True, but the packets in-flight can take different routes. If you have a machine on the switch, you know you've captured all the packets that were in-flight. This make it easier to break the encrypted packets.
It's a choice--everything in security is a risk-management assessment, but I'm surprised rsync.net was able to get so many security certifications with this setup.
Dumb switches will blast packets to all interfaces that are connected. If there's a machine on the switch that's in promiscuous mode, it can see all the packets on the local network (including the backups coming in from customers).
Managed switches typically have ACL support. I get the KISS principle, but this setup seems to be trading security for simplicity.
I've been looking for something like this for a while. It's hard to break into FPGA design coming from a Software Engineering viewpoint, but I think it teaches how the machine REALLY works and can produce better Software developers.
"The Spinner* sends you an innocent looking link. This link is sent to the target via text message. When the target presses the link, a cookie connected to the link attaches itself to the target’s phone."
Is this legal? I never click on links sent via SMS.
https://www.youtube.com/watch?v=fvRpntmUIxs