Google says hackers obtained bogus TLS certificates by hijacking country-code domains
On Tuesday, Google announced that attackers succeeded in acquiring fake HTTPS certificates for a number of prominent web services after taking control of three country‑code top‑level domains.
They hijacked the registration workflow for the compromised domains, causing certificates that looked as if they were issued by trusted certificate authorities to be generated. Possession of such certificates would have enabled threat actors to launch man‑in‑the‑middle attacks or to build believable phishing sites that evade standard browser alerts.
In response, Google’s security engineers revoked the bogus certificates and released Chrome updates that prevent any connections employing them. Consequently, browser users were protected from possible interception automatically, without any required steps.
The firm explained that the hijacked domains were not owned by the affected services; instead, they served as intermediaries to meet the “domain‑validation” criteria used by many public CAs. Controlling the DNS entries of those three country‑code domains allowed the attackers to pass the validation tests and secure legitimate‑appearing certificates.
Specialists point out that this case highlights the persistent danger associated with domain‑validation certificates, which depend only on demonstrating control of a domain instead of thorough identity checks. Although these certificates facilitate quick issuance for bona‑fide sites, they become exploitable when an adversary seizes a seemingly unrelated domain.
Google has cautioned fellow browser makers and certificate‑authority operators to examine comparable requests closely and to contemplate extra protections, like tighter validation for high‑value domains. It also advised companies to keep watch for unauthorized certificates bearing their brand names.
The incident occurs amid a larger surge of supply‑chain and credential‑theft attacks, serving as a reminder that even peripheral assets such as country‑code domains can serve as pathways for widespread credential fraud.
Comments (0)
Be the first to comment.
Join the discussion