[saag] Re: On path Active Attackers, and Meddlers in the M iddle

Deb Cooley <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CAGgd1OeGZOXQR0bP=mP=YAA_Q5Z_6oLhkQHkU358QRxX10qSWw@mail.gmail.com>
Just a couple of observations...

On Sun, Jan 5, 2025 at 5:33 PM Eric Rescorla <[email protected]> wrote:

> On Sun, Jan 5, 2025 at 2:06 PM Michael Richardson <[email protected]>
> wrote:
>
>>
>> Carsten Bormann <[email protected]> wrote:
>>     > I remember doing a quick informal survey of the usage of related
>> terms
>>     > in research papers at some time in the late 2010s, and there was a
>>     > clear consensus for MITM, and, incredibly, still for the
>>     > “man-in-the-middle” expansion.
>>
>>     > For what RFC 4949 describes as MITM, we should stick with MITM, but
>>     > maybe update with the better expansion.  (For other active on-path
>>     > attacks, and specifically for describing the capability instead of
>> the
>>     > attack, we can use the more general term.)
>>
>> Yes, so MITM properly is Active On-Path Attacker.
>> The idea is that MITM is a CNAME for Active On-Path Attacker.
>>
>
> While I agree with you that we should mostly just stop saying "MITM",
> I don't think that this is strictly correct, for two reasons:
>
> 1. Classically, a MITM attacker impersonates Alice to Bob and Bob to Alice,
> (hence the DH example), though I agree that 4949 is kind of vague on this
> point. However, not all on-path impersonation attacks involve impersonation
> in both directions; many involve impersonating  (for instance) a server to
> the
> client without connecting to the server at all.
>

[DC]  I would have called this Masquerading.

>
> 2. There are active on-path attacks that don't involve any impersonation
> at all. For example, consider the case of TLS 1.3 0-RTT replay, where
> the attacker is just retransmitting valid data from the client to the
> server.
>

[DC] I would have said this was just a Replay attack.

>
> With that said, I like the term "Active On-Path Attacker" for capabilities.
> I just think we ought to use more precise names for the attacks themselves
> (e.g., "server impersonation") if we do that, I doubt we will need to use
> the
> term MITM much if it all.
>
> -Ekr
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.