HomeSecurityFake Google digital certificates originate from Indian Authorities

Fake Google digital certificates originate from Indian authorities

14s15google-thumb-large

Google warns that suspicious SSL certificates issued by India's National Informatics Centre (NIC) are available: these certificates can be used by servers to disguise themselves as legitimate Google websites and monitor or interfere with users' encrypted communications.

According to this announcement from Google's security team, Google employees noticed unauthorized certificates for various Google domains since last Wednesday, and they were originating from NIC.

What is worrying is that the issuer holds several intermediate CA certificates that are considered safe by the Indian Certification Authority (India CCA), as well as some Western companies.

Google engineers notified both Indian agencies and Microsoft about the issue, and the fake certificates were revoked a day later. In the meantime, Google has revoked all certificates using Chrome's CRLSet feature and claims its products are "clean." It now appears that Microsoft users are also covered.

The Indian CCA has launched a full investigation to determine exactly what happened and led to the issuance of the certificates, but this is not the first time that certification authorities have either been tricked into issuing fake certificates, or have been subject to hacking attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS