Live data from Hacker News

Vulnerabilities exploited in VPN products used worldwide

ncsc.gov.uk

41–50 of 140 posts

Re: Vulnerabilities exploited in VPN products used worldwide

#41
post #39
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

> The gold standard, as ever, is Wireguard. Not disagreeing with you about the state of commercial VPN products, but regarding WG specifically. Something I don't see in the other replies just yet is that Wireguard doesn't yet have an ecosystem around it, but is designed for that in a good way. By which I mean, it follows the Unix philosophy of focusing on one specific task and doing it very well, and it has succeeded…

> It very explicitly doesn't want to deal with integrating with key management/HSMs/AD policies/whatever.

If you look at the list of vulnerabilities, they're all precisely in those parts of the stack that Wireguard doesn't address.

So what value is Wireguard providing, exactly? It's a beautiful protocol, but security isn't a beauty contest. It's easy to create a beautiful solution when you avoid dealing with the difficult problems.

Re: Vulnerabilities exploited in VPN products used worldwide

#42
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

AnnyConnect from Cisco is ok and I'm pretty sure wiedly audited.

Re: Vulnerabilities exploited in VPN products used worldwide

#43
post #10

>These vulnerabilities are well documented in open source. Seeing this awkward use of "open source" a lot lately. Its almost as if people think "readable on the internet for free" equals open source.

It does mean that. Free software and open source mean different things.

To me "source" implies code though. Not article.

Re: Vulnerabilities exploited in VPN products used worldwide

#44
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

I am sure you have valid crypto concerns, but outside of FUD, is there anything specific you have against, for example, GlobalProtect? Or any particular platform, for that matter?

Re: Vulnerabilities exploited in VPN products used worldwide

#45
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

Problem #1: they are closed source. Good luck verifying their security.

Problem #2: it is in the best interest of nation states to be able to break the VPNs and it's in the best interest of large vendors to quietly cooperate with the government.

Re: Vulnerabilities exploited in VPN products used worldwide

#46

Earlier quoted context omitted.

I could be wrong, but it’s superseded by FIPS140-3. Anyway, compliance doesn’t necessarily imply security.

Unless you are purposely trying to pedantic, one should know that FIPS140-3 just came out. You can't even search the Cryptographic Module Validation Program (CMVP) tool for FIPS140-3 standard level yet. FIPS140-2 for all practical purposes is the current standard to measure against. And if you really are negating FIPS140-X and what it means to large organizations and government entities... you should do some reading…

It is great that FIPS140-3 has finally become effective. The previous standard, was getting long in the tooth (FIPS140-2)...

Re: Vulnerabilities exploited in VPN products used worldwide

#47
post #23

Earlier quoted context omitted.

Yes, I know that is the problem, but that doesn't make it any less self-inflicted.

How is having to conform to an audit performed by an external party as required by regulatory agencies or legislation "self-inflicted"?

Regulations (PCI at least) don't prevent you from making your own unaffected COTS VPN server. You may need a FIPS compliant HSM for keying and revocation control but if your a college educated IT professional in an enterprise environment this should be well within your scope.

Of course we all know that's a lie. You could pick 10 random tech executives and none of them would know half the acronyms in this post. Why would they need to? That's why they were paying a vendor. Self inflicted indeed.

Re: Vulnerabilities exploited in VPN products used worldwide

#48

Earlier quoted context omitted.

Empathy for a self-inflicted problem? Why?

Because they undergo audits that have arbitrary rules, sometimes making it harder or impossible for them to use tools like wireguard.

This is largely false.

Re: Vulnerabilities exploited in VPN products used worldwide

#49
post #41
post #39

Earlier quoted context omitted.

> The gold standard, as ever, is Wireguard. Not disagreeing with you about the state of commercial VPN products, but regarding WG specifically. Something I don't see in the other replies just yet is that Wireguard doesn't yet have an ecosystem around it, but is designed for that in a good way. By which I mean, it follows the Unix philosophy of focusing on one specific task and doing it very well, and it has succeeded…

> It very explicitly doesn't want to deal with integrating with key management/HSMs/AD policies/whatever. If you look at the list of vulnerabilities, they're all precisely in those parts of the stack that Wireguard doesn't address. So what value is Wireguard providing, exactly? It's a beautiful protocol, but security isn't a beauty contest. It's easy to create a beautiful solution when you avoid dealing with the diff…

>If you look at the list of vulnerabilities

If you look at THIS list of vulnerabilities, sure. That's not an exhaustive list of every problem standard VPNs have had though, you understand that right?

>So what value is Wireguard providing, exactly?

Even ignoring vulnerabilities entirely, OpenVPN and the like are full of footguns and are very, very easy to fuck yourself with. You talk about the value of practicality and solutions, which is very true, and that's just the point. One of the core aspects of modern security practice is making it hard to fuck up, the few knobs and dials the better. For example, older protocols still have obsolete awful crypto options that you shouldn't use, but precisely because they exist as choices at all you have to worry about misconfiguration or classes of issues like downgrade attacks. There are plenty more, like if you remember back during Logjam, tons of SSH/VPN/HTTPS servers were using identical prime numbers for Diffie-Hellman key exchange.

WG aims to be a better foundation for the VPN component of things. Contrary to your assertion, the problem it deals with isn't trivial and does matter. Having something that is focused on that rather then part of a gigantic blob makes it easier to verify, and also makes whatever auth and other systems it's ultimately tied into easier to verify. Also just plain lower overhead.

I mean, I'm barely touching on things here but there are good reasons a lot of people are enthusiastic about its potential.

Re: Vulnerabilities exploited in VPN products used worldwide

#50
post #7

Commercial enterprise VPN products are an open sewer, and there aren't any, from any vendor, that I trust. I don't like OpenVPN or strongSwan, but you'd be better off with either of them than you would be with a commercial VPN appliance. The gold standard, as ever, is Wireguard.

Problem #1: they are closed source. Good luck verifying their security. Problem #2: it is in the best interest of nation states to be able to break the VPNs and it's in the best interest of large vendors to quietly cooperate with the government.

If you are worried about your secrets being revealed to a nation state, then chances are you shouldn’t be putting any of them over the public internet - VPN or not.
Post reply on HN