AI News Feed
Market watch
Cybersecurity

Google says attackers hijacked three country-code domains to issue fake HTTPS certificates

Google says hackers hijacked three country-code domains to issue fake HTTPS certificates for sites, then revoked them.

The hijacked domains were .gh for Ghana, .sl for Sierra Leone and .as for American Samoa, according to Google. The attackers modified authoritative DNS records, which allowed them to obtain HTTPS certificates covering not only Google but also other organizations. Any website operating on those domains, and its visitors, was at risk.

By manipulating authoritative DNS records, the attackers could redirect traffic from legitimate sites to malicious ones under their control while still showing visitors the padlock icon associated with HTTPS. Visitors who entered login credentials, payment information or other data could lose it to the attackers, and depending on the circumstances they could also end up installing malware.

Google said it had no reason to believe the certification authorities that issued the affected certificates did anything wrong. The company said it immediately blocked use of unauthorized certificates for Google properties in Chrome through CRLSets and worked with the issuing CAs to ensure the certificates were revoked to protect users of clients other than Chrome.

Google warned that its interventions might not have identified every affected domain or protected users of other browsers. It said several leading global brands and widely used online services were affected, and that all certificates used in the attacks were blocked. Where possible, Google reached out to impacted organizations to alert them. Google did not say which of its own domains were affected, did not name victim companies, and did not disclose how many organizations were impacted.

Chrome users do not need to take action to be protected, according to Google. Domain owners, however, should perform ongoing monitoring of Certificate Transparency for all their domains and publish restrictive CAA records with ACME account bindings. Google also said it will continue working with the broader community to limit the impact of transient routing and DNS compromises on web safety, and it committed to long-term HTTPS ecosystem improvements, such as reducing certificate validity and DCV reuse, through the Chrome Root Program and the new Chrome Quantum-resistant Root Program.

Similar attacks have occurred before. In 2011, cybercriminals compromised Dutch certificate authority DigiNotar and generated 531 fraudulent certificates for domains belonging to Google, Microsoft, Mozilla, Skype and others. Some of those certificates were allegedly used to intercept encrypted communications of Iranian internet users, and the incident ultimately forced major browser vendors to withdraw trust in DigiNotar, putting the company out of business. Earlier that year, attackers stole an account belonging to a registration authority partnered with Comodo and obtained nine fraudulent certificates for domains operated by Google, Yahoo, Microsoft and others. In 2015, Google discovered that Symantec's Thawte-branded certificate authority had improperly issued an unauthorized certificate during internal testing covering Google's domains; that incident was more of an internal failure than an attack, and subsequent investigations uncovered numerous additional misissued certificates.