[saag] Re: On path Active Attackers, and Meddlers in the M iddle
Phillip Hallam-Baker <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CAMm+LwijiCJrp8E4inCqCG5gdT+eQnAAAo8oBebzBnzAY1rq3w@mail.gmail.com> |
I have always thought changing the terminology for 'man in the middle' to be tilting at wind turbines because it is always a *THING* in the middle, so getting caught up about the arbitrary gender we apply to the inanimate thing seemed to be missing the point that anthropomorphising things is bad generally. No, Alice doesn't do RSA in her head, nor does Bob.... This terminology gives us a principled means of rejecting the whole problem by going for a BETTER, clearer scheme: * Active On-Path Attacker * Passive On-Path Attacker Being on-path definitely gives the attacker an advantage. But being able to change the messages is a heap more powerful than merely observing them. MITM fails to distinguish between the two cases. So rather than trying to get people to call MITM something else, just cross it out and ask 'is this attacker active or passive?' and MITM goes away. On Sun, Dec 22, 2024 at 9:49 PM Michael Richardson <[email protected]> wrote: > Some hallway conversations at 121 in Dublin encouraged me to revise and > bring > this document forward again. While I was previously seeking comments > about a > number of different options, this version just makes a clear choice. > > In particular, it changes MITM to expand to Meddler In The Middle, > but prefers Active On-Path Attacker as the clearer term. > > Github: https://github.com/mcr/saag-onpath-attacker > (I'll put that into the I-D) > > > [email protected] wrote: > > A new version of Internet-Draft > draft-richardson-saag-onpath-attacker-04.txt > > has been successfully submitted by Michael Richardson and posted to > the > > IETF repository. > > > Name: draft-richardson-saag-onpath-attacker > > Revision: 04 > > Title: A taxonomy of eavesdropping attacks > > Date: 2024-12-13 > > Group: Individual Submission > > Pages: 8 > > URL: > https://www.ietf.org/archive/id/draft-richardson-saag-onpath-attacker-04.txt > > Status: > https://datatracker.ietf.org/doc/draft-richardson-saag-onpath-attacker/ > > HTML: > https://www.ietf.org/archive/id/draft-richardson-saag-onpath-attacker-04.html > > HTMLized: > https://datatracker.ietf.org/doc/html/draft-richardson-saag-onpath-attacker > > Diff: > https://author-tools.ietf.org/iddiff?url2=draft-richardson-saag-onpath-attacker-04 > > > Abstract: > > > The terms on-path attacker and MITM Attack have been used in a > > variety of ways, sometimes interchangeably, and sometimes meaning > > different things. > > > Increasingly people have become uncomfortable with the gendered term > > "Man" in the middle and have sought alternatives. > > > This document offers an update on terminology for network attacks, > > retaining some acronyms terms while redefining the expansion, and > > clarifying the different kinds of attacks. Consistent terminology is > > important in describing what kinds of attacks a particular protocol > > defends against, and which kinds the protocol does not. > > > > > The IETF Secretariat > > > _______________________________________________ > saag mailing list -- [email protected] > To unsubscribe send an email to [email protected] > _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]