Back to Blog

What Is a Man-in-the-Middle Attack and How HTTPS Protects You

PB

Patrick Bushe

September 27, 2024 · 5 min read

In a man-in-the-middle attack, someone secretly places themselves between you and a website, so your traffic passes through them. They can read it, change it, or pretend to be the site. HTTPS is the main defense, and it works well when you let it.

How attackers get in the middle

  • Fake Wi-Fi: a hotspot named like the café's or airport's network, run by the attacker.
  • Compromised routers: home or office routers with default passwords or old firmware.
  • Local network tricks: on shared networks, attackers can redirect other devices' traffic through their own.
  • DNS tampering: sending you to a fake server when you look up a site.

How HTTPS stops them

  1. Encryption: traffic between your browser and the site is scrambled, so an interceptor sees only noise.
  2. Certificates: the site proves its identity with a certificate signed by a trusted authority. An attacker can't produce a valid certificate for a site they don't control.
  3. Integrity: any tampering with the data in transit is detected.

Many sites also use HSTS, which tells browsers to always use HTTPS for that site, so attackers can't downgrade you to an unencrypted connection.

Take certificate warnings seriously

If Chrome shows "Your connection is not private", it couldn't verify the site's certificate. On a public network, that can mean someone is intercepting traffic. Don't click through to sites where you sign in or pay. Go back, switch networks, and try again.

Turn on HTTPS-First

In Chrome, Settings → Privacy and security → Security → Always use secure connections makes Chrome try HTTPS first and warn you before loading any page without it.

Where HTTPS can't help

  • Phishing: a fake site can have a perfectly valid certificate for its own address. Check the address itself. See spotting fake websites.
  • Malware on your device sees everything before it's encrypted.
  • Managed devices: work computers may have company certificates installed to inspect traffic. That's a legitimate setup, but it means your employer can see your browsing on that device.
  • Which sites you visit: HTTPS hides pages and content, not the fact that you're connecting to a site. See DNS over HTTPS.

On public Wi-Fi

Protect what you copy

Clipboard Guard stops web pages from reading your clipboard, a separate risk from interception, useful when you copy passwords or codes.

More Tools by Patrick Bushe

Free Chrome extensions to boost your productivity and privacy