Security/ security · google · dns-hijacking · tls-certificates

Hijacked Domains Let Hackers Forge HTTPS Certificates for Google

Attackers hijacked Ghana, Sierra Leone, and American Samoa's domain systems to mint valid-looking certificates for Google and other major sites.

Someone forged valid HTTPS certificates for Google and other major sites, and Google says it wasn't even the certificate authorities' fault.

Attackers hijacked three country-code top-level domains - Ghana's .gh, Sierra Leone's .sl, and American Samoa's .as - by tampering with their authoritative DNS records. That access let them obtain legitimate-looking HTTPS certificates covering Google properties and services run by other "leading global brands," though Google won't name which ones or say how many organizations were hit. With a valid certificate and control over DNS, attackers could redirect visitors to lookalike sites that still display the padlock icon, harvesting logins and payment details or serving malware. Google blocked the fraudulent certificates in Chrome through CRLSets and pushed the issuing CAs to revoke them, but it warned that users of other browsers may still be exposed.

The padlock icon tells you a connection is encrypted, not that you're talking to who you think you are. Certificate issuance still leans on domain validation, and that validation is only as trustworthy as the DNS registry behind it. A small ccTLD registry for Sierra Leone or American Samoa makes an easier target than a major registrar, yet its domains plug into the same global trust system every browser relies on.

Google points to 2011's DigiNotar breach as the cautionary tale - 531 fraudulent certificates, encrypted traffic of Iranian users intercepted, and a Dutch certificate authority put out of business. This time Chrome's automated defenses kicked in before anyone could prove similar damage, though that claim rests on Google's own account of an incident it still won't fully detail.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →