[saag] Re: On path Active Attackers, and Meddlers in the M iddle

Phillip Hallam-Baker <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CAMm+LwijiCJrp8E4inCqCG5gdT+eQnAAAo8oBebzBnzAY1rq3w@mail.gmail.com>
I have always thought changing the terminology for 'man in the middle' to
be tilting at wind turbines because it is always a *THING* in the middle,
so getting caught up about the arbitrary gender we apply to the
inanimate thing seemed to be missing the point that anthropomorphising
things is bad generally. No, Alice doesn't do RSA in her head, nor does
Bob....

This terminology gives us a principled means of rejecting the whole problem
by going for a BETTER, clearer scheme:

* Active On-Path Attacker
* Passive On-Path Attacker

Being on-path definitely gives the attacker an advantage. But being able to
change the messages is a heap more powerful than merely observing them.
MITM fails to distinguish between the two cases.

So rather than trying to get people to call MITM something else, just cross
it out and ask 'is this attacker active or passive?' and MITM goes away.


On Sun, Dec 22, 2024 at 9:49 PM Michael Richardson <[email protected]> wrote:

> Some hallway conversations at 121 in Dublin encouraged me to revise and
> bring
> this document forward again.  While I was previously seeking comments
> about a
> number of different options, this version just makes a clear choice.
>
> In particular, it changes MITM to expand to Meddler In The Middle,
> but prefers Active On-Path Attacker as the clearer term.
>
> Github:  https://github.com/mcr/saag-onpath-attacker
> (I'll put that into the I-D)
>
>
> [email protected] wrote:
>     > A new version of Internet-Draft
> draft-richardson-saag-onpath-attacker-04.txt
>     > has been successfully submitted by Michael Richardson and posted to
> the
>     > IETF repository.
>
>     > Name:     draft-richardson-saag-onpath-attacker
>     > Revision: 04
>     > Title:    A taxonomy of eavesdropping attacks
>     > Date:     2024-12-13
>     > Group:    Individual Submission
>     > Pages:    8
>     > URL:
> https://www.ietf.org/archive/id/draft-richardson-saag-onpath-attacker-04.txt
>     > Status:
> https://datatracker.ietf.org/doc/draft-richardson-saag-onpath-attacker/
>     > HTML:
> https://www.ietf.org/archive/id/draft-richardson-saag-onpath-attacker-04.html
>     > HTMLized:
> https://datatracker.ietf.org/doc/html/draft-richardson-saag-onpath-attacker
>     > Diff:
> https://author-tools.ietf.org/iddiff?url2=draft-richardson-saag-onpath-attacker-04
>
>     > Abstract:
>
>     > The terms on-path attacker and MITM Attack have been used in a
>     > variety of ways, sometimes interchangeably, and sometimes meaning
>     > different things.
>
>     > Increasingly people have become uncomfortable with the gendered term
>     > "Man" in the middle and have sought alternatives.
>
>     > This document offers an update on terminology for network attacks,
>     > retaining some acronyms terms while redefining the expansion, and
>     > clarifying the different kinds of attacks.  Consistent terminology is
>     > important in describing what kinds of attacks a particular protocol
>     > defends against, and which kinds the protocol does not.
>
>
>
>     > The IETF Secretariat
>
>
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.