Comodo, the Jersey City, NJ-based security company whose reseller issued the bogus certificates, disputed the charge, saying that at no time was anyone at risk.
Last week, attackers used a valid username and password to obtain nine SSL certificates -- used to prove that a site is legitimate -- from an Comodo affiliate. The certificates were for six Web sites, including the log-on sites for Microsoft's Hotmail, Google's Gmail, the Internet phone and chat service Skype, and Yahoo Mail. A certificate for Mozilla's Firefox add-on site was also acquired.
At least one of the certificates, for logon.yahoo.com, was used to legitimize a fake Yahoo site hosted by an Iranian ISP (Internet service provider), Comodo said yesterday.
Comodo's CEO and founder, Melih Abdulhayoglu, said there was evidence, largely circumstantial, that the Iranian government had backed the hack of its partner to obtain SSL certificates.
http://www.computerworld.com/s/arti...put_Iranian_activists_at_risk_says_researcher
It is unsafe to use Google, Skype, Microsoft and Yahoo on iOS 4.3 or before if you use it check your e-mail, VOIP, or send anything sensitive when using iOS 4.3 or before because you are vulnerable to man in the middle attacks. Since iOS Safari and derived browsers have no means of updating trusted certificates or blacklisting them, you absolutely MUST upgrade to iOS 4.3.1 released today, which I believe should contain the blacklisted certificates.
iOS 4.3.1 is *not* optional people, it is a security upgrade.