On October 6, Google revealed that attackers had compromised three country-code top-level domains (ccTLDs), acquiring unauthorized HTTPS certificates for multiple Google domains. These affected domains include those ending in .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). Although Google’s internal systems were not breached, the incident posed a risk as attackers could impersonate Google’s sites to intercept private data.
Google’s Swift Response to the Threat
In response to the breach, Google quickly blocked the unauthorized certificates using Chrome’s CRLSets, a tool designed to rapidly invalidate certificates in emergencies. Furthermore, Google collaborated with the certificate authorities (CAs) responsible for issuing the certificates to ensure their revocation, safeguarding users across various browsers and applications.
The Certificate Transparency logs, which document all certificates issued by CAs, showed that at least 12 unauthorized certificates were issued between September 22 and September 27 for domains like google.com.gh, google.sl, and google.as. These certificates were issued by Let’s Encrypt and ZeroSSL, with the attackers manipulating DNS records to obtain them.
Insight into Certificate Transparency Logs
On October 7, The Hacker News identified the unauthorized certificates through CT search services. The 12 certificates covered seven different domains, with Let’s Encrypt responsible for issuing 11 of them and ZeroSSL for one. The issuance of these certificates was recorded on separate days for each ccTLD: .gh on September 22, .sl on September 25, and .as on September 27.
All certificates were domain-validated, meaning they were issued after verifying the applicant’s control over the domain. Normally, Google Trust Services, Google’s own CA, issues certificates for these Google domains. However, during these hijacks, attackers managed to modify authoritative DNS records to gain certificate issuance.
Recommendations for Domain Owners
In light of the attack, Google advised domain owners to monitor Certificate Transparency logs for their domains, including parked and regional ccTLD names. Google also recommended publishing a strict Certification Authority Authorization (CAA) record to restrict which CAs can issue certificates for a domain. Moreover, any unauthorized certificate should be reported to the issuing CA for prompt investigation.
Although CAA records cannot prevent certificate issuance during an active DNS hijack, they become crucial once domain control is restored. They help ensure that unauthorized certificates cannot be reissued by exploiting a previously completed domain check. Google’s proactive measures underscore the importance of robust domain security practices to protect against such sophisticated cyber threats.
As of October 7, all affected certificates were revoked, with the revocation process taking between a day and a week to complete. Google’s efforts to mitigate the impact included informing other potentially affected organizations and enhancing security protocols to prevent future incidents of this nature.
