We are aware that the new Web-based access is growing in popularity. But, although the providers sport the fact that they use triple-DES or 128-bit encryption, what is you opinion of the true Network Security Issues.
If Triple-DES or 128-bit encryption was so secure, why has ARINC of Annapolis recently developed a high-speed higher encryption standard?
Requires Free Membership to View
The good news about SSL-based VPN is that one doesn't need special purpose client software and can get to the network from virtually any device. Of course, this is bad news on the security front. I need to pay special attention to user authentication since the device is not locked down and I need to beware of new attacks such as retrieving data from a web cache or programs that capture key strokes. I also, need to make sure that an employee retrieving corporate data from an airport kiosk doesn't walk away with the session active using techniques like timeouts. One other caveat about SSL is that it doesn't support ALL IP applications; IPSec does.
Regarding encryption standards, we're always looking for stronger methods and they will continue to change as processors become more powerful. The availability of new encryption methods doesn't necessarily mean that the older ones are no good. It's just the nature of the game. Although most vendors implement 168-bit 3DES, IPSec has no specific encryption standard and can accommodate new ones as they become available.
This was first published in March 2003
Network Management Strategies for the CIO

Join the conversationComment
Share
Comments
Results
Contribute to the conversation