Forged SSL Certificates Pervasive on the Internet

Current Berkman People and Projects 2014-05-16

About 0.2% of all SSL certificates are forged. This is the first time I've ever seen a number based on real data. News article:

Of 3.45 million real-world connections made to Facebook servers using the transport layer security (TLS) or secure sockets layer protocols, 6,845, or about 0.2 percent of them, were established using forged certificates.

Actual paper.