Jump to content

Talk:Man-in-the-middle attack

Page contents not supported in other languages.
Add topic
From Wikipedia, the free encyclopedia

Biometrics are no more secure, deleted...

[edit]

Most biometrics don't change; if they do, a secure-channel transfer must be made...since they are unchanging, they don't add any extra authentication security. They can just be relayed along as-is. It is generally impractical to do more than one secure channel transfer, so real-time biometrics are out. The only example I can think of that works is voice, but that is unreliable, easy to fool in only a few tries, and would rely on strings of randomly chosen words. Also, if your voice is hoarse, etc., it will lock you out. Eyes don't change, fingerprints don't change, etc. --Pokeme444 22:11, Mar 20 2010 (UTC)

https://developers.googleblog.com/upcoming-security-changes-to-googles-oauth-20-authorization-endpoint-in-embedded-webviews/ ~2026-38072 (talk) 21:08, 2 January 2026 (UTC)Reply

Any thoughts on updating the title to match industry standards?

[edit]

Proposal to rename this article to better reflect modern industry standards. While "Man-in-the-middle" remains a common historical term, leading cybersecurity frameworks have transitioned to more descriptive and technically accurate terminology. Specifically, the MITRE ATT&CK framework now categorizes this technique as Adversary-in-the-middle (AiTM)[1], while the CAPEC list identifies it as Adversary in the Middle[2]. Additionally, "On-path attack" is frequently utilized in academic and technical documentation.[3]. This change would align Wikipedia with the evolving nomenclature used by NIST, CISA, and major industry vendors.

Requesting community feedback on whether Adversary-in-the-middle attack or On-path attack is the more appropriate title for the primary entry. The current title would remain as a redirect to ensure historical continuity and searchability.

Please provide your rationale for either preference below to help reach a consensus.

I personally feel like it makes more sense to use Adversary-in-the-middle, as the impression I get is that it more widely used term within the cyber security community.

--Cktom (talk) 04:22, 31 January 2026 (UTC) Cktom (talk) 04:22, 31 January 2026 (UTC)Reply

References

  1. ↑ MITRE ATT&CK. "Adversary-in-the-Middle." https://attack.mitre.org/techniques/T1557/
  2. ↑ CAPEC. "CAPEC-94: Adversary in the Middle." https://capec.mitre.org/data/definitions/94.html
  3. ↑ NIST Computer Security Resource Center. "On-path Attack." https://csrc.nist.gov/glossary/term/on_path_attack