prodil89 Posted August 16, 2010 Report Posted August 16, 2010 "This paper introduces the compelled cer-ticate creation attack, in which governmentagencies may compel a certicate authority toissue false SSL certicates that can be used byintelligence agencies to covertly intercept andhijack individuals' secure Web-based commu-nications. Although we do not have direct ev-idence that this form of active surveillance istaking place in the wild, we show how prod-ucts already on the market are geared and mar-keted towards this kind of use|suggesting suchattacks may occur in the future, if they arenot already occurring. Finally, we introducea lightweight browser add-on that detects andthwarts such attacks."[url]http://files.cloudprivacy.net/ssl-mitm.pdf[/url] Quote