The idea being that your web browser trusts certificate authorities (like verisign) in other foreign nations. Those CAs can be forced by their government to create a false certificate for say like http://www.bankofamerica.com. The end user would notice nothing wrong if sent to a fake site.
https://docs.google.com/viewer?url=h...t/ssl-mitm.pdf
Abstract: This paper introduces a new attack, the compelled certificate creation attack, in which government agencies compel a certificate authority to issue false SSL certificates that are then used by intelligence agencies to covertly intercept and hijack individuals' secure Web-based communications. We reveal alarming evidence that suggests that this attack is in active use. Finally, we introduce a lightweight browser add-on that detects and thwarts such attacks.
Comment