Hackers forge TLS certificates for Google and other major services
Hackers have managed to obtain fraudulent TLS certificates for Google and other major services by exploiting control over three country-code top-level domains (ccTLDs). The attackers altered IP addresses of selected websites, allowing them to pass certification authority (CA) tests and issue unauthorized certificates. Google noted that while Chrome took steps to block these certificates, browser-side interventions are not a reliable long-term solution, especially for non-Chrome users.
The full extent of the affected organizations and the number of unauthorized certificates issued remains unclear. The process for revoking certificates is slow, so stakeholders have implemented quicker browser-level blocks. However, any undiscovered certificates could still pose a security threat. Google clarified that the incident did not involve a compromise of the infrastructure of the affected domain owners or DNS operators.
This is not the first time such an attack has occurred. In 2011, a hack of the certificate authority DigiNotar allowed attackers to forge certificates for Google.com and over 200 other domains. Those certificates were used in targeted attacks against at least 300,000 people with ties to Iran. Similar incidents have happened due to failures by certificate authorities or domain holders.