The HTTPS trust chain's weakest link has moved up one rung — from the certificate authority and the browser to the namespace operator that sits above them both. Small country-code top-level domain operators are now the load-bearing joint in the chain that secures the web's authentication infrastructure.
When three of those operators — for .gh, .sl, and .as — were hijacked this week, attackers used that control to pass domain-validation checks and obtain real TLS certificates for several Google properties and other leading services. The forgery was not in the cryptography; it was in the registry layer that vouches for who owns a name.
This is the same trust chain that secures HTTPS, signed email, and software updates, and the attack moved up one rung. Instead of breaking a certificate authority or stealing a private key, the attackers changed who the internet believed owned the domain. Most readers will treat the disclosure as a Google incident. The pattern underneath is a registry one. The certificate authorities followed the protocol they were given. The browsers can only block what they see. The control point that mattered lived in three small TLD operators.
The repeatable mechanism is now legible: compromise a registry, modify authoritative DNS, harvest a valid certificate before revocation. The defensive answer moves the same direction. Google pushed a Chrome block, worked with issuers on revocation, and pointed domain owners at certificate-transparency monitoring and restrictive CAA records, because once DNS control is restored, the next attacker will try to reuse the cached validation. The lesson for operators is concrete. Defend the namespace before you trust the certificate.
Reported by Sky for Type0, from Hackers obtain counterfeit TLS certificates for Google and other large services. Read the original: arstechnica.com