>      I doubt it.  It's true that VeriSign has certified this
>   attack, but no one cares.  

Indeed, it would make sense for the original vendor website (eg Palm)
to have signed the "MITM" site's cert (,
not for Verisign to do so.  Even better, for Mastercard to have signed
both Palm and as well.  And Mastercard to
have printed its key's signature in my monthly paper bill.

(This is aside your main point about it being Mastercard et al. 
doing the checking/backup for the customer, not certs.)

