HeadlinesBriefing HeadlinesBriefing.com

Hackers obtain counterfeit TLS certificates for Google

Ars Technica •
×

Hackers obtained counterfeit TLS certificates for Google and other large services by gaining control of three country-code top-level domains (ccTLDs), enabling them to modify DNS records and pass domain validation checks. Google stated that while Chrome took steps to block suspected unauthorized certificates, browser-side intervention should not be relied upon.

It is unclear how many unauthorized certificates were issued or if all but those for Google domains have been blocked. The affected domain owners' infrastructure was not compromised, and certificate authorities followed all requirements. With control of the three cc TLDs, attackers changed IP addresses and modified DNS records for selected domains.

This isn't the first such incident. A 2011 hack of Netherlands-based certificate authority Digi Notar allowed attackers to mint counterfeit certificates for Google.com and over 200 other domains, affecting at least 300,000 people in Iran. Similar incidents have occurred since, often due to failures by certificate authorities or domain holders.

Source: Ars Technica · Summarized by HeadlinesBriefing