Hackers obtain counterfeit TLS certificates for Google and other large services
Hackers obtain counterfeit TLS certificates for Google and other large services
黑客获取了针对谷歌及其他大型服务的伪造 TLS 证书
Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.”
谷歌周二表示,攻击者劫持了三个顶级域名,并利用其控制权为谷歌及其他大型组织伪造了 TLS 证书。攻击者对 .gh(加纳)、.sl(塞拉利昂)和 .as(美属萨摩亚)这三个国家代码顶级域名(ccTLD)发动了一系列攻击,随后修改了这些命名空间内特定域名的权威 DNS 记录。通过控制这些 DNS 记录,攻击者得以通过自动化的域名控制验证检查,并为“多个谷歌域名”以及“多个全球领先品牌和广泛使用的在线服务”获取了未经授权的证书。
Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.
谷歌表示,已更新 Chrome 浏览器以拦截所有被识别为未经授权的证书,并与颁发证书的认证机构合作,确保针对谷歌资产的未经授权证书被撤销。
Certificate issuance: The weak link in the chain
证书颁发:链条中的薄弱环节
TLS certificates are the cryptographic credentials that underpin authentication and encryption protections for websites, mail servers, and other Internet infrastructure. These x.509 certificates use a digital signature to bind a domain name such as google.com to a public key. The public key is publicly available, while the private key is held only by the website operator. When a connection shows that the keys match, the visiting party knows it’s connected to the authentic site rather than an impostor. Possession of unauthorized certificates allows attackers to cryptographically impersonate the affected infrastructure.
TLS 证书是支撑网站、邮件服务器及其他互联网基础设施身份验证和加密保护的加密凭证。这些 x.509 证书使用数字签名将域名(如 google.com)与公钥绑定。公钥是公开的,而私钥仅由网站运营商持有。当连接显示密钥匹配时,访问方就知道其连接的是真实网站而非冒充者。持有未经授权的证书使攻击者能够在加密层面冒充受影响的基础设施。
Google didn’t identify the affected domains it owns or name any of the other organizations whose domains were affected. While noting that Chrome users do not need to take any action to be protected, Google cautioned domain owners not to rely solely on browser-side interventions to protect their users. The company is advising domain owners to monitor certificate transparency logs for unexpected certificate issuance across their domains and to publish restrictive Certification Authority Authorization (CAA) DNS records to prevent attackers from reusing cached validation data after DNS control is restored.
谷歌并未指明其受影响的自有域名,也未透露其他受影响组织的名称。谷歌指出 Chrome 用户无需采取任何行动即可获得保护,但同时提醒域名所有者不要仅依赖浏览器端的干预来保护用户。该公司建议域名所有者监控证书透明度日志,以发现其域名下是否存在异常的证书颁发情况,并发布限制性的“证书颁发机构授权”(CAA)DNS 记录,以防止攻击者在 DNS 控制权恢复后重复利用缓存的验证数据。
“While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users,” Google said. “Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.”
“虽然 Chrome 在这些事件中采取了措施,识别并拦截了受影响 ccTLD 下的可疑未经授权证书,但不应依赖浏览器端干预来保护您的用户,”谷歌表示,“由于 DNS 劫持的复杂性,我们无法保证我们的分析识别出了每一个受影响的域名,Chrome 的干预措施也无法可靠地保护非 Chrome 用户。”
It’s not immediately clear what the other affected organizations are, how many unauthorized certificates were issued, or if all of them, except for those for Google domains, have been blocked. The process for officially revoking certificates is slow and cumbersome, so browser makers have devised quicker methods to block specific certificates at the browser level. With all known unauthorized certificates now blocked, the risk is mitigated, but as Google noted, any certificates that remain undiscovered pose a threat.
目前尚不清楚其他受影响的组织有哪些,颁发了多少未经授权的证书,或者除了谷歌域名的证书外,其余证书是否已被全部拦截。官方撤销证书的过程缓慢且繁琐,因此浏览器厂商设计了更快捷的方法,在浏览器层面拦截特定证书。随着所有已知的未经授权证书被拦截,风险已得到缓解,但正如谷歌所指出的,任何未被发现的证书仍然构成威胁。
Google noted that the incident didn’t involve the compromise of the infrastructure of any of the affected domain owners and that certificate authorities followed all requirements. With control of the three ccTLDs, the attackers were able to change the IP addresses of a selected list of websites. With the ability to send and receive traffic on those sites, the attackers were able to modify authoritative DNS records and nameserver delegations for selected delegations, allowing them to pass industry validation checks requiring an applicant to prove control of the domain.
谷歌指出,此次事件并未涉及任何受影响域名所有者的基础设施被入侵,且证书颁发机构均遵循了所有要求。通过控制这三个 ccTLD,攻击者能够更改特定网站列表的 IP 地址。由于能够发送和接收这些网站的流量,攻击者得以修改特定域名的权威 DNS 记录和名称服务器委派,从而通过了行业验证检查,即要求申请者证明其对域名的控制权。
This isn’t the first time threat actors have obtained unauthorized certificates. A 2011 hack of Netherlands-based certificate authority DigiNotar allowed attackers to mint counterfeit certificates for Google.com and more than 200 other high-traffic domains. The certificates were used against at least 300,000 people with ties to Iran as they browsed the sites impersonated by the forged certificates. There have been many similar incidents since, most often through failures by certificate authorities but also domain holders.
这并非威胁行为者首次获取未经授权的证书。2011 年,总部位于荷兰的证书颁发机构 DigiNotar 遭到黑客攻击,攻击者得以伪造 Google.com 及其他 200 多个高流量域名的证书。这些证书被用于针对至少 30 万名与伊朗有关联的人员,他们在浏览被伪造证书冒充的网站时受到了影响。此后发生了许多类似事件,大多是由于证书颁发机构的失误,但也涉及域名持有者的疏忽。