Attackers hijacked three country-code top-level domains - .gh, .sl, and .as - then altered authoritative DNS records and nameserver delegations for selected domains inside those namespaces to pass automated domain-control validation and obtain unauthorized TLS certificates for several Google domains and multiple leading global brands and services. With those counterfeit x.509 certificates, attackers could cryptographically impersonate affected sites because possession of an authorized certificate binds a domain name to a public key. Google updated Chrome to block the identified unauthorized certificates and coordinated with issuing certificate authorities to revoke certificates for its properties, but did not list the affected Google domains or name other victim organizations. Google also stated that the attackers did not compromise the infrastructure of the domain owners; control of the ccTLDs alone enabled the DNS and IP changes used to satisfy certificate issuance checks.
The incident highlights that certificate issuance tied to DNS validation remains a weak link: revocation through official channels is slow, so browsers implement faster blocking mechanisms that Google used for Chrome, but those interventions do not protect non-Chrome users and cannot be relied on as a sole defense. Google urged domain owners to monitor Certificate Transparency logs and publish restrictive CAA records to limit which authorities can issue certs and to prevent reuse of cached validation data after DNS control is restored. The breach recalls the 2011 DigiNotar compromise and underscores the need to harden registries, DNS delegations, and CA validation processes.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.