[saag] Re: On path Active Attackers, and Meddlers in the M iddle

Eric Rescorla <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CABcZeBNnkaUTEk5ahLfTVRSCSZn-y2hHORVYUrWqpERngfPzUg@mail.gmail.com>
On Sun, Jan 5, 2025 at 2:06 PM Michael Richardson <[email protected]>
wrote:

>
> Carsten Bormann <[email protected]> wrote:
>     > I remember doing a quick informal survey of the usage of related
> terms
>     > in research papers at some time in the late 2010s, and there was a
>     > clear consensus for MITM, and, incredibly, still for the
>     > “man-in-the-middle” expansion.
>
>     > For what RFC 4949 describes as MITM, we should stick with MITM, but
>     > maybe update with the better expansion.  (For other active on-path
>     > attacks, and specifically for describing the capability instead of
> the
>     > attack, we can use the more general term.)
>
> Yes, so MITM properly is Active On-Path Attacker.
> The idea is that MITM is a CNAME for Active On-Path Attacker.
>

While I agree with you that we should mostly just stop saying "MITM",
I don't think that this is strictly correct, for two reasons:

1. Classically, a MITM attacker impersonates Alice to Bob and Bob to Alice,
(hence the DH example), though I agree that 4949 is kind of vague on this
point. However, not all on-path impersonation attacks involve impersonation
in both directions; many involve impersonating  (for instance) a server to
the
client without connecting to the server at all.

2. There are active on-path attacks that don't involve any impersonation
at all. For example, consider the case of TLS 1.3 0-RTT replay, where
the attacker is just retransmitting valid data from the client to the
server.

With that said, I like the term "Active On-Path Attacker" for capabilities.
I just think we ought to use more precise names for the attacks themselves
(e.g., "server impersonation") if we do that, I doubt we will need to use
the
term MITM much if it all.

-Ekr

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.