>
> While I agree with you that we should mostly just stop saying "MITM",
> I don't think that this is strictly correct, for two reasons:
>
> 1. Classically, a MITM attacker impersonates Alice to Bob and Bob to Alice,
> (hence the DH example), though I agree that 4949 is kind of vague on this
> point. However, not all on-path impersonation attacks involve impersonation
> in both directions; many involve impersonating (for instance) a server to the
> client without connecting to the server at all.
>
> 2. There are active on-path attacks that don't involve any impersonation
> at all. For example, consider the case of TLS 1.3 0-RTT replay, where
> the attacker is just retransmitting valid data from the client to the server.
>
> With that said, I like the term "Active On-Path Attacker" for capabilities.
> I just think we ought to use more precise names for the attacks themselves
> (e.g., "server impersonation") if we do that, I doubt we will need to use the
> term MITM much if it all.
I also agree that we should stop -- I've never liked the term because it is too vague, and indeed, people use it for both passive and active attacks.
The classic one is a double-impersonation, proxy attack. The attacker is, as you say, impersonating Alice to Bob and Bob to Alice, while modifying the traffic as needed. It's really hard to describe that pithily.
While I'm not sure I like "active on-path attacker" the only thing I have that is better would be to say "proxy" instead of "on-path." To me, "proxy" is better and at the same time, I totally understand an objection to it. Alternatively, "in-path" is also good; I prefer it. (Also, AIP has fewer collisions than AOP in our world, for the inevitable initials.)
In any event, I like that it mentions the three elements: active, in/on the path, and an attack. To my mind, a passive attack is pretty much just eavesdropping; if it's not on-path (or proxying the connection) then it's something else entirely; and if it's not an attack then it's also something else.
For example, there are ad-blockers and malware blockers that are active, on-path *defenses*, and even if they might have peculiar placements in the path. And of course, the proxy firewalls of yore are also a thing.
So yeah -- I am totally on board with this. If we can't come up with a pithy alternative to In-Path (or On-Path), I'd say go with it. It's marvelous to put the other term out to pasture.
Jon
_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.