Google blocks unauthorized TLS certificates after .gh, .sl and .as registry hijacks
In short
Google said the country-code top-level domains .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) were hijacked, with attackers tampering with authoritative DNS records to obtain TLS certificates. Chrome blocked the identified unauthorized certificates through its CRLSet mechanism and Google asked certificate authorities to revoke them. Google said it did not disclose how many certificates or which companies and services are affected, and warned that browser blocking does not protect non-Chrome users.
Read the full story 2 min read
Google has blocked a set of unauthorized TLS certificates after the country-code top-level domains .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) were hijacked, according to reports from Landian, cnBeta and IT Home citing a Google security blog post. IT Home said Google published the announcement on October 6, and that Google noticed the attack the previous week. [ 1 , 2 , 3 ]
According to IT Home, attackers breached a third-party domain registry management system and altered authoritative DNS records, then used that DNS control to pass certificate authorities' automated domain-control validation. Landian and cnBeta described the same sequence — a registry-level attack, tampered DNS records and certificate applications — and said the resulting certificates, combined with traffic redirection, could let impersonated sites pass certificate checks. IT Home said all domains using those suffixes may be at risk. [ 1 , 2 , 3 ]
Google said its own internal systems were not breached and that there is no reason to believe the certificate authorities violated their procedures, because under existing rules a valid DNS record is enough to demonstrate domain ownership, the outlets reported. Chrome blocked the identified unauthorized certificates through its CRLSet mechanism, and Google contacted the issuing certificate authorities to have the certificates revoked in order to protect other browsers and clients, according to Landian and cnBeta. IT Home said Google also reviewed certificate transparency logs. [ 1 , 2 , 3 ]
Google did not disclose which companies or services are affected or how many certificates are involved, Landian and cnBeta reported. Google said DNS hijacking is very complex and that it cannot guarantee it has found every affected domain, and that browser-side blocking cannot reliably protect users who do not use Chrome, the two outlets said. [ 1 , 2 ]
Domain holders were advised to check whether certificates have been issued for their domains, with Landian and cnBeta pointing to the crt.sh service and saying any certificate the holder did not request should be reported to the issuing certificate authority for revocation. IT Home said Google recommended continuous monitoring of certificate logs, including for parked domains and regional domains, and setting restrictive Certificate Authority Authorization (CAA) records — binding authorized accounts and validation methods — to stop attackers from using cached validation results to obtain new certificates after a hijack ends. [ 1 , 2 , 3 ]
Why it matters
Because any domain using those three suffixes may be affected, the incident reaches beyond the registries themselves to sites and services that depend on .gh, .sl and .as addresses. Google's own note that it cannot guarantee finding every affected domain, and that Chrome-side blocking does not cover other browsers, leaves certificate and DNS checks with domain holders as a main defence.
Key facts
- Google said the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) country-code top-level domains were hijacked. [ 1 , 3 ]
- Attackers tampered with authoritative DNS records and used that DNS control to pass certificate authorities' automated domain-control validation. [ 1 , 3 ]
- Google said its own internal systems were not breached and that there is no reason to believe the certificate authorities acted improperly. [ 1 , 2 , 3 ]
- Chrome blocked identified unauthorized certificates through its CRLSet mechanism, and Google contacted the issuing certificate authorities to revoke them. [ 1 , 2 , 3 ]
- Google did not disclose the affected companies or services, or the number of certificates. [ 1 , 2 ]
- Google said DNS hijacking is complex and it cannot guarantee it has found all affected domains. [ 1 , 2 ]
- Google said browser-side blocking cannot reliably protect users of browsers other than Chrome. [ 1 , 2 ]
- Google recommended domain holders monitor certificate logs, including for parked and regional domains, and set restrictive CAA records. [ 1 , 3 ]
Confirmed by several sources
- The .gh, .sl and .as country-code top-level domains were hijacked. [ 1 , 2 , 3 ]
- Chrome blocked unauthorized certificates using CRLSet and Google worked with certificate authorities to revoke them. [ 1 , 2 , 3 ]
- Google said there is no reason to believe the certificate authorities violated their procedures. [ 1 , 2 , 3 ]
Still unclear
- Which companies and online services are affected, and how many certificates were issued. Google did not disclose the list or the certificate count, according to two outlets; the documents name no affected brands.
- How far the hijacking spread and whether all affected domains have been identified. Google said DNS hijacking is complex and that it cannot guarantee finding every affected domain.
- Exactly how many domains were compromised and how long the attackers held control. The documents give no figures or duration; the timing is described only as Google noticing the attack last week.
What local media are saying
Timeline, local time
- Landian reports the .gh, .sl and .as hijacks and Chrome's blocking of unauthorized certificates obtained through tampered DNS records. [ 1 ]
- cnBeta publishes a report on the same incident, carrying Google's statement that its internal systems were not breached and linking to Google's security blog. [ 2 ]
- IT Home reports that Google announced the incident on October 6, saying attackers breached a third-party domain registry management system and listing CAA and certificate-log monitoring advice. [ 3 ]