4 ms·
I don't see any reason why it would be much harder to hit the middle hops for a MiTM attack. It certainly wouldn't be worth setting up a MiTM attack between my
by kgo 16y ago
I don't see any reason why it would be much harder to hit the middle hops for a MiTM attack.
It certainly wouldn't be worth setting up a MiTM attack between my house and the first Comcast router my cable hits. That approach doesn't scale. Sure maybe if I'm Warren Buffet (or some mobster if we're talking about the government) it might make sense. And if they did do that, then NO source I connect to is a trusted channel, as they could MiTM any and all connections.
The scheme wouldn't (always) protect you from an attacker setup somewhere in between you and your destination, like the NSA servers at AT&T, or the Firewall of China. Your trusted source could hit the same bad path.
And by your own acknowledgment, the scheme doesn't protect you from a hacker breaking into a bank's data center. If a hacker is smart, and only grabs say every 100,000th credit card, how long will it take to isolate the location of the exploit?
So the scheme doesn't really protect against anything with any level of confidence.
- modeless 16y agoYou get the initial trusted source cert through a secure channel in exactly the same way you get CA certs today, so this scheme is just as secure as SSL against an attacker who controls your entire connection. Sure, the scheme is only as good as your trusted source. But the trusted source could be very good. It could have multiple servers in different ISPs and even different countries verifying certs for you, and could use other methods of verification as well. The bank can easily check if their connections are getting MITM attacked. The hacker has to modify the certs seen by anyone who contacts the bank, even if he doesn't MITM every connection, and that would be easy for the bank to detect.
- kalmi10 16y agoYou are getting out of scope. A hacker breaking into a bank's data center is not at all releated to the discussion at hand.