27.02.2014 - 11:44 [ Techdirt ]

IETF Draft Wants To Formalize ‚Man-In-The-Middle‘ Decryption Of Data As It Passes Through ‚Trusted Proxies‘

One of the (many) shocking revelations from the Snowden leaks is that the NSA and GCHQ use „man-in-the-middle“ (MITM) attacks to impersonate Internet services like Google, to spy on encrypted communications. So you might think that nobody would want to touch this tainted technology with a barge-pole. But as Lauren Weinstein points out in an interesting post, the authors of an IETF (Internet Engineering Task Force) Internet Draft, „Explicit Trusted Proxy in HTTP/2.0,“ are proposing not just to use MITMs, but also to formalize their use.