Gogo — one of the largest providers of in-flight Internet service — has been caught issuing fake SSL certificates, allowing the inflight broadband provider to launch man-in-the-middle (MITM) attacks on its own users, view passwords and other sensitive information.The news came to light when security engineer Adrienne Porter Felt, who works on Google Chrome’s security team, was served the phony SSL certificate while trying to connect to Google's video service YouTube. She noticed that the SSL certificate was signed by an untrusted issuer and wasn’t issued by Google, but rather by Gogo itself.
Read more at:
http://thehackernews.com/2015/01/gogo-fake-ssl-certificate.html
0 comments: