User: Password:
Subscribe / Log in / New account

I ran into this problem

I ran into this problem

Posted Nov 8, 2012 14:50 UTC (Thu) by basdebakker (guest, #60977)
Parent article: Holes discovered in SSL certificate validation

One day my browser told me that gmail was returning an invalid certificate. It was a certificate for the correct domain, but signed by an untrusted authority. This was an actual MITM attack.

I noticed that my gmail notifier (checkgmail) just kept working! Apparently it didn't check the certificate. I ditched the notifier, changed my gmail password and sent an e-mail to the author of the notifier. Never got a reply, though.

(Log in to post comments)

I ran into this problem

Posted Nov 8, 2012 15:35 UTC (Thu) by cortana (subscriber, #24596) [Link]

Any idea who perpetrated the attack? Public wifi, an employer, etc.?

Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds