← Back to stories
Security

Hackers obtain counterfeit TLS certificates for Google and other large services

Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday.

The attackers launched a series of attacks on the.gh,.sl, and.as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.” Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.

Certificate issuance: The weak link in the chain

TLS certificates are the cryptographic credentials that underpin authentication and encryption protections for websites, mail servers, and other Internet infrastructure. …

You're reading a preview. The full article is published by Ars Technica on their website.

Read the full story on Ars Technica