Hackers hacked at hack.lu ...
Quote from his post:
So, what happened? As I said in a spontaneous lightning talk after that session, my diagnosis was that somebody was running a man-in-the-middle attack on a room full of security people. The tool they were using rewrote the TLS certificates that were shown by servers, but tried to keep the human-readable information in the certificate intact. (As Benny K notes in a comment, "the certificate seemed fine".)
Several people found it fascinating that several security professionals in the room still accepted the forged certificate while they new they were connected to a hostile wireless network. What if this happened during an anti-malware conference?
Would the result be different? In my opinion it shows the real thougts from a bad minded security guy. Is that not the real difference between the real security and the anti-malware world which is still a little bit different? I don't know.
<< Home