Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday.
The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified the DNS records for selected domains the registries issued. With the ability to receive and send traffic from those domains, the attackers created unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.” Google said it updated Chrome to block all certificates it has identified as counterfeit and worked with other certificate authorities to ensure other browsers did the same.
Certificate issuance: The weak link in the chain
TLS certificates are the cryptographic credentials that underpin authentication and encryption protections for websites, mail servers, and other Internet infrastructure. These x.509 certificates use a digital signature to bind an identity, such as Google, to a public key. The certificate is also bound to a specific domain belonging to the identity. The public key is publicly available, while the private key is held only by the website operator. When a connection shows that the keys match, the visiting party knows it’s connected to the authentic site rather than an impostor. Possession of unauthorized certificates allows attackers to cryptographically impersonate the affected infrastructure.
Google didn’t identify the affected domains it owns or name any of the other organizations whose domains were affected. It went on to caution both browser users and domain owners that it can’t be certain it has found all counterfeit certificates. The company is advising domain owners to check TLS transparency logs for the issuance of any certificates for site addresses they own.
“While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users,” Google said. “Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.”
It’s not immediately clear what the other affected organizations are, how many unauthorized certificates were issued, or if they have been revoked. The process for officially revoking certificates in browsers is slow and cumbersome, so certificate authorities and other stakeholders have devised a quicker method to block specific certificates at the browser level. With all known unauthorized certificates now blocked, the risk is mitigated, but as Google noted, any certificates that remain undiscovered pose a threat.
Google noted that the incident didn’t involve the compromise of the infrastructure of any of the affected domain owners or the DNS operators. With control of the three ccTLDs, the attackers were able to change the IP addresses of a selected list of websites. With the ability to send and receive traffic on those sites, the attackers were able to pass CA tests requiring an applicant to prove it has control of the underlying domain.
This isn’t the first time threat actors have managed to obtain unauthorized certificates. A 2011 hack of Netherlands-based certificate authority DigiNotar allowed attackers to mint counterfeit certificates for Google.com and more than 200 other high-traffic domains. The certificates were used against at least 300,000 people with ties to Iran as they browsed the sites impersonated by the forged certificates. There have been many similar incidents since, most often through failures by certificate authorities but also domain holders.







