Chrome has taken steps to protect users after attackers compromised three country-code top-level domains and exploited the incidents to acquire unauthorized HTTPS certificates for multiple organizations.
The affected namespaces are .gh for Ghana, .sl for Sierra Leone and .as for American Samoa. Attackers targeted the third-party registries which own the ccTLDs rather than Google directly.
In addition to the country-code top-level domain takeovers, the adversaries also modified the authoritative DNS records to compromise several Google domains and domains of other companies.
Chrome reported that it is not evident that Certification Authorities (CAs) that issued the certificates acted in bad faith but instead concluded that the problem stemmed from attackers’ tampering with DNS infrastructure of the country-code domains.
Chrome’s Secure Web and Networking Team responded to the incidents by utilizing CRLSets to block the unauthorized certificates associated with Google properties and coordinated with the CAs to revoke the certificates, protecting the users of the browsers and other clients.
The list of impacted entities grew as Chrome analyzed Certificate Transparency (CT) logs and identified a number of large publicly traded companies and popular internet services.
The team blocked certificates it suspected to be related to the attacks and reached out to the impacted businesses.
Users of Chrome do not need to take any action as the protections are designed to be transparent and work in the background. However, Google warned that organizations should not rely on the browser to protect them against the attacks and that Chrome did not identify all the affected domains. Similarly, protections worked on Google Chrome and may have not triggered in other browsers and clients.
Organizations are advised to ensure that they monitor the CT logs for all the domains and that they are notified if an unauthorized certificate is issued. This is critical because every certificate that is trusted by the public must be reported to CT logs. For domains that are impacted by the ongoing attacks, it is recommended to look over the most recent certificates to ensure that they have not been issued without authorization.
Google recommended the use of restricted Certification Authority Authorization (CAA) records and the use of ACME account bindings when available.
CAA records dictate which CAs can issue certificates and, while they do not prevent an attacker from using a hijacked domain to issue a certificate, they can help in ensuring that unknown CAs are not utilized. Additionally, the CAA records can prevent attackers from using domain-control validation for certificate issuance through misdirection.
Using issuing restrictions and validation method restrictions can prevent attackers from using certificates’ domain validation through cached entries. These protections are only effective after the control of the domain is re-established.
Chrome announced its intent to keep working on long-term projects to improve security and reduce the risks associated with the use of certificates. The proposed changes include shortening the lifespan of certificates and limiting the re-use of domain validation. They will continue to work to improve the Chrome Root Program with the Chrome Quantum-resistant Root Program as the Chrome ecosystem seeks to mitigate the risks posed by DNS and routing compromises.
Read the original article:
