Attackers compromised three top-level domains to obtain unauthorized TLS certificates for Google and other major organizations, according to a statement from Google on Tuesday. The attackers targeted the .gh, .sl, and .as country code top-level domains (ccTLDs), modifying authoritative DNS records for specific domains within those namespaces. This control allowed them to pass automated domain control validation checks and acquire unauthorized certificates for several Google domains and other prominent global brands and online services.
TLS certificates serve as cryptographic credentials that ensure authentication and encryption for websites, mail servers, and other internet infrastructure. These x.509 certificates bind a domain name, such as google.com, to a public key, with the private key held only by the website operator. When the keys match during a connection, it confirms the authenticity of the site.
Google has updated Chrome to block all identified unauthorized certificates and is collaborating with issuing certification authorities to revoke the unauthorized certificates related to Google properties. However, Google did not specify which domains were affected or name the other organizations involved. While Chrome users do not need to take any action for protection, Google advised domain owners to monitor certificate transparency logs for unexpected certificate issuance and to implement restrictive Certification Authority Authorization DNS records to prevent attackers from reusing cached validation data after DNS control is restored.
Google stated, "While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users." The company acknowledged that due to the complexity of DNS hijacks, it cannot guarantee that all affected domains were identified and that Chrome interventions may not protect non-Chrome users.
The extent of the unauthorized certificates issued and whether all except those for Google domains have been blocked remains unclear. The process for revoking certificates can be slow, prompting browser makers to develop quicker methods to block specific certificates at the browser level. Although all known unauthorized certificates are now blocked, Google warned that undiscovered certificates could still pose a risk.
Google clarified that the incident did not involve compromising the infrastructure of any affected domain owners and that certificate authorities adhered to all necessary requirements. By controlling the three ccTLDs, the attackers could alter the IP addresses of selected websites, enabling them to modify authoritative DNS records and nameserver delegations for those domains, thus passing industry validation checks.
This incident is not the first of its kind; a 2011 breach of the Netherlands-based certificate authority DigiNotar allowed attackers to create counterfeit certificates for Google.com and over 200 other high-traffic domains, affecting approximately 300,000 individuals in Iran who visited the impersonated sites. Similar incidents have occurred since, often due to failures by certificate authorities and domain holders.