Attackers obtained counterfeit TLS certificates for several Google domains and for other major global brands and widely used online services by hijacking country code top-level domains, Google disclosed. The company said it updated its Chrome browser to block every unauthorized certificate it identified and worked with the issuing certification authorities to have the certificates covering Google properties revoked. Google did not name the specific domains it owns that were affected, nor did it identify the other organizations involved.

According to Google, the attackers first targeted the .gh, .sl and .as ccTLDs and then altered authoritative DNS records for chosen domains inside those namespaces. That control let them clear the automated domain control validation checks that certificate authorities require, and certificates were issued as a result. Google said the episode did not involve any compromise of the affected domain owners' own infrastructure, and that the certificate authorities followed all applicable requirements. By taking over the three ccTLDs, the attackers could change the IP addresses of a selected set of websites and modify authoritative DNS records and nameserver delegations, which allowed them to demonstrate domain control.

TLS certificates are the cryptographic credentials behind authentication and encryption for websites, mail servers and other Internet infrastructure. Each x.509 certificate uses a digital signature to bind a domain name, such as google.com, to a public key. The public key is openly available, while the private key stays with the site operator, so a matching pair tells a visitor the connection is to the authentic site and not an impostor. Anyone holding unauthorized certificates can cryptographically impersonate the affected infrastructure.

Google said Chrome users do not need to take any action to be protected, but it warned domain owners against depending only on browser-side fixes. It advised them to watch certificate transparency logs for unexpected issuance across their domains and to publish restrictive Certification Authority Authorization DNS records so attackers cannot reuse cached validation data after DNS control is restored. Google also said that because DNS hijacks are complex, it cannot guarantee its analysis caught every affected domain, and that Chrome interventions do not reliably protect users of other browsers.

It is not immediately clear which other organizations were affected, how many unauthorized certificates were issued, or whether all of them other than those for Google domains have been blocked. Revoking certificates through the official process is slow and cumbersome, so browser makers have built faster ways to block specific certificates at the browser level. With all known unauthorized certificates now blocked, the immediate risk is reduced, but Google noted that any certificates still undiscovered remain a threat.

Unauthorized certificates have been obtained by threat actors before. A 2011 hack of the Netherlands-based certificate authority DigiNotar let attackers mint counterfeit certificates for Google.com and more than 200 other high-traffic domains, which were then used against at least 300,000 people with ties to Iran as they browsed the impersonated sites. Many similar incidents have followed, most often traced to failures by certificate authorities but sometimes to domain holders.

More cybersecurity news from TechManNews.