random ageless

Four Nerds


daily pointers
In association with
AORTAL - the anti-portal,
here's today's daily pointers:

02/11/12
CHIRP
Andrea Illán
matchbook

(RSS)

[daily pointers archive]
other projects
special thanks


Validated XHTML 1.0
Validated CSS


2000-2012 © Joe Jenett.
Some rights reserved.

banking/e-commerce at risk

Creating a rogue CA certificate

This successful proof of concept shows that the certificate validation performed by browsers can be subverted and malicious attackers might be able to monitor or tamper with data sent to secure websites. Banking and e-commerce sites are particularly at risk because of the high value of the information secured with HTTPS on those sites. With a rogue CA certificate, attackers would be able to execute practically undetectable phishing attacks against such sites.


Posted by jenett on 12/22/09