Researchers poke holes in super duper SSL
Spoofing the unspoofable
By Dan Goodin in San Francisco

Posted in Security, 28th March 2009 00:05 GMT

Websites that use an enhanced form of digital authentication remain just as vulnerable to a common form of spoofing attack as those that use less costly certificates, two researchers have found.

Previously, so-called extended validation secure sockets layer certificates (or EV SSL) were believed to be immune to man-in-the-middle attacks, in which an interloper on a hotel network or Wi-Fi hotspot sits between an end user and the site she is visiting. When researchers demonstrated one such attack in December, SSL issuers proudly proclaimed that the more expensive EV certs were impervious to the technique.