4 min Security

Hackers obtain HTTPS certificates for Google

Hackers obtain HTTPS certificates for Google

Attackers have managed to obtain valid HTTPS certificates for domains belonging to Google and other organizations. They did not need to breach the systems of the affected companies to do so.

By compromising the DNS infrastructure behind three country-code top-level domains, they were able to impersonate the legitimate administrators of websites. Google has since taken measures to prevent misuse of the certificates in Chrome.

The attacks targeted the domain registries of Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as), reports The Register. There, the attackers were able to modify authoritative DNS records. This allowed them to redirect internet traffic to servers they controlled.

The problem was not limited to the DNS infrastructure. Thanks to the altered records, the attackers were also able to prove control over domains to certificate authorities. These authorities then issued HTTPS certificates that were recognized as valid by browsers.

According to Google, several of its own domains were affected, as were domains belonging to other organizations. The company refers to internationally recognized brands and widely used online services but does not name any specific ones.

Valid certificate, wrong website

The incident exposes a vulnerability in the way websites verify their identity. Browsers rely on HTTPS certificates to establish encrypted connections and verify the identity of the visited website. But when attackers can both manipulate DNS traffic and possess a valid certificate, a user may unwittingly end up on a spoofed website.

In such cases, the browser does not necessarily display a certificate warning. The attacker may then be able to intercept or alter data. Such websites can also be used for phishing or the distribution of malware.

Google emphasizes that the certificate authorities involved did not necessarily make any mistakes. They issued certificates based on domain validations that could be successfully completed due to the manipulated DNS records.

There is no evidence that Google’s own systems were compromised. Nor has it been disclosed whether attackers actually intercepted user data.

Chrome blocks certificates

Google immediately blocked the unauthorized certificates for its own domains via CRLSets, a mechanism that allows Chrome to reject certain certificates. In addition, the company worked with the affected certificate authorities to revoke the certificates.

Upon examining public Certificate Transparency logs, Google subsequently discovered that more organizations were likely affected. Chrome has also blocked suspicious certificates for those domains. Where possible, the affected organizations have been notified.

According to Google, Chrome users do not need to take any action themselves. For users of other browsers, protection depends in part on the revocation of the certificates and how their software responds to it.

DNS administrators must check for themselves

Google warns that browser security alone is not sufficient. Due to the complexity of DNS hijacks, the company cannot guarantee that all affected domains have been identified. Techzine previously described how, in so-called “Sitting Ducks” attacks, domain names can be hijacked without attackers having to breach the domain owner’s systems.

Google advises organizations to continuously monitor their entire domain portfolio via Certificate Transparency logs. These public registries reveal when certificates are issued, even when the domain owner did not request them.

In addition, Google recommends the use of restrictive Certification Authority Authorization (CAA) records. These allow domain owners to specify which certificate authorities are permitted to issue certificates. By linking this authorization to specific accounts and verification methods, organizations can prevent attackers from obtaining new certificates based on previously performed validations after a DNS hijacking has been resolved.

However, during an active DNS hijack, such records do not provide complete protection, as attackers can also modify them.

Google also plans to further reduce the validity period of HTTPS certificates and limit the reuse of domain validations. This should shorten the period during which attackers can exploit improperly obtained certificates.