deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (hnrss.org)

Counterfeit TLS certificates for Google minted via hijacked country-code domains

Attackers who seized control of three country-code top-level domains passed certificate validation checks and obtained fake TLS certificates for Google and other major services, Ars Technica reports.

Counterfeit TLS certificates for Google minted via hijacked country-code domains

Attackers have obtained fraudulent TLS certificates for Google and several other major web services by seizing control of three country-code top-level domains, according to a report from Ars Technica published in early October 2026. Forged credentials of this kind could let the attackers impersonate those services to unsuspecting visitors, because a browser would treat the attackers' connection as legitimate and display a valid padlock.

How the attack worked

According to Ars Technica, the infrastructure of the affected domain owners was never breached, and the certificate authorities involved complied with every validation requirement. The weak point was DNS itself. Once the attackers held control of the three ccTLD registries, they could redirect the IP addresses of a hand-picked set of websites. That traffic-handling ability let them alter authoritative DNS records and nameserver delegations for chosen domains, which is precisely what certificate authorities check when an applicant must demonstrate control of a domain before a certificate is issued. The validation system worked as designed; the attackers simply arranged to be the ones it validated.

What remains unclear

Several details are still unknown, Ars Technica reports: which organizations beyond Google were affected, how many unauthorized certificates were issued in total, and whether every one of them, apart from those covering Google's domains, has been neutralized.

Blocking at the browser

Google said Chrome intervened during the incidents to detect and block suspect certificates tied to the affected ccTLDs. But the company was blunt about the limits of that approach. Because DNS hijacks are complicated to untangle, Google cannot promise its analysis caught every affected domain, and Chrome's countermeasures do nothing for people using rival browsers, the company cautioned.

Formal certificate revocation has long been slow and awkward, so browser makers developed faster ways to neutralize a specific certificate directly at the browser level. All known unauthorized certificates have now been blocked through such mechanisms, Ars Technica reports, which mitigates the immediate risk. Any certificate that has not yet been discovered, however, still poses a danger, as Google itself acknowledged.

This has happened before

The closest precedent is the 2011 breach of DigiNotar, a Netherlands-based certificate authority. In that incident, attackers forged credentials for Google.com and more than 200 other high-traffic domains, and the fakes were used against at least 300,000 people with ties to Iran as they browsed the impersonated sites. Ars Technica notes that many similar incidents have occurred since, more often through failures at certificate authorities than through domain holders, which is what makes this episode unusual: here the CAs appear to have followed the rules.

Why it matters

TLS certificates are the foundation of trust on the web, and this incident shows the issuance pipeline can be subverted without a single CA misstep and without compromising the victim organization. Control of a registry, a layer most site operators never think about, was enough to satisfy domain-control validation. Browser-level blocking, the current mitigation of choice, is a patch rather than a fix: it is browser-specific, dependent on complete discovery, and reactive by nature. For operators of large services, the episode is a reminder that their real attack surface extends down through registrars, registries and DNS infrastructure beneath their domains, and that watching for certificates they never requested is now part of basic security hygiene.

  • #tls
  • #dns
  • #security
  • #google
  • #certificates

Related posts