SSL/TLS Session-Aware User Authentication—Or How to Effectively Thwart the Man-in-the-Middle Rolf Oppliger