Banks and secure email systems use HTTPS and SSL VPN's. Why shouldn't I?
Banks rely on the fact that people don’t know how to do man-in-the-middle attacks, and the fact that in the US, authorities are required to get a court ordered subpoena to request the Internet Service Providers give them access to internet traffic.
However, the instructions and technology for performing a MITM attack are easily available to anyone on the internet and secondly, not every country has the same requirement of court ordered subpoenas, in fact most do not and most of the time the ISP is either directly owned or operated by the state.
For example this ethical hacker link shows one how to perform a MITM attack.
It’s true – 128 bits of encryption would take the fastest known super computer about 100 years to decrypt. But a MITM doesn't need to decrypt your data, it just steals the encryption keys used to encrypt the data as the keys are not encrypted in these types of VPN's, taking less than a second.
|