[saag] Re: On path Active Attackers, and Meddlers in the M iddle

Phillip Hallam-Baker <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CAMm+LwhO=U7x+1rDxm4zggEREfnZkSUDx8XgZqoVUbCgaiaROA@mail.gmail.com>
On Sun, Jan 5, 2025 at 8:17 PM Alan DeKok <[email protected]> wrote:

> On Jan 5, 2025, at 8:12 PM, [email protected] wrote:
> > I also agree that we should stop -- I've never liked the term because it
> is too vague, and indeed, people use it for both passive and active attacks.
> >
> > The classic one is a double-impersonation, proxy attack. The attacker
> is, as you say, impersonating Alice to Bob and Bob to Alice, while
> modifying the traffic as needed. It's really hard to describe that pithily.
>
>   The obvious solution is to describe that as the "ABBA" attack.  :)
>

Sold

Works even better with the ABBA logo.

I agree with the point EKR made about MITM being classically an
impersonation attack and that is one reason I have always disliked it. The
full bidirectional MITM attack is pretty much impossible to pull off
without detection long term. Mallet needs to insert himself into every
communication path to prevent Alice and Bob working out they have been
compromised.

Simpler AOPA like replay attacks or downgrade attacks are much easier to
pull off.

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.