's saying something... Just stick to the technical aspects so that people can fix this as quickly as possible.
With all due respect, find a more appropriate soap-box next time. All the ranting simply caught me off guard in a 0-day announcement.
Finding the vulnerability leaves him full of confused regret?
> Relativism and Utilitarianism are not a valid excuse for doing harm. A person who does harm consistently marks himself or herself as a bad actor. It is our job to name them and reduce harm.
The rhetoric doesn't fit reality so much. Like you said stick to the technical facts, so moral people everywhere can "do the right thing".
I find that when I keep my opinions to myself, people assume that something very different than what I am thinking. I have become more outspoken recently as I have found that people are more willing to listen to and argue things that they disagree with if they trust the person saying it (yourself perhaps?).
The audience of this document was the TA3M Seattle group, which is very different from the average tech audience. It was a mix of people who are programmers and people who are not. I tried to put the subject area into both areas. If I was speaking to a tech audience, I would have made the paper more like this: https://www.altsci.com/ipsec/ipsec-tools-sa.html and simply described the problem of software security prediction instead of trying to give people actionable advice and the reason why.
So this document attempts to give people 0-day and the motivations behind naming software as unmaintained. I think that most people don't understand how many hours I spent trying to report my findings (~20 hours) when finding the vulnerability took just 3-4 hours. If we want secure software, we need to remove IPsec-tools and similarly unmaintained software from the open source ecosystem so that we don't spend 20 hours trying to contact them every time we find a vulnerability.
You have convinced me to release a version of the report without the soapbox for people like you: https://www.altsci.com/ipsec/ipsec-tools-sa.html
I meant no harm. You are most probably accomplishing the types of things in the security field that I can only dream about. /me stares off into space, thinking of a day when I might discover a vital 0-day.
Congrats on the discovery!
The reason that many vulnerabilities have been found in Chrome is because it is a very large and complex project. The bug bounty only gives people the necessary additional motivation to work on it during business hours. Other projects that lack bug bounties have found similar numbers of bugs (Wireshark and ClamAV to name a few) due to their complexity.