[89389] in North American Network Operators' Group
Re: Security problem in PPPoE connection
daemon@ATHENA.MIT.EDU (Steven M. Bellovin)
Sun Mar 12 14:51:14 2006
Date: Sun, 12 Mar 2006 14:50:45 -0500
From: "Steven M. Bellovin" <smb@cs.columbia.edu>
To: Florian Weimer <fw@deneb.enyo.de>
Cc: joe_hznm@yahoo.com.sg, nanog@merit.edu
In-Reply-To: <877j6zihmd.fsf@mid.deneb.enyo.de>
Errors-To: owner-nanog@merit.edu
On Sun, 12 Mar 2006 20:32:26 +0100
Florian Weimer <fw@deneb.enyo.de> wrote:
>
> * Joe Shen:
>
> > What's your method to deal with such problem? Will
> > CHAP in PPPoE help?
>
> AFAIK, CHAP does not authenticate the terminal server, either, so it
> won't stop all attacks.
>
CHAP can be bidirectional.
--Steven M. Bellovin, http://www.cs.columbia.edu/~smb