Question

If the login password of an OpenVPN provider is not kept secure, is the encryption of the openvpn Internet connection then also potentially breached?

Était-ce utile?

La solution

No. The transferred data is encrypted by symmetrical encryption, which doesn't depend on the password. However I'm not sure if server certificate is checked during authentification. If yes, then you are secure and the only bad thing is that anyone with your password can connect to that VPN. If server certificate is not checked when using password auth, then this would mean the possibility of MITM (mad in the middle) attack during VPN creation.

Licencié sous: CC-BY-SA avec attribution
Non affilié à StackOverflow
scroll top