The dilemma, according to Intrepidus consultant Michael Zusman, is the degree of Web apps and automation CAs deploy to hasten the validation of certificates. Zusman demonstrated how he'd used phony credentials top obtain certificates from CAs StartCom, THWATE, and LoginLive.com.
Additionally he warned that CAs are not well-defended against cross-scripting attacks or SQL injections.
Zusman made his case at the DefCon 17 hacker conference, adding to the rising tide of SSL concerns and authentication worries.