Attackers hijack three country-code domains to obtain counterfeit TLS certificates
Google said attackers hijacked the .gh, .sl and .as domains to obtain unauthorized certificates for several Google domains and other large organizations.
Key facts
- Attackers hijacked the .gh, .sl and .as country code top-level domains and modified authoritative DNS records for selected domains, according to Google.
- Google said the attackers passed automated domain control validation checks and obtained unauthorized certificates for several Google domains and several leading global brands.
- Google said it updated Chrome to block the unauthorized certificates it identified and worked with issuing certification authorities to revoke those for Google properties.
- Google did not identify the affected Google domains or name the other organizations whose domains were affected.
- Google said the incident did not involve compromise of any affected domain owner's infrastructure and that certificate authorities followed all requirements.
Attackers hijacked three country code top-level domains, .gh, .sl and .as, and used that control to obtain counterfeit TLS certificates for Google and other large organizations, Google said on Tuesday, 6 October. Google said the attackers modified authoritative DNS records for selected domains within those namespaces. By controlling those records, the attackers passed automated domain control validation checks, according to Google.
Google said unauthorized certificates were obtained for "several Google domains" and for "several leading global brands and widely used online services." Google did not identify which of its own domains were affected or name any of the other organizations. Ars Technica reported it is not immediately clear how many unauthorized certificates were issued, what the other affected organizations are, or whether all of them except those for Google domains have been blocked.
TLS certificates are cryptographic credentials that bind a domain name such as google.com to a public key and underpin authentication and encryption for websites, mail servers and other internet infrastructure, Ars Technica reported. Possession of unauthorized certificates allows attackers to cryptographically impersonate the affected infrastructure, according to Ars Technica. Google said it updated Chrome to block all certificates it identified as unauthorized and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.
Google said Chrome users do not need to take any action to be protected. "While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users," Google said. Google also said that due to the complexity of DNS hijacks it cannot guarantee its analysis identified every affected domain, and that Chrome interventions do not reliably protect non-Chrome users.
Google advised domain owners to monitor certificate transparency logs for unexpected certificate issuance across their domains and to publish restrictive Certification Authority Authorization DNS records. Google said this prevents attackers from reusing cached validation data after DNS control is restored. Ars Technica reported that the official process for revoking certificates is slow and cumbersome, so browser makers have devised quicker methods to block specific certificates at the browser level. Ars Technica reported that with all known unauthorized certificates now blocked the risk is mitigated, but that any certificates remaining undiscovered pose a threat.
Google said the incident did not involve the compromise of the infrastructure of any of the affected domain owners and that certificate authorities followed all requirements. With control of the three ccTLDs, the attackers were able to change the IP addresses of a selected list of websites and to modify authoritative DNS records and nameserver delegations for selected domains, according to Google.
Context
TLS certificates let a browser check that a site is the one it claims to be. Attackers who control a top-level domain's DNS records can redirect traffic for selected sites and pass the automated checks that certificate authorities use to confirm a domain owner controls a domain, according to Google.
How outlets headlined it
How this was made
Compiled by our AI newsroom from 1 independent outlets, checked by a separate AI editor against the sources. Only claims found in the sources are reported. Spot an error? Every source is linked below.
Factual additions, source corrections, and primary references welcome. Strict zero-troll and zero-spin policy.
No notes yet. Be the first to provide factual context.
Reader Discussion & Community Notes
0 Contributions