Explain like I'm five · Security

What is a Man-in-the-Middle Attack?

A man-in-the-middle attack, told as a story about a fake postman who secretly opens and rewrites letters between the castle and the shop.

our castlethe postmanSHOPthe shop'send 10 coins' — the postman carries the letter

We send a letter from the castle to the shop. The postman carries it.The letter says 'send 10 coins'. When it reaches the shop, the shop reads it.

me: no idea10 coinsto the shopopens and readsthe fake postman100 coinsto the thiefrewrites itSHOPthe shop: no ideathe letter arrived just fine — but the words changed

A fake postman opens the letter, reads it, and rewrites it. Neither side knows.The letter still arrives. But the words are different. Both I and the shop believe he is the real postman.

our castlethe fake postman in the middleSHOPthe shopslips between two people, reads and rewrites their lettersboth sides believe he is the real postman

A man-in-the-middle attack is a postman who opens your letters on the way.He slips between two people. He reads the letter, rewrites it, seals it again, and passes it on.

Reads in secretthe letter's secrets leak
Rewrites it10 coins become 100
Neither side knowshe wears the postman's coat
The shared mailboxthe easiest place to slip in
can't read it!sealed letter: unreadable without the keySHOPyes, the real shop's sealshop ID: check it is real firstseal + ID = a postman in the middle can do nothingthe seal is encryption, the ID is a certificate

Seal the letter, and check the shop is real first.A sealed letter can't be read without the key. Checking the shop's ID first means we never send letters to a fake shop.

the village's shared mailboxanyone could be peekingsend it through the sealed tunnelcareful with the shared box, safe in the tunnela fake info desk can also point you the wrong way

Be careful with the village's shared mailbox. The sealed tunnel is safe.Public Wi-Fi is the shared mailbox. Send through the sealed tunnel instead. A fake info desk can also send you the wrong way.

In one breath

Man-in-the-middle = a fake postman who secretly slips between the castle and the shop, reading and rewriting letters. Stop it with sealed letters and checking the shop's ID.

An attacker inserts themselves between two communicating parties to eavesdrop on or tamper with traffic. HTTPS (TLS encryption plus certificate validation) and VPNs are the main defenses.

When grown-ups say it

Man-in-the-middle (MITM)
The postman who opens letters on the way. Slips between two sides, reads and rewrites. Neither side knows.
Eavesdropping
Reading in secret. Even without changing anything, secrets leak just by being read.
Tampering
Rewriting. 10 coins become 100; the shop's address becomes the thief's barn.
Public Wi-Fi
The village's shared mailbox. Anyone can use it, so it is the easiest place to slip in.
ARP / DNS spoofing
The fake info desk. Gives wrong directions so letters go to the thief. → the village info desk
HTTPS
Sealed letter + shop ID. Does both at once. The padlock in the address bar is the sign. → the letter no one can read without the key
Certificate
The shop's ID. Stamped by the town office, so a thief can't fake it.
VPN
The sealed tunnel. Skips the shared mailbox and goes straight to the castle. → the sealed tunnel
Next story
The Thief With a Thousand Keys →
Want another term as a picture book? Request →