Команда Chrome сообщила, что сначала заблокировала сертификаты для сайтов Google, а затем — для сайтов других организаций. Пользователям браузера ничего делать не нужно.
По данным Google, злоумышленники изменили DNS-записи (настройки адресации доменов) и получили HTTPS-сертификаты для сайтов Google и других организаций. Системы самой Google, по сообщению компании, взломаны не были.
Google предупреждает, что могла обнаружить не все пострадавшие домены и что меры Chrome не обеспечивают надёжной защиты пользователям других браузеров. Владельцам доменов в .gh, .sl и .as компания рекомендует проверить недавние записи в публичных журналах сертификатов Certificate Transparency на наличие неожиданно выданных сертификатов.
Проверка утверждений:
- Google заблокировала в Chrome сертификаты, выпущенные без разрешения при захвате доменов в зонах .gh, .sl и .as: сначала для сайтов Google, затем для сайтов других организаций. (подтверждено самой публикацией: доказательство; «Last week, we became aware of a series of domain hijacks in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level namespaces (i.e., ccTLDs). These incidents did not involve a compromise of Google’s systems; rather, attackers compromised the third-party ccTLDs, putting any domain ending in .gh, .sl, or .as at risk. During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations. Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong. As part of our usual incident response process, we immediately acted to protect users by blocking the use of unauthorized certificates for Google properties in Chrome via CRLSets . We also worked with the issuing CAs to ensure the certificates were revoked to protect users in clients other than Chrome. Following our initial mitigation, Certificate Transparency (CT) log data revealed additional organizations, including several leading global brands and widely used online services, believed to have been impacted by the same attacks. To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome.»)
- Пользователям Chrome ничего делать не нужно. (подтверждено самой публикацией: доказательство; «Chrome users do not need to take any action to be protected.»)
- По данным Google, злоумышленники изменили DNS-записи и получили HTTPS-сертификаты для сайтов Google и других организаций. (подтверждено самой публикацией: доказательство; «During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations.»)
- По сообщению Google, её системы взломаны не были. (подтверждено самой публикацией: доказательство; «These incidents did not involve a compromise of Google’s systems; rather, attackers compromised the third-party ccTLDs, putting any domain ending in .gh, .sl, or .as at risk.»)
- Google предупреждает, что могла обнаружить не все пострадавшие домены и что меры Chrome не обеспечивают надёжной защиты пользователям других браузеров. (подтверждено самой публикацией: доказательство; «Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.»)
- Google рекомендует владельцам доменов в .gh, .sl и .as проверить недавние записи в Certificate Transparency на наличие неожиданно выданных сертификатов. (подтверждено самой публикацией: доказательство; «If you operate a domain in .gh, .sl, or .as, review recent CT log entries for unexpected issuance.»)
Первоисточники:
оценка 52,8 из 100 · тип: инцидент