Posted Friday 20th April 2007 14:43 GMT
Even worse
There was a "high value"* investment service, that I can't name because of NDA, that issued its own certificate. They said that was okay, they just told their customers to accept it. So I issued my own certificate, hacked the site (Code Red days) and did some phishing, back before it was popular.
They bought a certificate from Verisign.
* high value - net worth in excess of $10M