Three country domains hijacked to mint rogue Google certificates

Contents

Plenty went wrong in security this week: Oracle Health/Cerner, the Danish CPR registry, ASOS, a FortiGate mass compromise, Atlassian bugs exploited within hours of a PoC. The one I keep thinking about is quieter, because it attacks something most of us treat as solved.

On 6 October, Google disclosed that attackers had hijacked three country-code TLDs (.gh for Ghana, .sl for Sierra Leone and .as for American Samoa) and used that control to get TLS certificates they should never have had. Google says its own systems were not breached.

How it works

Certificate authorities have to check that you control a domain before they issue a certificate. The common checks are DNS and HTTP challenges. If you control the DNS for a domain, you can pass them.

The attackers apparently didn’t go after Google. They went after the registries above it. By changing DNS records for chosen sites, they could answer validation challenges for domains they don’t own and walk away with valid-looking certificates for Google properties and other large brands.

The whole TLS trust chain was working as designed. The weak link was the DNS underneath it.

What the response looked like

  • Google blocked the certificates in Chrome through CRLSets.
  • CAs revoked the certificates.
  • Google warned it may not have found every affected domain, and that other browsers may not be covered by its block.

CRLSets is a Chrome mechanism. If you rely on Firefox, Safari, curl, or an app with its own trust handling, you depend on revocation actually reaching you, and revocation has always been the shaky part of the web PKI.

What I’d do about it

  1. Publish CAA records for your domains, so only the CAs you actually use can issue for you. It won’t stop a registry-level attacker who can also edit your CAA records, but it narrows the easy paths.
  2. Watch Certificate Transparency logs for your domains. A certificate you didn’t request is the clearest early signal of this class of attack.
  3. Lock down your registrar and DNS accounts with MFA and registry lock where it’s offered. Your TLS security is only as good as whoever can change your DNS.
  4. Don’t assume revocation protects you. Short-lived certificates limit how long a rogue one stays useful.

This is a reminder that “we have HTTPS” is a claim about DNS as much as about cryptography.

Details here come from Google’s disclosure as reported by the press. I’ve not independently verified the full list of affected brands.