logoalt Hacker News

fulafel • today at 5:15 AM • 2 replies • view on HN

From the Google blog "Chrome's Response to Recent ccTLD Registry Hijacks":

"These incidents did not involve a compromise of Google’s systems; rather, attackers compromised the third-party ccTLDs, putting any domain ending in .gh, .sl, or .as at risk. During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations."

So entire top level domain registries were compromised. Interesting times. Isn't there really any primary source on this?


Replies

bsoqk • today at 7:38 AM

Nothing novel about this. In fact this is the reason why years ago Google stopped using ccTLDs to serve their website.