back

by magnetic·7y ago·view on hn ↗
> I do disagree that a) there are bad guys between me and the http://catpictures.com right now

I don't know how one can disagree with something that can't be known one way or the other.

Security features/processes are there to account for the small possibility that an attack is attempted. They don't become useless simply because attacks aren't happening 100% of the time. For example: your door lock (deadbolt) is locked even when there isn't someone actively trying to break into your house.

In your particular example, sitting between A and B doesn't always mean sniffing packets you send from A to B as a "passive listener". It could simply be that the attacker has fed you his/her rogue IP via DNS and you are connecting to his server that is pretending to be B.

At that point yes the attacker is sitting between A and B, but it's not like s/he is sitting on a router sniffing your packets. S/he does not have to be a malicious player near the target server, or part of the infrastructure that you use to get to B. S/he can be somewhere completely remote.