Original upload date: Wed, 30 Oct 2013 00:00:00 GMT
Archive date: Tue, 21 Dec 2021 19:38:19 GMT
Defeating PPTP VPNs and WPA2 Enterprise with MS-CHAPv2
Moxie Marlinspike
David Hulton
Marsh Ray
MS-CHAPv2 is an authentication and key negotiation protocol that, while old and battered, is still unfo
...
rtunately deployed quite widely. It underpins almost all PPTP VPN services, and is relied upon by many WPA2 Enterprise wireless deployments. We will release tools that definitively break the protocol, allowing anyone to affordably decrypt any PPTP VPN traffic or CHAPv2-based WPA2 handshake with a 100% success rate.
Moxie Marlinspike was the CTO and co-founder of Whisper Systems, is a member of the Institute For Disruptive Studies, runs a cloud-based password cracking service, is the original developer of sslstrip and sslsniff, manages the GoogleSharing targeted anonymity service, is the creator of the Convergence SSL authenticity system, and is the co-creator of the TACK certificate pinning protocol. His tools have been featured in many publications, including CNN, Forbes, The Wall Street Journal, and The New York Times. He is also the author of the sailing film "Hold Fast."