Comment 38 for bug 312536

Revision history for this message
Miron Cuperman (devrandom) wrote :

A successful attack would mean that the attackers would have a rogue CA. They would then be able to generate a bogus certificate for any site without any additional resources. This issue should therefore be considered critical in my opinion. The benefit to an attacker would justify using considerable resources in generating the rogue CA cert.

I do think that the end-user should be able to override the security weakness warning.