hn.today

Hackers obtain counterfeit TLS certificates for Google and other large services

arstechnica.com54 points7 comments
Screenshot of Hackers obtain counterfeit TLS certificates for Google and other large services

Attackers hijacked three country-code top-level domains - .gh, .sl, and .as - then altered authoritative DNS records and nameserver delegations for selected domains inside those namespaces to pass automated domain-control validation and obtain unauthorized TLS certificates for several Google domains and multiple leading global brands and services. With those counterfeit x.509 certificates, attackers could cryptographically impersonate affected sites because possession of an authorized certificate binds a domain name to a public key. Google updated Chrome to block the identified unauthorized certificates and coordinated with issuing certificate authorities to revoke certificates for its properties, but did not list the affected Google domains or name other victim organizations. Google also stated that the attackers did not compromise the infrastructure of the domain owners; control of the ccTLDs alone enabled the DNS and IP changes used to satisfy certificate issuance checks.

The incident highlights that certificate issuance tied to DNS validation remains a weak link: revocation through official channels is slow, so browsers implement faster blocking mechanisms that Google used for Chrome, but those interventions do not protect non-Chrome users and cannot be relied on as a sole defense. Google urged domain owners to monitor Certificate Transparency logs and publish restrictive CAA records to limit which authorities can issue certs and to prevent reuse of cached validation data after DNS control is restored. The breach recalls the 2011 DigiNotar compromise and underscores the need to harden registries, DNS delegations, and CA validation processes.

Read on arstechnica.com7 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

Is Criminal Forensics Bullshit?

Is Criminal Forensics Bullshit?

Sara Gordon's research questions the scientific validity of forensic techniques like blood pattern analysis and ballistics, which are often accepted uncritically in court. Studies show these methods have significant uncertainties and rely more on subjective interpretation than rigorous science. (nautil.us)

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.