Hackers have reportedly obtained counterfeit TLS certificates for Google and other major services, raising significant security concerns. This incident, which involved the hijacking of three country code top-level domains (ccTLDs), allowed attackers to manipulate DNS records and issue unauthorized certificates, potentially compromising user security across various platforms.
According to Google, while Chrome implemented measures to identify and block these unauthorized certificates, the complexity of DNS hijacks means that not all affected domains may have been identified. The company emphasized that browser-level interventions should not be solely relied upon for user protection, as undiscovered certificates could still pose a threat. “Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain,” Google stated.
The exact number of unauthorized certificates issued and the full list of affected organizations remain unclear. However, Google confirmed that the incident did not involve any compromise of the infrastructure of the affected domain owners, and that certificate authorities adhered to all necessary protocols. By controlling the ccTLDs, attackers were able to redirect traffic and modify authoritative DNS records, enabling them to pass industry validation checks that typically require proof of domain control.
This incident is not isolated; it echoes past events, such as the 2011 breach of the Dutch certificate authority DigiNotar, which allowed attackers to create counterfeit certificates for Google and over 200 other domains. That breach impacted approximately 300,000 users in Iran. Similar incidents have occurred over the years, often due to failures by certificate authorities or domain holders.
With all known unauthorized certificates now blocked, the immediate risk has been mitigated. However, as Google cautioned, the potential for undiscovered certificates remains a concern, highlighting the ongoing challenges in maintaining secure digital communications.
For further details on the incident, refer to Ars Technica.


