Earlier quoted context omitted.
Since I see people on HN get this wrong more than 90% of the time I want to demystify the term Man in the Middle . https://en.wikipedia.org/wiki/Man-in-the-middle_attack The Wikipedia article's description is correct. MITM is a cryptographic attack where an impostor is performing certificate interception and so relays encrypted traffic. MITM is not merely listening to just any traffic. If the violation occurred over…
I do not understand the distinction you are trying to make. MITM has nothing in particular to do with certificates, and describes any attack in which Alice Bob, cryptographically or otherwise, and Mallory intercepts and controls communications via Alice Mallory Bob. Essentially every malicious proxy attack is a MITM. The bug here seems to be that the Steam local app relies on an HTTP 80/tcp connection for first conta…
I agree that it is a valid finding, but its reported in wildly different terms than what you just described. That is just cause to triage a reported incident as low priority.