Security

Man-in-the-Middle Attack

Interception or alteration of communication between parties that believe they are communicating directly. Encryption and certificate checks help prevent many forms of this attack.

How it works

A man-in-the-middle attack places an unauthorized intermediary between communicating parties so it can observe, impersonate or alter their exchange. The mechanism depends on the protocol and trust checks. Encryption without correct authentication is different from an encrypted connection that also verifies the intended endpoint.

A practical example

A manipulated connection could present a certificate warning while pretending to be a familiar service. Continuing past that warning can remove an important identity check. By contrast, a slow network alone provides no evidence that communications are being intercepted; performance and connection integrity require different investigation.

What to check

Use supported software and legitimate service addresses, and do not bypass unexpected certificate warnings to finish a sensitive task. Record the exact warning, address and network context for investigation. On managed equipment, ask the administrator whether any approved inspection system is involved rather than installing unfamiliar certificates or changing trust settings yourself.

Limits and safe use

HTTPS protects an authenticated connection but does not establish that every encrypted website is honest. A deceptive lookalike website can have its own valid certificate. A VPN also does not repair an infected endpoint or authorize the destination. Distinguish transport protection, website identity and the legitimacy of the requested action before drawing conclusions.

Technical sources

← All glossary terms