From the Google blog "Chrome's Response to Recent ccTLD Registry Hijacks":
"These incidents did not involve a compromise of Google’s systems; rather, attackers compromised the third-party ccTLDs, putting any domain ending in .gh, .sl, or .as at risk. During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations."
So entire top level domain registries were compromised. Interesting times. Isn't there really any primary source on this?
fulafel•1h ago
"These incidents did not involve a compromise of Google’s systems; rather, attackers compromised the third-party ccTLDs, putting any domain ending in .gh, .sl, or .as at risk. During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations."
So entire top level domain registries were compromised. Interesting times. Isn't there really any primary source on this?
proactivesvcs•35m ago
https://news.ycombinator.com/item?id=49988253
https://news.ycombinator.com/item?id=49981886