Hackers obtain counterfeit TLS certificates for Google and other large services
Compromise of 3 domain registries allows hackers to walk off with unauthorized certs.
Hackers infiltrated three top-level domains, .gh, .sl, and .as, to create counterfeit TLS certificates for prominent companies and websites, including Google, according to Google's announcement on Tuesday. The cybercriminals manipulated the authoritative DNS records for specific domains within these namespaces, enabling them to bypass automated domain control validation checks and obtain unauthorized certificates.
Google swiftly responded by updating Chrome to block all certificates identified as unauthorized and collaborated with the issuing certification authorities to ensure the fraudulent certificates for Google's properties were revoked. The incident underscores the vulnerability of the TLS certificate system, which serves as the cryptographic credentials that authenticate websites, mail servers, and other internet infrastructure.
The vulnerability lies in the x.509 certificates, which utilize a digital signature to link a domain name (e.g., google.com) to a public key. The public key is openly accessible, while the private key is exclusively held by the website operator. Unauthorized certificates enable attackers to cybernetically impersonate the targeted infrastructure, compromising the security and trust inherent in online communication.
Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.