Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Has my MacBook Air become a MITM target?

Hi everyone,


Yesterday I encountered a thing that has been bugging me. When I turn my Wi-Fi on and change the volume using the buttons on my keyboard, the appearance of the volume on-screen seems to lag. After touching the buttons several times the volume appears, but with a slight delay and lag. The scary part: when my Wi-Fi is turned off it works just as it should. Overall, my Mac is not slow in operating, but downloading updates (10.10.4) or a virus scanner from the App Store took way longer than it should be.


I downloaded AntiVirus Sentinel Pro and received the message 'a MiTM attack was blocked'. After searching what it meant I figured this would make sense given that the inconsistencies in my Mac operations only occur when the Wi-Fi is turned on.


What do you think, is MiTM the issue here? Any suggestions on how to solve this?


Many thanks!


MacBook Air (13-inch, Mid 2013)

1,3 GHz Intel Core i5

Intel HD Graphics 5000 1536 MB

Version: 10.10.4 (14E46)

MacBook Air, OS X Yosemite (10.10.4)

Posted on Jul 2, 2015 3:19 AM

Reply
Question marked as Best reply

Posted on Jul 2, 2015 4:25 AM

Sentinel Pro is a relatively new and still rather unknown player in the anti-virus business. There is absolutely no documentation I can find anywhere that describes what it may be looking for as a MiTM attack. My best guess would be that this is a false positive, but you should probably contact the company directly and see what they have to say.


As for the problem with the lag in the volume change, that is in no possible way related to a MiTM attack, or any other malicious activity. It's impossible to say what might be causing it, but since there appears to be correlation between two completely unrelated things (wifi being on and the lag in volume change), it may be a hardware issue.

5 replies
Question marked as Best reply

Jul 2, 2015 4:25 AM in response to MichielRietdijk

Sentinel Pro is a relatively new and still rather unknown player in the anti-virus business. There is absolutely no documentation I can find anywhere that describes what it may be looking for as a MiTM attack. My best guess would be that this is a false positive, but you should probably contact the company directly and see what they have to say.


As for the problem with the lag in the volume change, that is in no possible way related to a MiTM attack, or any other malicious activity. It's impossible to say what might be causing it, but since there appears to be correlation between two completely unrelated things (wifi being on and the lag in volume change), it may be a hardware issue.

Jul 2, 2015 4:51 AM in response to MichielRietdijk

Hi Michiel


it is very very very unlikely that you encounter a MITM attack, if you use an encrypted WiFi. The delay might have various reasons. If you switch on your WiFi, your computer starts looking for app updates, it might upload data to your dropbox, check credentials for other cloud services etc etc and so on. This requires quite some resources and thus some other commands (like volume control) might get a lower priority in the process execution. This should have stopped after some seconds, maybe a minute or so - and then everything should be back to normal.


The Antivirus sentinel Pro is generally perceived as worthless, see e.g. Is AntiVirus Sentinel Pro legit? If not, how can I delete it?


And btw: if there's really a MITM attack, you probably wouldn't recognize it at all! https://en.wikipedia.org/wiki/Man-in-the-middle_attack


Regards

MK

Jul 2, 2015 6:01 AM in response to thomas_r.

Many thanks for the advise, quite a relief! Could the issue be storage related, as I have 40GB left of the 120GB available?

What mac_kal said applies: "This should have stopped after some seconds, maybe a minute or so - and then everything should be back to normal."

The only thing is that it takes about 30 minutes, sometimes longer. I'll try moving files to my external hard drive and see if that will make a difference.

Jul 2, 2015 7:41 AM in response to MichielRietdijk

I downloaded AntiVirus Sentinel Pro

Start by getting rid of it. Like all commercial "security" products for the Mac, it's worse than useless and has already wasted your time. Back up all data before making any changes.


After cleaning up that mess, see below.

Launch the Console application in any of the following ways:

☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)

☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.

☞ Open LaunchPad and start typing the name.

The title of the Console window should be All Messages. If it isn't, select

SYSTEM LOG QUERIES ▹ All Messages

from the log list on the left. If you don't see that list, select

View ▹ Show Log List

from the menu bar at the top of the screen.

Click the Clear Display icon in the toolbar. Then take an action that isn't working the way you expect. Select any lines that appear in the Console window. Copy them to the Clipboard by pressing the key combination command-C. Paste into a reply to this message by pressing command-V.

The log contains a vast amount of information, almost all of which is irrelevant to solving any particular problem. When posting a log extract, be selective. A few dozen lines are almost always more than enough.

Please don't indiscriminately dump thousands of lines from the log into this discussion.

Please don't post screenshots of log messages—post the text.

Some private information, such as your name or email address, may appear in the log. Anonymize before posting.

When you post the log extract, you might see an error message on the web page: "You have included content in your post that is not permitted," or "The message contains invalid characters." That's a bug in the forum software. Please post the text on Pastebin, then post a link here to the page you created.

Has my MacBook Air become a MITM target?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.