Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Applied Cryptography mentions the 'Interlock Protocol' [1]. Why is something like this not used in today's protocols to try and detect MITM attacks?

1 - http://en.wikipedia.org/wiki/Interlock_protocol



It sounds like the interlock protocol only protects against MITMs that try to modify the conversation. It seems likely that most MITMing is for the purpose of merely reading a conversation, not modifying it. The wiki page also describes an attack against the protocol, so it might not be very effective.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: