Facebook discovered fake Digital Certificates while observing SSL connections

A group of researchers at Carnegie Mellon University in collaboration with Facebook, analyzed more than 3 million SSL connections and found strong evidence that at least 0.2% (6845) of them are made using forged Digital Certificates (self-signed certificates), which are not authorized by a legitimate Certification Authority, but which can be accepted as valid certificates for most browsers. They used Flash Player plugin to enable socket functionality and implement a partial SSL handshake to capture the forged certificates. In general, … Read more

14 Comments

How to solve the SSL certificate problem in Google Chrome

Because I’ve received countless messages and comments on the subject, I decided to write an article about it. Many of the problems with security certificates have a relatively simple solutions, while others have more complex ones. So I’m going to present you some of the solutions to solve these problems. What is a security certificate? A SSL security certificate is a digital document issued by a Certification Authority which certifies that the site in question is secure, recognized and safe. The … Read more

83 Comments