Seems like this is proof that it's not.
Seems like this is proof that it's not.
How so?
In order for this MITM to work, you must hand over the encryption certificates, so to block MITM, don't expose your private certs.
> I've never understood how/why encryption is the answer to man-in-the middle.
No encryption = Bob ---> Attacker (reads files) --> Alice
Encryption = Bob ---> Attacker (cannot read files) ---> Alice
In other words, it's not possible for MITM (like Privoxy) to operate in a transparent manner.
This is why it's recommended to use a client VPN on gateways you don't own, as MITM software can be added to any server to operate the same way (though they need to obtain the private keys of certs your browser already trusts, or silently install new ones to prevent your clients from alerting you).
Possible or not?
If Privoxy can do this, why wouldn't any other unknown/hostile MITM be able to do the same?
Because as with traditional HTTPS caching schemes like Squid, it first requires you to first install a Certificate Authority's public key into your application, browser, or OS's Certificate Store, which (barring an already compromised system) an attacker presumably can't just.. do.
FWIW, I learned that first-hand configuring Squid when I used to run my own BSD routers and have seen the situation talked to death online in any thread that mentions OpnSense or a PiHole; no degree is necessary for exposure. We all have our blind-spots, and what matters is a willingness to be in over your head while you do the hard work of learning your way around.
This includes stumbling in the dark until you learn how you learn in the first place.
Something like the below simply can not be used to implement a MITM?
Because if it can, the entire concept of using TLS to protect against MITM is pure BS --- in my uneducated opinion.
Anything is possible if you give the permissions and certs.
The Charles proxy CAN act in as a MITM, but you have to install Custom Certs on your computer (requires admin permissions).
This is similar to how a password set by someone else won't protect your documents from that person. Don't let them set the password on your computer.
"In Charles go to the Help menu and choose "SSL Proxying > Install Charles Root Certificate". Keychain Access will open. Find the "Charles Proxy..." entry, and double-click to get info on it. Expand the "Trust" section, and beside "When using this certificate" change it from "Use System Defaults" to "Always Trust". Then close the certificate info window, and you will be prompted for your Administrator password to update the system trust settings." [1]
1: https://www.charlesproxy.com/documentation/using-charles/ssl...