Visiting a website that is certified with an SSL certificate does not mean that the website is not fake. Secure Sockets Layer (SSL) protects Internet users in two ways, it uses public key encryption to encrypt sensitive information between a user's computer and a website, such as usernames, passwords, or credit card numbers, and to verify the identity of websites.
Today, hackers and cybercriminals use every means to steal user credentials and other sensitive information by inserting fake SSL certificates into fake social media, e-commerce, and financial websites.
A team of researchers, Lin – Shung Huang, Alex Ricey, Erling Ellingseny and Collin Jackson, from Carnegie Mellon University, in collaboration with Facebook have analyzed (PDF) more than 3 million SSL connections and found strong evidence that at least 6,845 (0.2%) of them were actually tampered with forged certificates, i.e. self-signed digital certificates that are not authorized by the legitimate owners of the website, but will be accepted as valid by most browsers.
They used the widely known Flash Player plug-in to enable the feature and implement a partial SSL to capture fake certificates and deploy this detection mechanism on Alexa's top 10 websites, Facebook, which terminates connections through a diverse set of network operators around the world.
Modern web browsers display a warning message when they encounter errors during SSL certificate validation, but the warning page still allows users to proceed with a potentially insecure connection.


