4 ms·
this cisco anyconnect system? https://www.cvedetails.com/vulnerability-list/vendor_id-16/product_id-20904/Cisco-Anyconnect-Secure-Mobility-Client.html https://w
by Hello71 7y ago
this cisco anyconnect system? https://www.cvedetails.com/vulnerability-list/vendor_id-16/product_id-20904/Cisco-Anyconnect-Secure-Mobility-Client.html https://www.cvedetails.com/vulnerability-list/vendor_id-16/p...
doesn't seem very secure to me.
- sbradford26 7y agoCVEs mean that a company can take action to mitigate a vulnerability. Wireguard is not mature enough to have something like that. A known vulnerability is bad, but not nearly as bad as an unknown vulnerability. This is not a knock on Wireguard, I use wireguard and love it. It just has several hoops to jump through before it is ready for widespread adoption. Like NIST approving it to be used instead of IPsec or OpenVPN.
- tptacek 7y agoI don't know what this means but can't think of an interpretation that isn't false. WireGuard will certainly do a better job mitigating vulnerabilities than Cisco will, and WireGuard's code will for obvious reasons get more attention than Cisco's horrible VPN code. It's true that Fortune 500 companies aren't going to deploy WireGuard. They're constitutionally incapable of deploying security gear that isn't awful, which is why a huge fraction of all VPN deployments through the F500 were backdoored in the 2000s. NIST is never going to approve WireGuard; it's not even a discussion worth having, nor is it NIST's place to certify which VPNs are or aren't safe to use, nor does NIST have the staff to do anything like that. That's no reason for startup engineers to make the same mistake. Startups definitely do deploy WireGuard.
- Hikikomori 7y agoWill take another look at wg once keys can be stored in non-exportable way on devices, or temporary keys generated per session after passing some auth mechanism. Sounds like a fun personal project.
- Hello71 7y agomy point is that it would appear that "Anyconnect Secure Mobility Client" has a shitton of vulnerabilities. sure, wireguard may have some vulnerabilities, but you don't need a formal audit to tell the difference between "this might have some issues" and "holy fuck this is a fucking dumpster fire". you need an audit to tell if "this might have some issues" is "this has some issues" or "this is actually pretty good". in particular, "Anyconnect Secure Mobility Client" appears to have a significant number of local privilege escalation exploits, some several dozen since 2011. that doesn't necessarily mean that the protocol is shit, but it probably does. it probably means that no serious security professionals have examined it, and the vulnerabilities that have been found are just the easiest ones that can be found with a scanner. but even ignoring all of that, wireguard has significantly better security guarantees. https://www.wireguard.com/formal-verification/ https://www.wireguard.com/formal-verification/ claims that "WireGuard has undergone all sorts of formal verification, covering aspects of the cryptography, protocol, and implementation." with references to several formal proofs of the protocol. furthermore, wireguard has actually received a CVE: CVE-2019-14899, which was posted here only a few weeks ago. it's not wireguard-specific though, it's a general problem with VPN setup on general-purpose operating systems.
- jlgaddis 7y agoI'm sure you know this but, for the benefit of others... With this exception, WireGuard does not CVEs because it is (for now) still considered pre-release software and not recommended for production use.
- kseifried 7y agoCVE does cover "pre-release" software, part of the argument being you can't simply label something as "beta" and escape CVE coverage especially if millions of people are using it (Google's Chrome web browser was a good example of this). For example: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=prereleases https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=prereleases
- loeg 7y ago
- kseifried 7y agoSorry but... no. You are wrong. Completely wrong. CVE is just an identifier for a security vulnerability. "Common Vulnerabilities and Exposures" CVE generally covers released software, hardware and (in the process or being added officially) services. It also covers beta software (https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=beta https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=beta). The reason Wireguard doesn't have CVEs is nobody has bothered to request them. For more details on CVE there's a bunch of episodes covering it: https://www.opensourcesecuritypodcast.com/search?q=cve https://www.opensourcesecuritypodcast.com/search?q=cve