Google Domains: ccTLD Hijacks Expose Security Risks
Google disclosed a security breach affecting multiple domains under its management, including .gh, .sl, and .as ccTLDs.
Security Breach Details
Compromised Domains
Google disclosed that multiple domains under its management were compromised due to a recent security breach targeting third-party country-code top-level domains (ccTLDs). The incident involved the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) domains, exposing all associated domains to potential risks.
Unauthorized Certificates
Attackers altered authoritative DNS records and obtained unauthorized SSL/TLS certificates for several Google domains, as well as for other organizations. The company stated that the certificate authorities (CAs) responsible for issuing these certificates were not at fault, as the attacks exploited vulnerabilities in domain control mechanisms.
Actions Taken by Google
Blocking and Revoking Certificates
Upon discovering the breach, Google immediately blocked the unauthorized certificates in Chrome and collaborated with CAs to revoke them. Analysis of Certificate Transparency (CT) log data revealed that additional organizations, including major global brands and online services, were also affected.
Proactive Mitigation
To mitigate risks, Google proactively blocked the certificates in Chrome and notified impacted entities of its findings and actions. However, the company acknowledged that some domains might still be vulnerable.
Recommendations for Domain Administrators
Monitoring CT Logs
Google advised domain administrators to monitor CT logs for all their domains, particularly those using the .gh, .sl, or .as suffixes. It also recommended implementing restrictive CAA (Certification Authority Authorization) DNS records to reinforce security once DNS control is restored.
Strengthening Security Measures
The company highlighted that CAs often cache and reuse domain validation checks, emphasizing the importance of enforcing strict CAA policies to limit certificate issuance to authorized accounts and validation methods.
Conclusion
The incident underscores the risks posed by compromised ccTLDs and the need for proactive measures to safeguard digital infrastructure. Organizations are urged to review their certificate management practices and ensure robust validation processes to prevent similar breaches.
