Google says hackers have stolen counterfeit TLS certificates from major services
- Attackers hijacked three country code domains to obtain fraudulent HTTPS certificates for major websites
- Fake certificates could allow convincing interception of traffic and phishing against affected domains
- Google revoked certificates, protected Chrome users and warned affected organizations
Recently, cybercriminals managed to hijack three country code top-level domains (ccTLDs) and used the access to generate HTTPS certificates covering several Google domains, as well as those belonging to other organizations. Google said the attack put thousands of websites at risk, but noted that the certificates have since been revoked.
According to Google, the hijacked domains are .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). During the attacks, threat actors modified authoritative DNS records and obtained HTTPS certificates covering not only Google, but other organizations as well.
In other words, any website operating on these domains was at risk, as were all visitors. By manipulating authoritative DNS records, threat actors could redirect traffic from legitimate websites to malicious sites under their control, while telling users that they were visiting the legitimate site by displaying the lock icon. Visitors entering login credentials, payment information, or other data would easily lose it to attackers and, depending on the circumstances, could also end up installing malware.
Latest videos ofTechnologyRadar
“Due to the nature of the attacks, we have no reason to believe that the certification authorities (CAs) that issued the affected certificates did anything wrong,” Google said.
Affecting the main brands
Although Google blocked unauthorized certificates in Chrome and worked to revoke them, it warned that its interventions may not have identified all affected domains or protected users of other browsers.
“As part of our regular incident response process, we acted immediately to protect users by blocking the use of unauthorized certificates for Google properties in Chrome through CRLSets,” Google added. “We also worked with issuing CAs to ensure certificates were revoked to protect users on non-Chrome clients.”
The risk to the websites was not theoretical. Google said that “several leading global brands and widely used online services” were affected by these attacks and emphasized that all certificates used in these attacks were blocked.
“Wherever possible, we reached out to affected organizations to alert them to our findings and actions,” Google concluded. The company did not say which of its domains were affected and declined to name the victim companies. We also do not know how many organizations were affected.
It was said that Chrome users don’t need to take any action to be protected, but domain owners do have a couple of things to do. That includes continuously monitoring certificate transparency for all domains and publishing restrictive CAA records with ACME account links.
It’s not the first rodeo
Attacks like this have happened before: In 2011, cybercriminals compromised Dutch certification authority DigiNotar, generating 531 fraudulent certificates for domains belonging to Google, Microsoft, Mozilla, Skype, and more. Some of these certificates were allegedly used to intercept encrypted communications from Iranian Internet users, and the incident ultimately forced major browser vendors to withdraw their trust in DigiNotar, putting the company out of business.
Earlier that year, threat actors stole an account belonging to a registration authority associated with Comodo, obtaining nine fraudulent certificates for domains operated by Google, Yahoo, Microsoft and others. Something similar happened in 2015, when Google discovered that Symantec’s Thawte Certification Authority had incorrectly issued an unauthorized certificate during internal testing, covering Google domains.
This incident, however, was more of an internal failure and less of an attack. Subsequent investigations uncovered numerous additional incorrectly issued certificates.
“In parallel with domain owners’ defenses, we will continue to work together with the broader community to limit the impact of transient routing and DNS compromises on web security,” Google concluded. “To keep our users safe, we are committed to long-term improvements to the HTTPS ecosystem, such as reducing certificate validity and DCV reuse, through the Chrome Root Program and the new Quantum-resistant Chrome Root Program.”
Through Ars Technique
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment