As mentioned in the comments: IE and Chrome on Windows trust any root certificates distributed by Active Directory. The upshot of this is that https traffic can be intercepted and decoded on corporate networks (as a MITM attack) without users being informed (as they would with firefox). Probably already deployed in any company doing serious Sarbanes-Oxley […]