Google Chrome blocks rogue certificates after ccTLD hijacks in Ghana, Sierra Leone, American Samoa
in plain words
Hackers broke into the systems running three country domain extensions - Ghana's .gh, Sierra Leone's .sl, and American Samoa's .as - and used that access to get fake security certificates for websites, including Google's. Chrome, Google's web browser, quickly blocked those fake certificates to keep users safe. Google says people do not need to do anything, but website owners should watch for suspicious certificates issued in their name.
Google's Chrome Secure Web and Networking Team says it detected a series of domain hijacks last week affecting three country-code top-level domains: .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). The team states the incidents stemmed from compromises of the third-party ccTLD manager The organization that runs a country code top-level domain. Full definition of ccTLD manager themselves, not any breach of Google's own systems. Attackers reportedly altered authoritative DNS record One entry in a DNS zone, made of a name, a type, a TTL and data. Full definition of DNS record for these namespace The set of all names in one naming system, such as the DNS. Full definition of namespace and used that access to obtain unauthorized HTTPS Hypertext Transfer Protocol Secure The encrypted version of the protocol web browsers use to load pages. Full definition of HTTPS certificates covering various Google domains along with domains belonging to other organizations. Google says it has no reason to suspect wrongdoing by the certificate authorities that issued the fraudulent certificates, since the attacks exploited registry-level DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS control rather than CA failures.
As part of standard incident response, Chrome blocked the unauthorized certificates for Google properties using its CRLSets mechanism, and separately coordinated with the issuing CAs to get the certificates revoked so that browsers other than Chrome would also be protected. After this initial response, analysis of Certificate Transparency log data turned up further organizations apparently hit by the same campaign, including what Google describes as several major global brands and widely used online services. Chrome proactively blocked those certificates too and attempted to notify the affected organizations directly.
Google states that Chrome users need take no action themselves, since the browser's protections apply automatically. However, the company stresses that browser-level blocking should not be treated as a substitute for domain owners securing their own certificates, since its analysis may not have caught every affected domain and Chrome's interventions do not help users of other browsers.
Google recommends that organizations continuously monitor Certificate Transparency logs across their entire domain portfolio A collection of domains held by one owner. Full definition of portfolio, including parked or regional ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD properties, and specifically check for unexpected certificate issuance if they operate domains under .gh, .sl, or .as. It also urges publishing restrictive CAA record Certification Authority Authorization A DNS record listing which certificate authorities may issue certificates for a domain. Full definition of CAA record (Certification Authority Authorization) records with ACME account bindings, which limit which CAs can issue certificates and can block attackers from exploiting cached domain validation after control of DNS is restored. Google adds that it will keep working with the wider web community on longer-term fixes, such as shortening certificate validity periods and limiting reuse of domain control validation, through its Chrome Root Program and the newer Chrome Quantum-resistant Root Program.