The most powerful deterrent against the use of man-in-the-middle attacks against SSL/TLS-encrypted connections may be how much easier it may be to simply attack from the endpoint. Certainly “man-in-the-middle” sounds more sophisticated, and as a pair of well-known academic researchers are preparing to report, the phrase has actually become a “starburst” marketing point for the sale of digital surveillance equipment to government agencies. However, perhaps the most serious defect in the SSL system lies in the ability of government agencies to acquire false intermediate certificates.