Computers

Google: Hackers Hijacked .GH, .SL, .AS Domains via Registry Breach

Google says attackers compromised third-party registry operators to hijack Google domains and obtain unauthorized HTTPS certificates, which Chrome has blocked.

Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the .GH, .SL, and .AS country-code top-level domains after compromising third-party operators and modifying authoritative DNS records, Google has disclosed. According to bleepingcomputer.com, the attacks did not involve a compromise of Google's own systems.

Google said it blocked the unauthorized certificates for its properties in Chrome through CRLSets, its certificate revocation mechanism, and worked with the issuing authorities to revoke them.

After examining Certificate Transparency logs, Google said it blocked additional certificates connected to the attacks and notified affected organizations where it could identify them.

Google cautioned that CRLSets only protect Chrome users, and that it cannot guarantee its analysis identified every affected domain.

Scope of the response

The disclosure points to abuse of the certificate authority and DNS pipeline rather than any flaw in Google's infrastructure. The company has not said how many organizations were affected beyond those it was able to notify.

Quick answers

Were Google's own systems compromised in the attack?

No. Google said the attacks did not involve a compromise of its systems.

How did Google block the unauthorized certificates?

Google blocked the unauthorized certificates for its properties in Chrome through CRLSets and worked with the issuing authorities to revoke them.

Does the CRLSets block cover all users?

No. Google warned that CRLSets only covers Chrome users.

Source