Most online users trust that sites matching the URLs they enter are safe. The most headline-grabbing attacks, launched by the so-called Comodohacker against certificate authorities Comodo and DigiNotar, aim to gather certificate information for popular social sites such as Google. With certificate information, anyone with access controls at an Internet service provider could easily create a ghost site, one that under common Internet browsing behavior and standards would be difficult for the average Web user to spot. Security experts say companies can implement additional authentication layers, including certificate testing and two-factor authentication.”]
Source: https://www.inforisktoday.com/certificate-security-matters-a-4067