Hackers Impersonate Google and Other Large Services With Counterfeit TLS Certificates
Attackers were able to compromise three top-level domain registries and mint TLS certificates for Google and other large organizations, allowing them to impersonate legitimate domains.
Google says the domains that were hijacked were country-code top-level domains (ccTLDs), specifically .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). These TLDs are the end of a domain, for example .com or .gov. They are controlled by organizations called domain registries and act as the authoritative database of every domain under their TLD. IANA, run by ICANN, operates as the master list of all TLDs.
Google's systems themselves were not compromised, but these specific ccTLDs were, potentially meaning any domain ending with them could have been impersonated by the attackers.
During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations. Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong.
Google says they immediately acted when they found out about the compromise and blocked the unauthorized certificates using CRLSets in Chrome and worked with the issuing certificate authorities (CAs) so that the certificates could get revoked in other browsers.
Firefox revokes these certificates using their CRLite which is meant to be a more privacy-preserving version. Google can control when they revoke certificates in Chrome but they can't control when other browsers do, so it's possible users in other browsers might be vulnerable longer than Chrome users.
Certificate Transparency (CT) logs revealed that other organizations were also affected including some "global brands and widely used online services." Google says they contacted the organizations to let them know about the attack, although they didn't name them.
Google advised domain owners to monitor CT logs in an ongoing basis for alerts when a certificate is issued to their domains.
They also advised domain owners to publish restrictive Certificate Authority Authorization (CAA) records with ACME account bindings:
Certification Authority Authorization (CAA) DNS records allow domain owners to declare which CAs are permitted to issue certificates for their domains. While CAA can not prevent certificate issuance during an active DNS hijack, it provides a critical safeguard after DNS control is restored, and can prevent some routing-based and HTTP attacks entirely. Because CAs are permitted to cache and reuse completed domain control validation (DCV) checks for subsequent issuance, restoring a restrictive CAA policy, especially one that restricts issuance to specific authorized accounts and validation methods, prevents an attacker from using cached validation state to mint new certificates after a hijack ends.
Attacks like this one show that despite improvements over the years, the security of the web still relies heavily on the security of a few specific entities.
Google says they're still working on several improvements to the HTTPS ecosystem like reducing certificate validity and DCV reuse and the Chrome Quantum-resistant Root Program.
Community Discussion