Hackers hijack three country-code domains to forge Google security certificates
Google said attackers took control of the .gh, .sl and .as domain registries and used them to obtain unauthorized HTTPS certificates for several Google domains and other organisations. Google said its own systems were not breached and that Chrome now blocks the rogue certificates, but other browsers may remain exposed longer. The episode shows how weaknesses in domain infrastructure, not just certificate authorities, can undermine the trust behind every padlock icon.
Bottom line — Google has not named the other affected organisations or the attackers, so the full scope of the certificates remains unknown.
Go deeper 9
-
Google said it learned of the attacks the week before its October 6 disclosure and did not say how the registries were compromised or who was behind them.
-
The .gh, .sl and .as domains belong to Ghana, Sierra Leone and American Samoa, and Google said any domain under those endings could have been put at risk.
-
According to Google, attackers changed authoritative DNS records, which let them pass the domain-control checks certificate authorities use before issuing a certificate.
-
Google said the certificate authorities involved had no reason to be blamed, since the attack exploited DNS control rather than a breach of their own systems.
-
Ars Technica and Help Net Security both note Chrome blocked the certificates through CRLSets, while Google worked with issuers to revoke them for other clients.
-
Privacy Guides reports that Firefox revokes these certificates through its CRLite mechanism, meaning users of other browsers may be exposed for longer than Chrome users.
-
Google recommends monitoring Certificate Transparency logs and publishing restrictive CAA records, though it warned CAA cannot stop issuance during an active DNS hijack.
-
The Register and Ars Technica both recall the 2011 DigiNotar breach, which produced fraudulent certificates for Google and over 200 other domains; Ars Technica reports they were used against at least 300,000 people with ties to Iran.
-
Google said it cannot guarantee it identified every affected domain, and that Chrome's protections do not reliably cover non-Chrome users.