← Back to context

Comment by akashshah

13 years ago

I fail to see how this is a MITM attack

It is absolutely an MITM attack, if for no other reason that your email has no presumption of privacy once it is in the hands of Facebook. Read the TOS. They can do whatever they like with the data that passes through your account.

They are counting on your not noticing that they changed your publicly displayed email address, so that instead of a message going straight to you and bypassing facebook.com, it now goes to facebook.com. You still get the message. So do they.

If someone wanted to send you a top secret email (as opposed to a facebook message), they'll send it to your email address, except now your email address is listed as @facebook. The "attack" assumes someone doesn't already know your email, has something top secret that they don't want facebook to know, and are so retarded they don't look at the address they're sending to.

It's a MITM attack on one particular means of distributing your email address, but it's not an attack on your email at all.

  • Be fair; anyone who wants to send me a "top secret" email, but has to go to facebook to find my email address; I don't want them sending me their "secrets".