The case of the fraudulent SSL certificates
The case of the fraudulent SSL certificates
Posted Mar 24, 2011 2:52 UTC (Thu) by ribbo (subscriber, #2400)Parent article: The case of the fraudulent SSL certificates
I read somewhere that these certificates may have actually been used by a particular country. In the case of the using a CRL or OCSP there's then nothing to stop the MITM from either just redirecting them or blocking access to the service just as they are for the other component of the MITM.
