Urgent.News

What's breaking now, across thousands of outlets.

Tech

Chrome's Response to Recent ccTLD Registry Hijacks

Over the past week, a number of domain hijacks were detected in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level domains. These attacks were not caused by a breach in Google's infrastructure, but by hackers taking control of the third-party ccTLDs, thus putting domains ending in .gh, .sl, or .as at risk.

In the course of these incidents, the hijackers manipulated authoritative DNS records and acquired unauthorized HTTPS certificates for several Google domains, as well as domains belonging to other entities. The root cause of the attacks could not be traced back to the Certification Authorities (CAs) that issued the compromised certificates.

In response, our usual incident response protocols were swiftly enacted to defend users. This involved blocking the use of unauthorized certificates for Google properties within Chrome through CRLSets, and ensuring the revoked certificates protected users in other web clients. Following this initial mitigation, data from Certificate Transparency (CT) logs indicated that additional organizations, comprising several major global brands and extensively used online services, were potentially affected by the same attacks.

To mitigate any potential harm to those websites, we took proactive measures to block these certificates in Chrome. Where feasible, we reached out to the impacted organizations to inform them of our findings and actions. Users of Chrome do not require any additional actions to remain protected. However, to safeguard their own domains and users, domain owners are advised to take proactive measures.

While Chrome's measures during the incidents have helped identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side interventions should not be solely relied upon for user protection. Due to the intricate nature of DNS hijacks, our analysis might not have identified all affected domains, and our Chrome interventions may not reliably ensure protection for non-Chrome users.

It is crucial for domain owners to be the most knowledgeable about the authorized certificates and CAs for their namespaces. We strongly recommend that organizations implement the following protective steps. In tandem with these defensive measures, we will continue to collaborate with the wider community to minimize the impact of transient routing and DNS compromises on the security of the web.

Our commitment remains steadfast towards long-term improvements in the HTTPS ecosystem, such as shortening certificate validity and preventing certificate validity reuse, through the Chrome Root Program and the newly introduced Chrome Quantum-resistant Root Program.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at blog.google →

More in Tech

More from Tuesday 6 October →