✓ AI-Debiased Article
Rewritten from Hacker News — Front Page • • 2 min read
4 Wire-neutral provisional

✓ No loaded language, vague sourcing, or framing detected.

Hackers Compromise Domain Registries to Obtain Counterfeit TLS Certificates

Hackers compromised three top-level domains to obtain unauthorized TLS certificates for Google and other organizations. Google has updated Chrome to block these certificates and advised domain owners to monitor for unexpected certificate issuance. The incident did not compromise the infrastructure of affected domain owners.

Companies
Google

Attackers compromised three top-level domains to obtain unauthorized TLS certificates for Google and other major organizations, according to a statement from Google on Tuesday. The attackers targeted the .gh, .sl, and .as country code top-level domains (ccTLDs), modifying authoritative DNS records for specific domains within those namespaces. This control allowed them to pass automated domain control validation checks and acquire unauthorized certificates for several Google domains and other prominent global brands and online services.

TLS certificates serve as cryptographic credentials that ensure authentication and encryption for websites, mail servers, and other internet infrastructure. These x.509 certificates bind a domain name, such as google.com, to a public key, with the private key held only by the website operator. When the keys match during a connection, it confirms the authenticity of the site.

Google has updated Chrome to block all identified unauthorized certificates and is collaborating with issuing certification authorities to revoke the unauthorized certificates related to Google properties. However, Google did not specify which domains were affected or name the other organizations involved. While Chrome users do not need to take any action for protection, Google advised domain owners to monitor certificate transparency logs for unexpected certificate issuance and to implement restrictive Certification Authority Authorization DNS records to prevent attackers from reusing cached validation data after DNS control is restored.

Google stated, "While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users." The company acknowledged that due to the complexity of DNS hijacks, it cannot guarantee that all affected domains were identified and that Chrome interventions may not protect non-Chrome users.

The extent of the unauthorized certificates issued and whether all except those for Google domains have been blocked remains unclear. The process for revoking certificates can be slow, prompting browser makers to develop quicker methods to block specific certificates at the browser level. Although all known unauthorized certificates are now blocked, Google warned that undiscovered certificates could still pose a risk.

Google clarified that the incident did not involve compromising the infrastructure of any affected domain owners and that certificate authorities adhered to all necessary requirements. By controlling the three ccTLDs, the attackers could alter the IP addresses of selected websites, enabling them to modify authoritative DNS records and nameserver delegations for those domains, thus passing industry validation checks.

This incident is not the first of its kind; a 2011 breach of the Netherlands-based certificate authority DigiNotar allowed attackers to create counterfeit certificates for Google.com and over 200 other high-traffic domains, affecting approximately 300,000 individuals in Iran who visited the impersonated sites. Similar incidents have occurred since, often due to failures by certificate authorities and domain holders.

Annotating as

No note attached

on this article.

Original vs. Neutral

Original Headline

Hackers obtain counterfeit TLS certificates for Google and other large services

Neutral Headline

Hackers Compromise Domain Registries to Obtain Counterfeit TLS Certificates