Smart news for curious minds.

Nerd News Network
Technology

Hackers obtain counterfeit TLS certificates for Google and other large services

Compromise of 3 domain registries allows hackers to walk off with unauthorized certs.

Lead image for “Hackers obtain counterfeit TLS certificates for Google and other large services”.
Image: Ars Technica
Share

Compromise of 3 domain registries allows hackers to walk off with unauthorized certs.

The short version

  • Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday.
  • “While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users,” Google said .
  • “Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.” Ars Technica has been separating the signal from the noise for over 25 years.

What happened

With our unique combination of technical savvy and wide-ranging interest in the technological arts and sciences, Ars is the trusted source in a sea of information. After all, you don’t need to know everything, only what’s important.

Why it matters

Ars Technica says hackers obtain counterfeit tls certificates for google and other large services is the central development readers should understand.

Summary by Nerd News Network. Read the full article at Ars Technica via the links above and below.

Share