Google's Secure WiFi Access Not So Secure?

from the whoops dept

There's been a lot of discussions going on around Google's release of a VPN solution. It seems like many of the stories have misinterpreted what it is. The press has turned this into a big thing about Google launching WiFi -- which it isn't (well, at least not yet). Google has been offering some free WiFi hotspots for a while already -- so that aspect wasn't new. The only thing that's new is this VPN offering. So, as a security offering, how secure is it? The folks over at Full Mesh/WiTopia took a look and sent us their analysis suggesting "not very" is the best answer. Full Mesh certainly is a biased party, considering that WiTopia offers a competing solution, but assuming the basic claims they're making are true (and it would be pretty easy for someone with the VPN client to check), then this solution really isn't particularly secure -- which is surprising, because it wouldn't have been hard to lock this down much tighter. The basic summary sent in by Feed Mesh is that the VPN uses PPTP instead of SSL. That's not entirely horrible if the PPTP offering is better locked down, but it doesn't appear to be (and SSL would have been a better overall solution no matter what). They're allowing both CHAP and MS-CHAP (v1) which have well known issues (as the Full Mesh guys point out, just check Google for lots of info on the problems with CHAP and MS-CHAP). Finally, they let pretty much everything pass through the VPN, rather than just TCP/IP. These are things that both WiTopia and HotSpotVPN do a much better job with. Obviously, the Google offering is quite beta, so it's possible they'll improve on this, but it's still worth noting that the "secure" part of the "secure" access might be a little misleading at this point.
Hide this

Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.

Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.

While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.

–The Techdirt Team


Reader Comments

Subscribe: RSS

View by: Time | Thread


  1. identicon
    Walter, 23 Sep 2005 @ 6:38am

    iPig alternative

    As a free alternative iPig was recommended to me. Its freeware (download at http://www.iopus.com/ipig)and includes the option to set up your *own* VPN server extremly easy.

    link to this | view in thread ]

  2. icon
    Mike (profile), 23 Sep 2005 @ 9:57am

    Re: iPig alternative

    As I said, what's nice about these other solutions is exactly the opposite: that you don't have to set up and maintain your own server. This is a solution for non-techies.

    link to this | view in thread ]


Follow Techdirt
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Discord

The latest chatter on the Techdirt Insider Discord channel...

Loading...
Recent Stories

This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it
Close

Email This

This feature is only available to registered users. Register or sign in to use it.