Cybersecurity
Criminal versus state is the wrong axis, since what matters is network position rather than motive. A compromised router at a regional ISP, a BGP hijack window, a resold hosting environment in path, those are all criminals, they just have better access than a kit operator, and access like that gets rented. On MPIC, the limitation worth testing is that it constrains where validation is observed from, not who observes it, so perspectives sharing upstream transit or concentrated in a few cloud regions can be satisfied at once by an actor with regional routing leverage. On your CT question, telling a Cloudflare-issued cert from a malicious one after the fact is genuinely hard, and accounturi is exactly the field that would have made it possible, so the flaw removes the preventive control and the detective one together. The workable substitute is a diff against your own inventory, which crt.sh covers for zones you control and which Bolster AI and Netcraft do against lookalikes for the ones you don't. Worth adding to your model that the attacker may not need MITM at all, since a browser-trusted cert on an adjacent name is enough for a credential harvest.
[link] [comments]