Earlier quoted context omitted.
Gender neutral and more accurate, it might not be how everyone else uses it but you got the meaning, no?
I would like person-in-the-middle attack, but unfortunately PITM would not be recognized as well as MITM. And in fact, it seems that we shouldn't really care so much that a person is in the middle, so we might be better off saying "in-the-middle attack" (ITM) anyway. Today, "man-in-the-middle" sounds familiar but I wonder if in a few decades, saying "man" instead of "person" or "human" will bear more meaning than tod…
Spying on HTTPS
51–60 of 121 posts
Re: Spying on HTTPS
#52Earlier quoted context omitted.
"Man in the middle" is not only an established concept it also is self-explanatory. Furthermore calling intercepters "monsters" is also a highly insensitive thing to do, if we're going to play the virtue signaling card. All this quixotism towards grammar and language is very stupid and pointless.
> "Man in the middle" is not only an established concept it also is self-explanatory. Being comprehensible and established does not make it "good" (sure, this is a relative notion). I get your point of view about calling the interceptors "monster", but we are calling the whole process an "attack", this could already be considered a judgment call with this reasoning. Monster are not necessarily evil though. A myth tha…
Re: Spying on HTTPS
#53Very interesting article, although if the message displayed to the end-user really was left at "You are using an unsupported environment variable: SSLKEYLOGFILE..." that would be truly awful UX with some potentially disastrous consequences.
Why? What "disastrous" consequences are you envisioning from a message like that? Note that the rest of the message (the part you omitted) explains in plain English what the part you quoted means to the average user.
Re: Spying on HTTPS
#54Re: Spying on HTTPS
#55There are many problems with using a MITM proxy, however. The primary problem is that it’s very very hard to ensure that it behaves exactly as the browser does and that it does not introduce security vulnerabilities. FUD. Why should we want "behaves exactly as the browser does", when browsers (in fact, mostly Google's) are in fact turning against their users? While browser vendors are wary of any sort of interception…
To avoid introducing vulnerabilities, the way lots of antivirus MITMs do, for example. Like it says in the rest of your quote.
> Especially Google's, because that's one of the ways you can still block ads and modify pages to have them displayed as the user(-agent) wants, while it continues to slowly remove abilities from browser extensions.
Blocking ads by MITM? Yikes. Extensions are very much a better tool for that. The idea that browser vendors are going to slowly cripple them so that they’re no longer an effective blocking tool is… wrong. But anyone who was on Chrome can use Firefox anyway.
> IMHO the whole "security" thing has turned into a power-grab for companies to enforce their control over users, which is the most disturbing part. We want security, but also control, which is not the "security" they want.
FUD.
> Edit: yay, instant downvotes! I hope you enjoy being herded by Google, because that's where the future is heading if we don't oppose.
Don’t.
Re: Spying on HTTPS
#56Earlier quoted context omitted.
Why? What "disastrous" consequences are you envisioning from a message like that? Note that the rest of the message (the part you omitted) explains in plain English what the part you quoted means to the average user.
Someone gets nefariously MITM'd and instead of giving the user an informative message, they're presented with something which means nothing to the lay-person.
Is there anything lost by _also_ including the technical information necessary to diagnose the problem?
Re: Spying on HTTPS
#57Earlier quoted context omitted.
> That's the ISP's problem. No. It is the user's problem, created by the ISP. > Mine doesn't do that. Otherwise put: "It isn't a problem for me, so why is anyone working on the issue instead of something that I do care about" > I trust it more than Google, at any rate. Fair enough. Though for many, choosing not to use Google properties is a lot easier than choosing not to use an ISP that they don't entirely trust.
How do I choose not to use Google properties, including their ad services, analytics, captcha, maps, etc? Is there at least a comprehensive list of their domains, if I choose to block it all (despite that rendering half the web unusable)?
Sorry, I wasn't specific enough. The poster I was replying to was commenting on their browser and I was expanding that to mean their browser and other applications.
Blocking all access to all Google services could be an uncompletable task, unless you start from blocking everything and using a white-list approach only which it unlikely to be practical (on top of creating the whitelist you'd have to monitor it and react when they or one of their related entities buy out or otherwise co-opt services you might have whitelisted in the past.
There are fairly comprehensive (though given the volunteer effort involved I'm sure they aren't 100%) lists available, but I don't know of one specific to Google so you would end up blocking other similar services unless you add your own filter to the filter list before using it.
> if I choose to block it all (despite that rendering half the web unusable)?
I doubt it would make nearly that much unusable. The only one of their services that blocking would stop you using other things is recapcha and I dare say anything "hidden" behind that is also available elsewhere. Blocking analytics isn't going to affect you as a user, maps blocks itself a lot ATM anyway ("this site is configured incorrectly" messages where a map should be because the rules for inlining maps have changed (or their enforcement has) and people haven't updated their pages to reflect the policy change at Google), etc.
Re: Spying on HTTPS
#58Re: Spying on HTTPS
#59Listener in the middle is most accurate and Politically Correct.
Re: Spying on HTTPS
#60Earlier quoted context omitted.
> "Man in the middle" is not only an established concept it also is self-explanatory. Being comprehensible and established does not make it "good" (sure, this is a relative notion). I get your point of view about calling the interceptors "monster", but we are calling the whole process an "attack", this could already be considered a judgment call with this reasoning. Monster are not necessarily evil though. A myth tha…
Your attempt to force your personal blend of newspeak onto the world has no place in tech nor in this discussion. Please leave your gender politics activism out of an interesting technical discussion that affects us all. Besides being pointless and stupid, it only adds noise to the debate.
GP never mentions gender in their post, but in terms of politics, it seems to me that this entire thread is a political conversation. It's certainly not technical -- a technical person would not care about whether someone used the term "monster" or "man", since:
a) it changes literally nothing about the technical details of the attack.
b) everyone understands what both terms are referring to.
The only reason why it makes sense for anybody at all to advocate for switching to "monster" or to advocate against switching to "monster" is because they're interested in the politics behind that switch.
From a technical point of view, if using the word "monster" makes some people happy, then why is it a problem for them to do so? My computer isn't going to stop working because of it ;)
If it makes someone feel more accepted, and it isn't causing any confusion, then I'm all for it.