Hacker News new | ask | show | jobs
by dasrecht 5913 days ago
If someone (with a malicious background) owns a Root CA wich is embedded into the Mozilla Cert Storage he could sign SSL Certs sites as he wants to... and clearly the user won't be warned that the connection isn't secure because the Root CA is there.

Basically it's a Secure Connection to a malicious Site. Got it?