Linux.com

Mostly agree...

Posted by: Anonymous Coward on September 28, 2005 09:22 PM
But, you must remember that we do not live in a perfect world and therefore perfect security may not be possible. Along with strong security we must also factor in ease of use and evaluate the cost of the risk.

The fact is that many businesses are willing to forgo the greater security of a client server VPN in favor of ease of use because the greater security hampers the user. Put another way, the clientless VPN enables greater efficientcy and productivity due to its ease of use.

Client based VPN's require the company to give the user a laptop and the user has to lug it around, both of which are often undesirable.

A clientless SSL VPN though not the most secure, is usually "secure enough" while offering sufficient convenience to increase user productivity. Protecting trade secrets for most companies is not as critical as protecting research data at Los Alamos. Additionally, with USB dongles that store encryption keys or with security tolkens, the risk to clientless VPN's goes down tremendously.

No, it's not perfectly secure but, we don't live in a perfect world and since there are no real guarantees in life, why would anyone expect it from a VPN?

#

Return to SSL VPNs and OpenVPN: A lot of lies and a shred of truth