99% of customers, it won't matter as they're just watching Hulu or Dr Who. If somebody is decrypting your traffic you got bigger problems.
-
-
-
But for residential customers (and PIX customers) we should probably drop the Private from VPN.
End of conversation
New conversation -
-
-
These are all bullshit.... none of these are valid. Where did you find this?
-
they are valid. Here's an example, Private Internet Access from their website.pic.twitter.com/IvXuOFdMDt
End of conversation
New conversation -
-
-
It only applies to the legacy protocols. Note that PIA tells people not to use L2TP: https://www.privateinternetaccess.com/pages/client-support/android-l2tp ….
-
Why should they be shamed for this when they're telling people that the legacy protocol isn't useful for encryption?
-
They explain why they offer legacy protocols, when they can be useful and that they don't offer useful encryption.
-
They state use cases for weak protocols there: "masking one's IP address, censorship circumvention, and geolocation"
-
those activities are illegal in lots of countries. Without encryption, those users are more at risk.
@GossiTheDog@daveaitel -
they aren't saying L2TP is not secure, only that it lacks encryption. An average Joe won't understand
@GossiTheDog@daveaitel -
besides L2TP/IPsec is known as less secure than OpenVPN, not as completely insecure.
@GossiTheDog@daveaitel -
they make it completely insecure, when they could have set it up with per user shared secret instead
@GossiTheDog@daveaitel
End of conversation
New conversation -
-
-
I bet their password setting rules for customers are really obnoxious though
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
@micahflee afaik “your favourite” is only true if using L2PT protocol. Native app, IpSec and OpenVPN don’t have shared keys.Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
@daveaitel username and password still required. people who need encryption won't be using L2TP anyway. -
how bad is l2tp on those services? That's what people use on Chromebooks...
-
what do you mean by bad? Common on ios devices too because no built in openvpn client.
-
decryptable wou ld be bad
-
L2TP risk MitM attack. Chromebook had NO VPN support in Nov-Dec 2015 even though it looked connected:-S
End of conversation
New conversation -
-
-
@RHamptonCISSP Oh, I like 'gogoVPN'. Who knew Inspector Gadget did infosec?Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.