← Back to the feed

Attackers exploit three country-code domains to obtain fraudulent TLS certificates

Ars Technica ·

Attackers took control of three country-code top-level domains, .gh, .sl and .as, and used changes to DNS records to obtain counterfeit TLS certificates for several Google domains and other major online services. The certificates could allow the affected sites’ infrastructure to be impersonated, undermining the authentication and encryption that TLS provides.

Google says Chrome now blocks all the unauthorised certificates it has identified, and certificates for Google properties have been revoked. The other affected organisations and domains, and the total number of certificates, remain unknown; Google warns that some may have gone undetected. It recommends that domain owners monitor certificate transparency logs and publish restrictive Certification Authority Authorisation records.

  • Attackers used control of three domain registries to obtain counterfeit certificates.
  • Chrome blocks the certificates Google has identified.
  • Domain owners are urged to monitor logs and restrict certificate issuance.

New here? Start with this

TLS certificates are digital credentials that secure your connection to websites. When you visit a major service like Gmail or Google Search, your browser checks the site's TLS certificate to verify that you are connecting to the real service, not to an impostor. This protects your data from interception and prevents criminals from stealing information passing between you and the site.

Each country has an internet domain extension of its own, such as .uk for the United Kingdom or .de for Germany. Attackers gained control of the registries that manage three of these country domains: .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). With access to these registries, the attackers convinced the organisations that issue TLS certificates that they had authority over these domains and obtained fraudulent certificates for Google and other major services.

With forged TLS certificates, attackers could impersonate these major services and intercept traffic sent by users, potentially stealing sensitive data. The breach shows that a critical part of internet security depends on the integrity of country-level domain registries. The full number of affected organisations and fake certificates created remains unknown.

Cybersecurity Technology

Read the full article at the source →

Originally published by Ars Technica as “Hackers obtain counterfeit TLS certificates for Google and other large services”.