Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The characters are largely irrelevant. If an attacker is an opportunist and (for example) just wants to run any traffic passing his house through something quick and dirty then it's going to boil down to whether or not his wordlist contains your password.

If the adversary is reasonably well organised they might use something like AWS to offload the cracking, in which case they may well expend more resources on a bigger and more wordlist. Cloud-based cracking is really interesting, especially when GPU support comes into play as most of the traditional models of attack complexity fall like a house of cards once your average joe can get the kind of supercomputing power only previously available to three letter agencies.

In all honesty I would just avoid PPTP and stick to L2TP or an SSL-based VPN. In TFA the author chose PPTP because he wanted to stick what was available on his router and compatible with his devices. I understand their decision, although personally I don't see this as being any more secure than running a password protected browser-based file manager and port forwarding it to the world. You'd still have to obtain a password, but it's not hard.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: