Hasty Briefsbeta

Bilingual

Chrome's Response to Recent ccTLD Registry Hijacks

8 hours ago
  • Attackers compromised third-party ccTLDs (.gh, .sl, .as), not Google's systems, putting domains under those namespaces at risk.
  • Chrome blocked unauthorized certificates for Google properties via CRLSets and worked with CAs to revoke them.
  • Certificate Transparency logs revealed additional impacted organizations, including global brands; Chrome proactively blocked those certificates.
  • Chrome users do not need to take any action to be protected.
  • Domain owners should monitor CT logs for their entire domain portfolio to detect unexpected certificate issuance.
  • Domain owners should publish restrictive CAA records with ACME account bindings to limit certificate issuance after DNS control is restored.
  • Chrome is working on long-term HTTPS ecosystem improvements like reducing certificate validity and DCV reuse.