Interestana
Home/News/Hackers Forge TLS Certificates for Google and Major Services by Hijacking ccTLDs
Ars Technica••4 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Hackers Forge TLS Certificates for Google and Major Services by Hijacking ccTLDs

Hackers Forge TLS Certificates for Google and Major Services by Hijacking ccTLDs

Attackers have successfully obtained counterfeit Transport Layer Security (TLS) certificates for Google and a number of other prominent global organizations by hijacking control of three country code top-level domains (ccTLDs): .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). Google disclosed this significant security incident on Tuesday, explaining that the malicious actors first gained control over these specific ccTLDs. Once control was established, the attackers proceeded to modify the authoritative Domain Name System (DNS) records for selected domains residing within these compromised namespaces. This manipulation of DNS records was a critical step, as it allowed the attackers to bypass the automated domain control validation checks that are a standard requirement for obtaining legitimate TLS certificates. By successfully passing these checks, they were then able to acquire unauthorized digital certificates for "several Google domains" and "several leading global brands and widely used online services."

The implications of this breach are substantial, given the fundamental role of TLS certificates in modern internet security. TLS certificates, specifically x.509 certificates, are the cryptographic credentials that enable both authentication and encryption for a vast array of online services, including websites, mail servers, and other critical internet infrastructure. They function by digitally binding a specific domain name, such as google.com, to a public key. The integrity of this system relies on the corresponding private key being exclusively held and protected by the legitimate operator of the domain. When a user's web browser initiates a connection to a website, it performs a verification process to ensure that the public key presented by the server matches the expected key. This validation confirms that the user is indeed connected to the authentic site and not an imposter, thereby preventing man-in-the-middle attacks where an attacker intercepts and potentially alters communication. The possession of unauthorized certificates by attackers grants them the ability to cryptographically impersonate the targeted infrastructure, opening the door to widespread data interception, phishing attacks, and other fraudulent activities.

In response to this sophisticated attack, Google has taken immediate action. The company announced that it has updated its Chrome web browser to block all identified unauthorized certificates, thereby preventing users from connecting to sites that might be using these fraudulent credentials. Furthermore, Google has been actively collaborating with the issuing certification authorities (CAs) responsible for these certificates to ensure that all unauthorized certificates issued for Google's properties have been promptly revoked. This swift action aims to mitigate further risks to Google's users and services. The incident underscores a critical vulnerability within the domain name system and the broader certificate issuance ecosystem, highlighting the paramount importance of robust security measures and continuous vigilance at all levels of internet infrastructure to protect against such advanced threats.

Original source — read the full reporting at the publisher:

Read on Ars Technica

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next