Hackers obtain counterfeit TLS certificates for Google and other major services

“While Chrome has taken steps during these incidents to identify and block suspected unauthorized certificates in the affected ccTLDs, you should not rely on browser-side intervention to protect your users,” Google said. “Due to the complexity of DNS hijacking, we cannot guarantee that our analysis identified all affected domains, and Chrome interventions do not reliably protect non-Chrome users.”

It was not immediately clear which other organizations were affected, how many unauthorized certificates were issued or whether all but those for Google domains were blocked. The process of officially revoking certificates is slow and tedious, so browser manufacturers have designed faster methods to block specific certificates at the browser level. With all known unauthorized certificates now blocked, the risk is mitigated, but as Google noted, any undiscovered certificate poses a threat.

Google noted that the incident did not involve a compromise of the infrastructure of any of the affected domain owners and that the certificate authorities met all requirements. By controlling the three ccTLDs, the attackers were able to change the IP addresses of a selected list of websites. With the ability to send and receive traffic to these sites, the attackers were able to modify authoritative DNS records and name server delegations for selected domains, allowing them to pass industry validation checks requiring an applicant to prove control of the domain.

This is not the first time malicious actors have obtained unauthorized certificates. In 2011, a hack of Dutch certificate authority DigiNotar allowed attackers to create counterfeit certificates for Google.com and more than 200 other high-traffic domains. The certificates were used against at least 300,000 people with ties to Iran as they browsed sites spoofed by the fake certificates. Many similar incidents have occurred since then, most often due to failures of certification authorities but also of domain holders.

Gn tech

Scroll to Top