Signal

Hackers obtain counterfeit TLS certificates for Google and other large services

First reported by Ars Technica ·

The signal ●●○○ Compiled by AI from Ars Technica and Hacker News
Why you might care

The process for validating domain control for issuing TLS certificates is flawed, allowing impersonation of major online services.

What happened

Attackers successfully compromised three top-level domains (.gh, .sl, and .as) and used this control to issue counterfeit TLS certificates for Google and other major organizations. By manipulating DNS records for selected domains within these country-code top-level domains, the hackers were able to bypass automated validation checks required by certificate authorities. This allowed them to obtain unauthorized certificates for several Google domains and other leading global brands. Google has since updated Chrome to block these illicit certificates and worked with issuing authorities to revoke them. While Google's Chrome users are protected, the company advises domain owners to actively monitor certificate transparency logs and implement restrictive Certification Authority Authorization records to prevent future attacks. The incident did not involve breaches of the affected domain owners' infrastructure, but highlights a vulnerability in the domain registration and certificate issuance process.

What it means

This incident exposes a critical weakness in the domain registration and TLS certificate issuance ecosystem, where control over even a few top-level domains can be leveraged for widespread impersonation. The attack vector, relying on DNS record manipulation, bypasses standard validation procedures, indicating that current security measures are insufficient to prevent sophisticated threats. This compromise affects the trust users place in online communications, as even legitimate-looking connections could be hijacked.

The reliance on browser-side interventions and certificate revocation, while effective for mitigation, highlights a reactive approach to security. Future attacks might exploit undiscovered counterfeit certificates or target certificate authorities directly, requiring a fundamental re-evaluation of how domain control is verified and certificates are issued. Organizations must now consider proactive measures, such as enhanced monitoring and stricter DNS configurations, to safeguard their digital presence and user trust.

AI-written summary. May contain errors.