hn.today

Hackers obtain counterfeit TLS certificates for Google and other large services

arstechnica.com9 points3 comments
Screenshot of Hackers obtain counterfeit TLS certificates for Google and other large services

Attackers hijacked three country-code top-level domains - .gh, .sl, and .as - then changed authoritative DNS records and nameserver delegations for selected domains to pass automated domain-control validation and obtain unauthorized TLS certificates for several Google domains and other high-profile services. Google updated Chrome to block the identified certificates and worked with issuing certification authorities to revoke them, while advising domain owners to monitor certificate transparency logs and publish restrictive CAA DNS records to prevent reuse of cached validation data. Google emphasized that Chrome’s interventions don’t guarantee protection for non-Chrome users and that the incident did not involve compromise of the affected organizations’ own infrastructure; certificate authorities followed required procedures, but control of the ccTLDs allowed attackers to manipulate DNS and satisfy validation checks.

The incident underscores that certificate issuance remains a weak link in Internet authentication: possession of unauthorized x.509 certificates lets attackers cryptographically impersonate sites and intercept traffic. Revocation through formal channels is slow, so browser-level blocking is used as a faster mitigation, but undiscovered certificates still pose a live threat. The attack echoes past incidents such as the 2011 DigiNotar breach, illustrating recurring systemic risks and the need for rigorous DNS and CA defenses alongside continuous monitoring.

Read on arstechnica.com3 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

Is Criminal Forensics Bullshit?

Is Criminal Forensics Bullshit?

Sara Gordon's research questions the scientific validity of forensic techniques like blood pattern analysis and ballistics, which are often accepted uncritically in court. Studies show these methods have significant uncertainties and rely more on subjective interpretation than rigorous science. (nautil.us)

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.