What Is a Man-in-the-Middle Attack and How HTTPS Protects You
Patrick Bushe
September 27, 2024 · 5 min read
In a man-in-the-middle attack, someone secretly places themselves between you and a website, so your traffic passes through them. They can read it, change it, or pretend to be the site. HTTPS is the main defense, and it works well when you let it.
How attackers get in the middle
- Fake Wi-Fi: a hotspot named like the café's or airport's network, run by the attacker.
- Compromised routers: home or office routers with default passwords or old firmware.
- Local network tricks: on shared networks, attackers can redirect other devices' traffic through their own.
- DNS tampering: sending you to a fake server when you look up a site.
How HTTPS stops them
- Encryption: traffic between your browser and the site is scrambled, so an interceptor sees only noise.
- Certificates: the site proves its identity with a certificate signed by a trusted authority. An attacker can't produce a valid certificate for a site they don't control.
- Integrity: any tampering with the data in transit is detected.
Many sites also use HSTS, which tells browsers to always use HTTPS for that site, so attackers can't downgrade you to an unencrypted connection.
Take certificate warnings seriously
If Chrome shows "Your connection is not private", it couldn't verify the site's certificate. On a public network, that can mean someone is intercepting traffic. Don't click through to sites where you sign in or pay. Go back, switch networks, and try again.
Turn on HTTPS-First
In Chrome, Settings → Privacy and security → Security → Always use secure connections makes Chrome try HTTPS first and warn you before loading any page without it.
Where HTTPS can't help
- Phishing: a fake site can have a perfectly valid certificate for its own address. Check the address itself. See spotting fake websites.
- Malware on your device sees everything before it's encrypted.
- Managed devices: work computers may have company certificates installed to inspect traffic. That's a legitimate setup, but it means your employer can see your browsing on that device.
- Which sites you visit: HTTPS hides pages and content, not the fact that you're connecting to a site. See DNS over HTTPS.
On public Wi-Fi
- Confirm the network name with staff.
- Use a trustworthy VPN for extra protection. See what a VPN protects on public Wi-Fi.
- Prefer your phone's mobile data for banking.
Protect what you copy
Clipboard Guard stops web pages from reading your clipboard, a separate risk from interception, useful when you copy passwords or codes.