âThis successful proof of concept shows that the certificate validation performed by browsers can be subverted and malicious attackers might be able to monitor or tamper with data sent to secure websites,â said security researcher Alexander Sotirov, who worked with others from the U.S., the Netherlands, and Switzerland.
A successful attack would allow attackers to appoint themselves as an Intermediate Certificate Authority, and then generate trusted certificates without having to contact a real CA. The spoofed certificates could then be used to add the appearance of legitimacy to a phishing site designed to steal bank account passwords, for example.
http://www.insidetech.com/news/articles/36...T_nlet_20090107
yah.