-
Attackers hijacked some domain systems and obtained unauthorized HTTPS certificates for Google domains and other organizations.
-
Google confirmed that the breach did not result in the compromise of any of its resources, as Chrome identified and blocked fake certificates relating to Google websites.
-
Every website owner needs to check Certificate Transparency logs, examine DNS configuration, and utilize CAA records to minimize the chances of attacks.
Criminals hijacked the domain registration systems of Ghana, Sierra Leone, and American Samoa. They changed DNS records and obtained HTTPS certificates for major brands, including several Google domains.
Google confirmed the incidents and said they did not involve a breach of its own systems. Instead, the attackers targeted the country-code domain systems and created risks for websites using the affected extensions. Chrome has blocked unauthorized certificates linked to the incident.
Attackers target three country-code domain systems
The attack affected three country code Top-Level Domains (ccTLDs) – .gh, .sl and .as. These country code extensions stand for Ghana, Sierra Leone and American Samoa.
A ccTLD provides websites with an ending associated with a specific country or region. For instance, a company from Ghana may end its website address with .gh. The firms and groups can utilize the same TLD to reach customers within the local region.
But if attackers get hold of the systems responsible for assigning TLDs, serious problems may arise. Google reported that the recent attacks permitted attackers to change the DNS records inside the affected name-space.
The DNS system is responsible for the browsers connecting to servers that host websites. It converts the domain name into the IP address that computers use for connection. When the attackers alter it, they can change where each domain leads visitors.
According to the security update of Google, the attackers can access HTTPS certificates that cover several Google domains and websites belonging to other organizations. This new trend raises concerns in security – this is because browsers depend on these certificates to help establish secure connections.
Unauthorized certificates created a security risk
HTTPS certificates allow browsers to verify whether the website users visit controls the corresponding domain. Furthermore, they provide the needed encryption and establishment of secure communications between websites and users. Their operations allow protection against unauthorized access from any outsiders trying to read or change information that moves within a network.
A legal certificate, however, doesn’t mean that a website is trustworthy – rather, it shows the establishment of the connection between a domain and its public key. Browsers use this information while deciding to turn on secure communications.
According to the reports, the attackers took over the controls of the domain systems to obtain certificates for domains without ownership. That’s important as browsers normally trust certificates coming from recognized Certificate Authorities (CAs).
Certificate Authorities provide certificates only after making sure that candidates are eligible for the certificate and meet the control conditions. In this case, Google said it had no reason to believe the CAs involved had acted improperly. The control of the attackers over the affected DNS systems created the conditions for the unauthorized issuance.
As a result, the incident highlights a weakness that can emerge when attackers compromise the infrastructure used to verify domain ownership. Even well-known organizations can face risks when another part of the internet’s trust system comes under attack.
Other website incidents have also required organizations to revise their initial understanding of what went wrong, as seen in the Nextcloud breach, which initially blamed an infrastructure issue.
Chrome blocks the unauthorized certificates
Google said Chrome moved quickly to protect users after discovering the domain hijacks. The browser blocked unauthorized certificates covering Google properties through its CRLSet mechanism.
CRLSets authorizes Chrome to share information regarding certificates that the browser has to reject. Through this approach, Google can block any known problematic certificate without having to wait for an affected website owner to resolve the incident independently.
Therefore, Chrome users should benefit from this browser-level response when they encounter certificates covered by the block. However, the action does not mean attackers compromised Google’s internal systems. Google made it clear that the attack was only on the domain registry and did not impact Google or its infrastructure.
This incident also illustrates that good browser security goes beyond simply having a strong password or secure code for the website. Domain registries, DNS providers, certificate authorities, and browsers have different support individually in providing web security.
If an attacker breaches one aspect of the web security system, this could affect other companies that depend on it. This means that the involvement of browser builders, domain operators, certificate authorities plus affected web owners is imperative for coordination of the response.
What website owners should do next?
According to Google, organizations should keep an eye on their Certificate Transparency logs to look out for any unexpected certificate activity. These public logs contain information about certificates issued for websites and would enable the owners of domains to identify certificates they did not request.
Organizations should assess all their domains, even the ones that have less frequent usage. A forgotten or unused domain can still create vulnerabilities for a firm. This is because criminals may target it to obtain the certificate or DNS details.
Google also suggested that organizations can use restrictive Certificate Authority Authorization (CAA) records. These DNS records tell certificate authorities which issuers a domain owner permits to issue certificates for its domains.
CAA records can reduce some certificate-related risks. However, they cannot prevent every attack during an active DNS hijack. Google pointed out that CAs may sometimes repeat domain verification checks used in the past. Thus, owners of affected domains should review their policies related to CAA after regaining access to their sites.
Country-code domain registration organizations under the reported regions should be more careful regarding recent certificate records. They must verify the DNS settings of their systems and ensure that only authorized parties will manage their infrastructure.
The incident itself contains a more general lesson for the internet security world. In particular, organizations must monitor their certificates and DNS records continuously, instead of thinking that the website is safe simply because it is working.