Compromised Certificate Authority

One of the nightmare scenarios in the computer security world has happened, a Certificate Authority has been compromised. This is somewhat similar to someone hacking into the DMV and issuing fake licenses, you can no longer trust a card holder’s identity. A large number of secure sites can no longer be trusted, malicious sites can impersonate legitimate sites, and secure communications can be intercepted. This has been discussed as a “what if” for years, but no actual occurrences have been reported. The Mozilla and Chrome web browsers have been patched to help negate the effects, but other applications like email, chat, and file transfer applications are currently vulnerable. There are mitigating circumstances so this may turn out to be a smaller issue than it appears to be at the moment.

https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-browser-collusion