HomeSecurityUnauthorized certificates for Google: DNS records altered

Unauthorized certificates for Google: DNS records altered

The breach of three country code top-level domain (ccTLD) management systems facilitated the issuance of unauthorized HTTPS certificates for Google and other organizations’ domain names. The attackers tampered with DNS records for the .gh, .sl, and .as domains, although Google clarifies that its own systems were not compromised.

DNS records in corrupted paths

These extensions correspond to Ghana, Sierra Leone, and American Samoa. DNS records determine where each domain points. Changing a name's DNS records can be done without accessing the systems of the organization that uses it. Google says the attackers modified them after third-party administrators of the specific namespaces were affected. This created the ability to issue HTTPS certificates for names that they normally do not control.

Google did not name the affected domains or the other companies it believes were affected. In an independent review, The Hacker News found at least 12 certificates for seven Google and YouTube domains, including google.com.gh, google.sl and google.as. The report says all had been revoked by October 7.

Possession of a certificate does not in itself prove that the perpetrators used the names to intercept traffic or data. The Hacker News article notes that Google does not report whether any certificate was used for impersonation or data interception, while the company does not name the perpetrators. The available information therefore does not document a breach of Google services or accounts.

See also: DNS breach at cubepilot.org took down services and forums

How DNS records led to HTTPS certificates

HTTPS certificates allow the browser to verify the name of the website and establish an encrypted connection. To issue them, a certificate authority must confirm that the applicant controls the corresponding name. This confirmation is often done through DNS, by adding a special record that proves control. DNS records are therefore critical for proving ownership.

The altered DNS records allowed the attackers to influence the verification process for selected names. Google says they obtained HTTPS certificates for several of its own domains, as well as names belonging to other organizations. It does not claim that the certificate authorities circumvented the rules; instead, it says it has no reason to believe that the publishers acted improperly.

The Hacker News report says that 11 of the 12 certificates were issued by Let's Encrypt and one by ZeroSSL. The public transparency records appeared between September 22 and 27. The finding concerns specific Google and YouTube names that the outlet examined; it is not a complete inventory of all potential victims or endpoints. Google did not release a total number of issues.

HTTPS certificates for Google services

According to Google, the incidents did not result from a breach of its own infrastructure. The company has not publicly disclosed how the attackers gained access to the third-party administrators or attributed the action to a specific group. The distinction is important: DNS records can affect services that are operating normally, without the provider itself being compromised.

What Google did and what users know

Google added the unauthorized certificates to Chrome's CRLSets, which allow the browser to quickly block specific certificates. It also worked with issuing authorities to revoke them to cover other apps and browsers. For Chrome users, the company says no action is required.

However, Google warns that it cannot guarantee that it has detected every name that was affected. Protection through Chrome does not automatically cover every browser, and certificate revocation by issuing authorities is the most widespread remediation measure. The Hacker News reports that all 12 certificates it examined were listed as revoked on October 7.

The case shows that the validity of a certificate is not enough when control of a name or DNS records has temporarily passed to third parties. The SecNews technical team points out that organizations need to monitor their entire domain portfolio, even names that are inactive or use regional suffixes.

Certificate and DNS monitoring

How can managers mitigate risk?

Google recommends that you constantly monitor your public Certificate Transparency (CT) files. Every certificate that Chrome trusts by default is listed in these files, so administrators can detect unexpected releases. The audit should cover all domains, including those that remain inactive. DNS records should also be checked after every administrator change.

Another measure is restrictive Certificate Authority Authorization (CAA) records, which specify which issuers are allowed to issue certificates for a domain. Google clarifies that CAA records do not prevent issuance while an active DNS breach is ongoing, if the perpetrator can also change these records. However, they do help after control is regained, by limiting reissuance based on cached verification.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Chrome will soon get its own root certificate directory

See also: Chinese hackers UNC6384 target diplomats with new techniques

Administrators of .gh, .sl and .as are specifically urged to check for recent versions in their CT files, while any organization using regional extensions should confirm that their DNS records and issuance policies remain under their control. Google will continue to update its blocking measures, but it emphasizes that browser protection is not a substitute for domain owners’ oversight of their domains.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS