Pergunta

If the login password of an OpenVPN provider is not kept secure, is the encryption of the openvpn Internet connection then also potentially breached?

Foi útil?

Solução

No. The transferred data is encrypted by symmetrical encryption, which doesn't depend on the password. However I'm not sure if server certificate is checked during authentification. If yes, then you are secure and the only bad thing is that anyone with your password can connect to that VPN. If server certificate is not checked when using password auth, then this would mean the possibility of MITM (mad in the middle) attack during VPN creation.

Licenciado em: CC-BY-SA com atribuição
Não afiliado a StackOverflow
scroll top