Abstract:
Many domain names, including Google, have been hijacked. After the hackers gain control of the domain names, their main behavior is to tamper with DNS records to apply for the issuance of a TLS certificate. Once the certificate is successfully issued, they can point the domain name to the hacker's server and use it for hijacking and traffic decryption. Google revealed in a blog that unauthorized TLS certificates were issued on domain names of multiple organizations, including Google.

Google emphasized that the company's internal system has not been compromised, and there is no reason to believe that the Certificate Authority (CA) that issued the certificate violated relevant procedures, because according to the existing CA procedures, as long as a valid DNS record is added to the domain name, it can prove that the applicant owns the domain name, so the certificate can be issued.
After discovering this incident, Google blocked a large number of identified unauthorized certificates through the Chrome CRLSet mechanism. At the same time, Google contacted the relevant certificate authority to revoke the certificates to protect other browsers and clients. Google then analyzed the certificate transparency logs and found that many global brands and commonly used online services may be affected, so users will also see Chrome's blocking prompts when they visit the corresponding websites.
Google did not disclose the list of affected companies or services and the number of certificates. Google said that DNS hijacking is very complex and cannot guarantee that all affected domain names will be found. Browser-side interception cannot reliably protect non-Chrome users. Users of relevant domain names should check certificates and DNS protection records. If abnormal records are found, they should be deleted in time.
If you use GH, SL and AS domain names, the domain name holder can visit the crt.sh website to query the certificate issued by the corresponding domain name. If you find that there is a certificate that you did not apply for, you should contact the certificate authority as soon as possible to revoke the corresponding certificate to prevent hackers from continuing to use these certificates to hijack users.
Learn more:
https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/
Comments