Hackers obtain counterfeit TLS certificates for Google and other large services

生活指南 法律法规 杂七杂八
Hackers obtain counterfeit TLS certificates for Google and other large services
摘要

谷歌称攻击者劫持了.gh、.sl和.as三个国家代码顶级域名,篡改其下选定域名的权威DNS记录,从而通过自动化域名控制验证,为谷歌及其他大型机构非法获取TLS证书。谷歌已更新Chrome以阻止相关未授权证书,并与签发机构合作撤销涉谷歌域名的证书。TLS证书用于绑定域名与公钥,是网站等基础设施认证与加密的基础,未授权证书可被用于冒充受影响服务。

Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday.

The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.” Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.

Certificate issuance: The weak link in the chain

TLS certificates are the cryptographic credentials that underpin authentication and encryption protections for websites, mail servers, and other Internet infrastructure. These x.509 certificates use a digital signature to bind a domain name such as google.com to a public key. The public key is publicly available, while the private key is held only by the website operator. When a connection shows that the keys match, the visiting party knows it’s connected to the authentic site rather than an impostor. Possession of unauthorized certificates allows attackers to cryptographically impersonate the affected infrastructure.

Read full article

Comments

转载信息
原文: Hackers obtain counterfeit TLS certificates for Google and other large services (2026-10-06T19:21:14)
作者: Dan Goodin 分类: 科技
评论 (0)
请 登录 后发表评论

暂无评论,来留下第一条评论吧