Skip to content

Karios

Tech news

Support me 1

Gaming History Podcast (GR)

  • Gaming History – Επεισόδιο 27 – Sega Dreamcast
  • Gaming History – Επεισόδιο 26 – Psygnosis
Primary Menu
  • Home
  • Books
  • Shop
    • Browse Shop
    • Cart
    • Checkout
    • Orders
    • Account details
    • Lost password
  • Articles
    • All Articles
    • Games
    • DIY
    • Retro
  • Gaming History Podcast (GR)
  • Contact me
  • News

Hackers obtain counterfeit TLS certificates for Google and other large services

admin Posted on 1 day ago 2 minutes read
Hackers obtain counterfeit TLS certificates for Google and other large services

​Compromise of 3 domain registries allows hackers to walk off with unauthorized certs. 

Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday.

The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.” Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.

Certificate issuance: The weak link in the chain

TLS certificates are the cryptographic credentials that underpin authentication and encryption protections for websites, mail servers, and other Internet infrastructure. These x.509 certificates use a digital signature to bind a domain name such as google.com to a public key. The public key is publicly available, while the private key is held only by the website operator. When a connection shows that the keys match, the visiting party knows it’s connected to the authentic site rather than an impostor. Possession of unauthorized certificates allows attackers to cryptographically impersonate the affected infrastructure.

Read full article

Comments

 Ars Technica – All content Read More

About The Author

admin

See author's posts

Post navigation

Previous: Best Robot Companions for 2026: Mirumi, Moflin, Loona, Ropet and Eilik
Next: It looks like the Atlantic storm season may finally produce a hurricane

Related

Jaguar Type 01 debuts; now, no one remembers the electric Ferrari
  • News

Jaguar Type 01 debuts; now, no one remembers the electric Ferrari

admin Posted on 4 hours ago
Trade group crunches numbers on Trump’s impossible push for 100% US-made tech
  • News

Trade group crunches numbers on Trump’s impossible push for 100% US-made tech

admin Posted on 4 hours ago
Mistral says "Le Chonk" can challenge the best AI models
  • News

Mistral says “Le Chonk” can challenge the best AI models

admin Posted on 6 hours ago

Listen on Apple Music

You may have missed

Jaguar Type 01 debuts; now, no one remembers the electric Ferrari
  • News

Jaguar Type 01 debuts; now, no one remembers the electric Ferrari

admin Posted on 4 hours ago
Trade group crunches numbers on Trump’s impossible push for 100% US-made tech
  • News

Trade group crunches numbers on Trump’s impossible push for 100% US-made tech

admin Posted on 4 hours ago
Mistral says "Le Chonk" can challenge the best AI models
  • News

Mistral says “Le Chonk” can challenge the best AI models

admin Posted on 6 hours ago
Google rolls out improved SynthID AI content detector, now available globally
  • News

Google rolls out improved SynthID AI content detector, now available globally

admin Posted on 6 hours ago

If you are located in Europe, you can buy my new sci-fi fantasy book “Ground Zero” directly from me for a better price than Amazon.