
A recent
study found that Trend Micro Internet users in 40 different networks of
Internet providers and the University of Iranians turned out to contain fake
SSL certificate issued by DigiNotar.
Providers
and suppliers sites SSL certificate authority certificate in the Netherlands,
was used to spy on Internet users in Iran on a large scale.
In theory,
false certificates could be used to trick users into visiting a fake version of
a Web site, or used to control communication with the actual site without the
user noticing.
But the
trick of a false certificate, a hacker must be able to direct Internet traffic
routed through a server he controls. That's something only the Internet service
provider, or government with a single command,...