You probably know that some Web https certificate issuers have been hacked these last month. These hacking enabled to create fake https certificates for Google.com, Microsoft.com, twitter.com, FaceBook.com and many others. Reports indicate that these fakes certificates has been used to intercept communication between users and Google, web mail services and social medias. Thus, they were able to intercept user account name and password, and any communication, finally to own their account or spy on them continuously, beside use of the https protocol, encrypted and designed to protect your privacy. There’s a mechanism to prevent usage of these fake certificates, it’s updating the root certificates, to disable all certificates that were issued by the hacked providers. Then a fake google.com certificate won’t be accepted in any browser, the browser will refuse it, but still the correct google certificates will be recognized as signed and correct. I discovered today on my Virtual Fusion Windows, that Microsoft don’t offer this update by default: my Windows and my Internet Explorer where using a totally outdated root certificate list, opening the ability for anyone using a fake certificate to spy any communication I have with Google, Microsoft and others! What the hell it is