LWN.net Logo

Man in the middle

Man in the middle

Posted Jan 5, 2008 16:29 UTC (Sat) by rfunk (subscriber, #4054)
In reply to: Man in the middle by copsewood
Parent article: The future of unencrypted web traffic

I'm not qualified to say much about the legal aspects in any country, though the 
combination of big companies and technology often makes for a lack of reason in the 
judicial world.

But your DNSSEC solution does nothing to protect against the ISP doing a MIM attack.  
The scenario I was talking about doesn't depend on DNS forgery at all.  That's the 
advantage the ISP has that other attackers don't have.


(Log in to post comments)

Man in the middle

Posted Jan 7, 2008 1:19 UTC (Mon) by copsewood (subscriber, #199) [Link]

If DNSSEC secures the DNS and DNS domain registration includes provision of certificates this
makes having certificates as routine as registering a domain. 

Man in the middle

Posted Jan 7, 2008 2:10 UTC (Mon) by rfunk (subscriber, #4054) [Link]

Sorry, you're apparently still not understanding my point.  Or I'm not getting yours.  Or 
both.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds