TechRadar News.
Technology

Google says hackers forged TLS certificates after seizing country‑code domains

Google says hackers forged TLS certificates after seizing country‑code domains

On Tuesday, Google announced that attackers had succeeded in acquiring fake HTTPS certificates for a number of high‑profile web services by taking control of three country‑code top‑level domains.

They hijacked the registration flow for the compromised domains, causing certificates that seemed to be issued by trusted certificate authorities to be generated. Possessing such certificates would have allowed the threat actors to launch man‑in‑the‑middle attacks or create persuasive phishing sites that could evade standard browser alerts.

In response, Google’s security team revoked the bogus certificates and released Chrome updates that prevent any connections employing them. Consequently, browser users were protected from possible interception automatically, without any required action on their part.

The firm explained that the hijacked domains were not owned by the affected services themselves; instead, they served as intermediaries to meet the "domain‑validation" criteria used by many public CAs. By seizing control of the DNS entries for those three country‑code domains, the attackers were able to pass the validation process and acquire legitimate‑looking certificates.

Security experts point out that this episode highlights the persistent danger associated with domain‑validation certificates, which depend on proving domain control rather than conducting thorough identity checks. Although these certificates allow fast issuance for genuine sites, they become exploitable when an attacker commandeers an unrelated domain.

Google has cautioned fellow browser makers and certificate‑authority operators to examine comparable requests closely and to contemplate extra protections, like tighter validation for high‑value domains. It also advised organizations to keep an eye out for any unauthorized certificates issued under their brand names.

This incident arrives amid a wider surge of supply‑chain and credential‑theft attacks, serving as a reminder to enterprises that even peripheral assets such as country‑code domains can serve as conduits for large‑scale credential fraud.

Source: TechRadar
TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related