5 ms·
What is the exact problem here? Who would be doing a MITM attack on someone and how? It doesn't seem to matter to me if my ISP is MITM, because someone inside
by nanoscopic 9y ago
What is the exact problem here? Who would be doing a MITM attack on someone and how?
It doesn't seem to matter to me if my ISP is MITM, because someone inside the ISP would need to cause that. If my ISP is forced to MITM by government etc, I am in trouble anyway.
I could see that it could be done by using a bad/spoofed wireless or a public network connection somewhere. That makes sense. I don't do that though; I only use my own secure home network in a wired fashion when accessing my bank account.
If people are able to spoof my network connection, they could interfere with non-https software updates on my machine, which would let them replace the root certs of my browser potentially, in which case https wouldn't matter. Is the assumption here that all software updates on my machine are happening via https and only the bank website is a danger?
My point here is that while I agree what the bank is doing is bad practice, I don't see how it would affect me in any way.
- moreira 9y agoThere are plenty of people accessing their banks on public / insecure networks; it’s folly to assume that MITM attacks just can’t happen. You yourself might not be at risk, but you’re not the only person out there. The assumption is that yes, all of your machine’s updates are served over HTTPS. If they weren’t, then of course you’re right - it’d be possible to hijack your machine by serving malicious binaries. That’d be one hell of a security hole.
- nanoscopic 9y agoI stated specifically that I agree it is bad in situations where you could be MITM. I also agree many people do that. My question here is only how it could effect me or people who follow the practice I follow.
- zAy0LfpBZLC8mAC 9y agoYour assumption that there is such a thing as a "secure network" is foolish. ISPs inject vulnerable javascript into pages, ISPs have vulnerable routers, ISPs have bad passwords on their devices, ISPs have criminals on staff, ISPs run traffic through unencrypted microwave links that anyone close to the beam can listen in to, ISPs have devices running in remote locations, ... and your traffic is going to run through who knows how many ISPs, possibly even through other countries, ... in short, it simply doesn't make sense to build anything on the assumption that the network is secure.
- jackweirdy 9y agoDon't think about _you_, think about the layman. Who probably has a WiFi router from 5 years ago with outdated firmware that their ISP can't be bothered patching.
- nanoscopic 9y agoThe layman clicks on links that say "you have a virus; download this tool to remove it". They then click 'Yes I authorize' to verify that the downloaded program should be allowed to corrupt their machine. I fail to see how the bank changing their website to HTTPS is going to save the average Joe. There are so many websites and things that operate over HTTP that make our machines vulnerable, that I think it is foolishness to use a link that could be MITM to begin with. That is, it seems to me, that if you simply avoid ever using wireless there is no danger of MITM. I could see that XSS could be done on some sites with ads, and that would be worsened by lack of HTTP. Is it as simple as "Don't use wifi. Use adblock. HTTP/HTTPS then no longer matters." ?
- biggio 9y agoWith the layman example, you are describing man in the browser attack. It doesn't matter if you use wireless or not.
- yjftsjthsd-h 9y agoThis sounds a lot like "we can't protect average joes from themselves, so let's not bother adding protections"? Sure there are always other attack vectors, but that doesn't excuse ignoring the ones that are easy to fix.
- deleted 9y ago[deleted]