4 ms·
To your aside, MITM seems more likely to happen to the end-user, but it is possible to happen at the Cloudflare-->Website side. We already know that the NSA lo
by mr_potato_face 10y ago
To your aside, MITM seems more likely to happen to the end-user, but it is possible to happen at the Cloudflare-->Website side. We already know that the NSA logs all traffic going over certain backbone routers[1], and that some ISPs are modifying non-HTTPS connections[2]. So if your traffic bounces through certain "bad" networks between Cloudflare and your site, who knows what happens.
Relatedly, Tor recommends all users use HTTPS[3], as otherwise the connection from the exit node to the target site is vulnerable to MITM. Given that there are malicious exit nodes[4], seems like a good idea. But, as the article brings to light, that still doesn't make any guarantees of safety.
[1] https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A
[2] e.g. http://www.infoworld.com/article/2925839/net-neutrality/code-injection-new-low-isps.html http://www.infoworld.com/article/2925839/net-neutrality/code...
[3] https://www.torproject.org/docs/faq.html.en#CanExitNodesEavesdrop https://www.torproject.org/docs/faq.html.en#CanExitNodesEave...
[4] e.g. http://www.cs.kau.se/philwint/spoiled_onions/ http://www.cs.kau.se/philwint/spoiled_onions/ but plenty of other sources
- true_religion 10y agoWhen it comes to security, the question of "whom is my attacker?" really determines how much invenstment you make in securing your service. Many online providers don't care if the NSA is slurping up their data. For example, do you think that Macy's online is going to stick out their necks to protect clothing transactions from the government? Nope. Personally, I've seen end-users more worried about MtM close to their endpoint, such as their employers or schools scanning their traffic. They're not trying to evade governments here.