Re: CVE-2007-659[01]

* Stefan Fritsch:

> I don't agree with this. An attacker can trick a user to accept a
> certificate for '*' which then allows to do MITM attacks for any
> websites.

You still need to subvert IP routing.  If you do that, most users will
click away the warnings anyway.

