Everything2
Near Matches
Ignore Exact
Full Text
Everything2

Man In The Middle

created by Rolling Cutter

(idea) by ink- (4.8 y) (print)   ?   (I like it!) Sat Dec 15 2001 at 22:31:31

Man in the middle can also refer to a type of cryptographic attack, not just an ABBA song. The original model used to analyze cryptosystems assumed that an enemy could listen to the ciphertext traffic, and perhaps even interfere with it, but not that messages could be intercepted and completely hidden. Unfortunately, this is in fact the situation in a store-and-forward computer network like the internet. Routing is not secure on the internet, and it is at least conceivable that messages between two people could be routed through connections on the other side of the world. This leads to possibilities that encrypted information could be routed to flow through a particular computer for special processing.

These attacks are mainly applicable to public key systems such as RSA, and focuses on the idea that many people will send their public keys on the network. The bad part of this is a lack of key authentication, because the enemy can send a key just as easily, and pretend to be the other end. Then, if you use that key, then you have secure communication with the enemy, instead of your intended destination. The enemy can receive a message, decipher it, read it, re-encipher it in the correct public key, and send it along. In this way, neither end sees anything wrong, yet your enemy is reading the messages.

Perhaps the worst part of this is that a successful attack does not involve any attack on the actual cipher itself. No need to factor the product of large primes, no ecletic mathematics. This means that all proofs or confidence in the security of particular ciphering mechanisms is totally irrelevant to the security of a system which is vulnerable to man in the middle attacks.

The way to avoid man in the middle attacks is to certify public keys, but this is inconvenient and time-consuming. Unless the cipher requires keys to be certified, this is rarely done. The worst part of this is that a successful attack consumes few resources, and does not need any particular vulnerability in the cipher itself.

It is interesting to note that, regardless of how inconvenient it may be to share keys for a secret-key cipher, this is an inherent authentication which prevents man in the middle attacks.


printable version
chaos

Dark One's Dictionary RSA Illegal prime number Public Key Infrastructure
Opportunistic Encryption The Matrix Reloaded and nmap ABBA Informational Constraints
exploit computer security routing Avalanche Effect
Completeness Effect MITM DES Double lock encryption
Don't kill your invisible husband to see what he looks like or you'll sob your heart out. But don't worry about the millions of invisible men coming to attack your village because they won't kill you if you don't know how to fight them. Authentication packet sniffing certify
dsniff Commutative lock solution Monkey in the middle An open letter to Michael Moore
Y'know, if you log in, you can write something here, or contact authors directly on the site. Create a New User if you don't already have an account.
  Epicenter
Login
Password

password reminder
register

Everything2 Help

Cool Staff Picks
Look at this mess the Death Borg made!
It's the End of the Node as We Know It
He flew an A-10 Thunderbolt
Guessing the worth of something
A Blather of Paradoxes
Bodhisattvacaryavatara
Emmett Till
OLA Scary Story Contest 2000
Genesis
Squished tubers and dead bird: An orphans' Thanksgiving
Pascal's Triangle
Nessun dorma
I caught the football
The Rise of Christianity
New Writeups
Mythi
July 24, 2008(personal)
locke baron
The fall of Earth(fiction)
BookReader
Fear the Cold(dream)
Pavlovna
Kathleen MacInnes(person)
stainedglass
1(fiction)
kalen
Three "T"s(idea)
octillion369
Undead(idea)
archiewood
Ico(fiction)
Heisenberg
Why I love Everything2(log)
octillion369
Death Knight(person)
XWiz
Are you hoping for a miracle?(review)
santo
The Host(review)
LostPsion
"Shut the Fuck Up" Theaters(idea)
beatrice
You've been slowly taking me over for nearly a year, do you know that?(idea)
Berek
YouTube(thing)
This page courtesy of The Everything Development Company