A series of registry hijacks of the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) ccTLDs allowed attackers to modify authoritative DNS records and obtain unauthorized HTTPS certificates covering Google domains and many other organizations. Chrome responded immediately by blocking those unauthorized certificates in the browser using CRLSets and coordinating with issuing Certificate Authorities to revoke the certificates so non-Chrome clients were protected. Analysis of Certificate Transparency logs uncovered additional affected brands and services; Chrome proactively blocked those certificates as well and reached out to impacted organizations. Chrome says end users of the browser do not need to take any action.
Chrome warns that browser-side mitigations are not a substitute for domain owner defenses and outlines concrete steps: continuous monitoring of Certificate Transparency logs for unexpected issuance across all domain holdings, and publishing restrictive CAA records with ACME account bindings to limit which CAs and accounts can issue certificates. CAA helps prevent new issuance after DNS control is restored and mitigates reuse of cached domain-control validations. Chrome also commits to ecosystem changes - reducing certificate validity and DCV reuse through the Chrome Root Program and a new quantum-resistant root initiative - to limit the impact of transient routing and DNS compromises.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.