Hackers Forge TLS Certs for Google via DNS Hijack
Original: Hackers obtain counterfeit TLS certificates for Google and other large services
Why This Matters
Shows that CA validation systems remain vulnerable when DNS infrastructure is compromised.
Attackers hijacked three country-code top-level domains (.gh, .sl, .as) to manipulate DNS records, pass domain validation checks, and mint unauthorized TLS certificates for Google and other major services, Google disclosed Tuesday.
Three country-code top-level domains — .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) — were compromised by attackers who then altered authoritative DNS records for targeted domains within those namespaces. With DNS control in hand, the attackers sailed through automated domain control validation and obtained counterfeit TLS certificates for 'several Google domains' and unnamed 'leading global brands and widely used online services.'
TLS certificates are the backbone of web authentication, binding a domain name to a public key via a digital signature. Unauthorized possession lets attackers cryptographically impersonate legitimate infrastructure — intercepting or spoofing encrypted traffic without tripping browser warnings.
Google updated Chrome to block all identified unauthorized certificates and worked with issuing certificate authorities to revoke those tied to its own properties. Chrome users require no manual action. However, Google acknowledged gaps: 'Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.'
Google is advising domain operators to monitor Certificate Transparency logs for unexpected issuance and to publish restrictive CAA (Certification Authority Authorization) DNS records. The company did not name affected third-party organizations or disclose the total number of rogue certificates issued.