Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This Ars article from last week gives some context and explanation:

http://arstechnica.com/business/news/2012/02/critics-slam-ss...

In short, at least one CA, Trustwave, has issued a "subordinate CA certificate" (which allows another party to issue certs which will be trusted as if they were from Trustwave) to a network admin who used it to create forged certificates and intercept SSL traffic on their internal network.



Has there been any talk about which company received the subordinated cert? The excuse for it being used in an internal network only doesn't really hold any weight due to the ability to install custom certs on all web browsers.


This way even user-installed browsers would accept the subordinated cert. It's one of those things I believe should be prosecuted.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: