This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| man-in-the-middle attack | |
|---|---|
| Name | Man-in-the-Middle attack |
| Type | Cybersecurity attack |
man-in-the-middle attack
A man-in-the-middle attack is a form of interception in which an adversary covertly relays, alters, or injects communications between two parties. Notable for its relevance to Edward Snowden, Julian Assange, Chelsea Manning, Glenn Greenwald, and Laura Poitras in discussions about surveillance, the technique has been implicated in incidents involving Microsoft, Google, Yahoo!, Facebook, and Twitter. Historical and legal debates invoking Wikileaks, The New York Times, The Guardian (London), ProPublica, and Reuters have expanded public awareness alongside technical responses from IETF, NIST, ENISA, ICANN, CERT Coordination Center, and US-CERT.
A man-in-the-middle attack compromises the authenticity and confidentiality of communications between endpoints such as servers operated by Amazon (company), Cloudflare, Akamai Technologies, and clients running software from Mozilla Foundation, Google LLC, Apple Inc., Microsoft Corporation, and Linux Foundation. Early cryptographic concerns raised by Claude Shannon, Alan Turing, Whitfield Diffie, Martin Hellman, Ronald Rivest, Adi Shamir, and Leonard Adleman shaped protocols standardized by IETF working groups and codified in documents from NIST and rulings influenced by United States Court of Appeals for the Ninth Circuit, European Commission, and Court of Justice of the European Union. Political and commercial controversies featuring Eric Schmidt, Marissa Mayer, Vint Cerf, Tim Berners-Lee, Linus Torvalds, and Ken Thompson have intersected with technical defenses like Transport Layer Security, IPsec, and Secure Shell.
Attack techniques include passive eavesdropping, active session hijacking, and cryptographic downgrades used in exploits linked to incidents involving RSA Security, DigiNotar, Comodo, Symantec, Let's Encrypt, and Entrust. Variants such as SSL/TLS stripping, HTTP downgrade, ARP spoofing, and DNS spoofing have been studied by researchers at MIT, Stanford University, University of California, Berkeley, Carnegie Mellon University, ETH Zurich, and University of Cambridge. Examples of protocol-level weaknesses tied to OpenSSL, GnuTLS, Secure Sockets Layer, Transport Layer Security, and Quic (protocol) prompt responses from organizations including Apache Software Foundation, Nginx, Red Hat, Canonical (company), and Debian Project. Research literature from IEEE, ACM, USENIX, IACR, and Arxiv catalogs techniques such as man-in-the-browser attacks, malicious proxy insertion documented by teams at Kaspersky Lab, Symantec Research Labs, Trend Micro, McAfee, and ESET.
Common vectors exploit network infrastructure and end-user systems operated by AT&T, Verizon Communications, Deutsche Telekom, Vodafone, BT Group, China Telecom, China Mobile, Orange S.A., and Telstra. Targets include webmail services run by Gmail, Outlook.com, Yahoo! Mail, enterprise VPNs from Cisco Systems, Palo Alto Networks, Fortinet, and Juniper Networks, and financial systems used by institutions such as JPMorgan Chase, Goldman Sachs, Bank of America, Deutsche Bank, HSBC, Visa Inc., Mastercard Incorporated, and SWIFT. Mobile ecosystems managed by Apple Inc., Google LLC, Samsung Electronics, and carriers tied to BlackBerry Limited have been exploited via malicious apps flagged by Google Play, Apple App Store, F-Droid, and APKMirror. State-level operations attributed to actors like Equation Group, Fancy Bear, Cozy Bear, Lazarus Group, APT28, and APT29 have leveraged interception capabilities at chokepoints in networks including nodes operated by Level 3 Communications and CenturyLink.
Detection employs certificate pinning used by Dropbox, Slack Technologies, WhatsApp, Signal (software), Telegram (software), and Zoom Video Communications, alongside monitoring by Cloudflare, Akamai Technologies, Fastly, and Imperva. Prevention strategies include adoption of DNSSEC, DANE, HSTS, MFA, OAuth, and hardware-backed keys promoted by Yubico, Google Titan Security Key, and Feitian Technologies. Standards bodies such as IETF, W3C, IEEE Standards Association, NIST, and ETSI produce guidelines implemented by vendors like Cisco Systems, Juniper Networks, Arista Networks, Netgear, and Ubiquiti Networks. Legal instruments and procurement policies influenced by GDPR, HIPAA, Sarbanes-Oxley Act, PCI DSS, and directives from European Central Bank affect deployment choices at enterprises including Siemens, General Electric, Boeing, Lockheed Martin, and Raytheon Technologies.
Use of interception tools raises legal debates involving courts such as the Supreme Court of the United States, European Court of Human Rights, High Court of Justice of England and Wales, and regulatory agencies including Federal Communications Commission, National Security Agency, GCHQ, Federal Bureau of Investigation, Department of Justice (United States), European Data Protection Board, and Information Commissioner's Office. Ethical discourse referencing whistleblowers like Daniel Ellsberg and journalists at The Washington Post, The Guardian (London), The New York Times, and Der Spiegel informs policies at universities including Harvard University, Yale University, Oxford University, Cambridge University, and Stanford University. International law considerations engage bodies such as the United Nations, Council of Europe, NATO, World Trade Organization, and treaties like the Budapest Convention on Cybercrime.
Documented incidents include the DigiNotar breach that affected European and government customers, disputes involving Google Inc. and nation-states, the Stuxnet campaign analysis implicating supply-chain and interception concerns, and interception controversies tied to PRISM revelations. High-profile compromises reported by The New York Times, The Guardian (London), Wired (magazine), Bloomberg News, The Wall Street Journal, Politico, and Zerodium highlight attacks against targets such as Yahoo!, DigiCert, Comodo, RSA Security, Equifax, Target Corporation, and Sony Pictures Entertainment. Academic case studies from MITRE Corporation, RAND Corporation, Brookings Institution, Chatham House, and Carnegie Endowment for International Peace analyze campaigns attributed to Chinese PLA Unit 61398, Russian GRU, Iranian Revolutionary Guard Corps cyber units, and North Korean Reconnaissance General Bureau operations.