This is a Firefox plug-in that checks SSL certificates against the list of the RSA keys compromised by Debian's predictable OpenSSL PRNG mess. A site using such certificates appears completely normal and secure in the Firefox. However it is absolutely trivial to mount a man-in-the-middle attack against an SSL session with such a site, thus completely negating the effects of SSL protection.
Detailed description of the issue is available both on the plug-in page and at this URL:
http://www.metasploit.com/users/hdm/tools/debian-openssl
(edit)
Here is a notable example - https://www.clickpass.com