Skip to content

Security3 publishersIndependently confirmed2 min readPublished

Hijacked .gh, .sl and .as registries handed attackers HTTPS certificates for Google domains

Attackers who hijacked the operators of three country-code domains obtained HTTPS certificates for Google domains, Google disclosed. The company says the issuing CAs did nothing wrong, so its defence came after issuance, and it cannot promise it found every affected domain.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Hijacked .gh, .sl and .as registries handed attackers HTTPS certificates for Google domains
Generated illustration

What happened

  • The .gh, .sl and .as registries were run by third-party operators, and the attackers used that access to change authoritative DNS records for names under those endings.
  • Google blocked the certificates for its own properties in Chrome through CRLSets and worked with the issuing CAs to revoke them for other browsers and clients.
  • Certificate Transparency log data turned up other victims, including large global brands and popular online services, and Google blocked those certificates in Chrome too.
  • Google learned of the hijacks last week and has not said how the registries were breached, who carried it out, or when it began.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Correct CA behaviour did not prevent issuance, so for these names the controls that counted sat with the registry operator and with monitoring after a certificate already existed.
  • decision Owners of names under .gh, .sl and .as are left to search CT logs themselves, since Google's blocks and revocations reach only the certificates it found.
  • precedent Google closed its disclosure with a commitment to shorter certificate validity and less DCV reuse through its root programs, so CAs can expect tighter rules on both.

Google places the failure below the certificate authorities. "Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong," the company said [3]. The attackers held the authoritative DNS records for the names involved [2]. The CAs issued certificates because the attackers controlled those records, and Google says no CA made an error [11].

"These incidents did not involve a compromise of Google's systems," Google said [10]. The attackers got Google's certificates, and the other brands' certificates, by going through registry operators those companies do not run [14]. A registry takeover exposes every name under its ending [2]. An organisation with names under many country endings depends on every one of those registries for its domain-validated certificates. A breach at any one of them is enough to get certificates issued for the names under it [14].

Three registry operators were compromised in one set of incidents, and Google links the other victims it found to the same attacks [15]. On that evidence the attackers got in through the registry operators. Individual brands were not breached [15].

Chrome users are covered for the certificates Google found. "Chrome users do not need to take any action to be protected," Google wrote [5]. The company also said its Chrome interventions do not reliably protect people using other browsers [7]. Outside Chrome, the only remaining defence is CA revocation [16]. "We cannot guarantee that our analysis identified every affected domain," Google said [6]. If its analysis missed a domain, any certificate for that domain is neither blocked in Chrome nor revoked [16].

Google's longer-term answer is root-program policy. "To keep our users safe, we are committed to long-term HTTPS ecosystem improvements, such as reducing certificate validity and DCV reuse, through the Chrome Root Program and the new Chrome Quantum-resistant Root Program," the company said [12]. Both measures are about time limits: how long a certificate stays valid, and how long a CA can reuse an earlier domain control check [17]. Google said it would go on working with others to reduce the harm when DNS or routing is compromised [13].

What to watch

  • Disclosure from the .gh, .sl or .as operators on how they were breached and whether they have confirmed control of their DNS records.
  • New certificates for affected brands appearing in Certificate Transparency logs, or victims Google contacted confirming they were hit.
  • Chrome Root Program proposals that cut certificate validity or DCV reuse periods and cite these hijacks.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories