The Actual News

Stay informed without the news wearing you out.

Hackers obtain counterfeit TLS certificates for Google and other large services

Hackers obtain counterfeit TLS certificates for Google and other large services

Summary

Hackers took control of three country-level internet domains and used this to create fake security certificates for Google and other big companies. Google updated its Chrome browser to block these fake certificates and is working to remove them from the system.

Key Facts

  • Attackers hijacked the .gh, .sl, and .as country code top-level domains.
  • They changed important DNS records to prove control of certain domains.
  • This allowed them to get fake TLS certificates for Google and other top brands.
  • TLS certificates help prove a website is real and secure by using secret keys.
  • Google blocked the unauthorized certificates in Chrome and asked the certificate issuers to cancel them.
  • Google warned domain owners not to depend only on browsers to protect users.
  • The hackers did not compromise the servers of the affected companies, only the domain controls.
  • Certificate revocation is a slow process; browsers block certificates faster to reduce risks.
Read the Full Article

This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.

Monday's biggest stories, one calm email.