| ▲ | Hackers obtain counterfeit TLS certificates for Google and other large services(arstechnica.com) | |||||||||||||
| 56 points by colinprince 4 hours ago | 11 comments | ||||||||||||||
| ▲ | Borealid 3 hours ago | parent | next [-] | |||||||||||||
This sounds like something that HPKP ( https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning ) could have prevented and CAA records ( https://letsencrypt.org/docs/caa/ ) could not. But HPKP is deprecated. | ||||||||||||||
| ||||||||||||||
| ▲ | rswail 3 hours ago | parent | prev | next [-] | |||||||||||||
The affected country ccTLDs are: AS: American Samoa GH: Greenland SL: Sierra Leone | ||||||||||||||
| ||||||||||||||
| ▲ | 3 hours ago | parent | prev | next [-] | |||||||||||||
| [deleted] | ||||||||||||||
| ▲ | aiXis 2 hours ago | parent | prev | next [-] | |||||||||||||
[flagged] | ||||||||||||||
| ▲ | fulafel 4 hours ago | parent | prev | next [-] | |||||||||||||
From the Google blog "Chrome's Response to Recent ccTLD Registry Hijacks": "These incidents did not involve a compromise of Google’s systems; rather, attackers compromised the third-party ccTLDs, putting any domain ending in .gh, .sl, or .as at risk. During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations." So entire top level domain registries were compromised. Interesting times. Isn't there really any primary source on this? | ||||||||||||||
| ||||||||||||||
| ▲ | netik 2 hours ago | parent | prev [-] | |||||||||||||
This seems like bullshit given certificate pinning and other countermeasures here. What am I missing ? Is it TLDs lacking support for this? | ||||||||||||||
| ||||||||||||||