Reply to post:

WikiLeaks drama alert: CIA forged digital certs imitating Kaspersky Lab

Anonymous Coward
Anonymous Coward

Impersonation <> properly signed (by the CA) certificate. How are they getting around this? How are they signing the cert such that client is accepting it without a security warning? Surely that is the most interesting bit here?

Anyone can issue a cert for any site, getting that cert trusted by the client is the hard bit.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon