Google-ը հայտնել է անվտանգության սերտիֆիկատների կեղծման մասին

10 աղբյուր
  • Google-ը երեքշաբթի հայտարարեց, որ հաքերները զավթել են .gh, .sl և .as երկրների դոմենները՝ ստանալով չարտոնված սերտիֆիկատներ իր և այլ խոշոր ապրանքանիշերի կայքերի համար։
  • DNS գրառումները փոխելով՝ հարձակվողները շրջանցել են սերտիֆիկացման մարմինների ավտոմատ ստուգումները. Google-ը նշել է, որ սեփականատերերի ենթակառուցվածքը չի վնասվել, իսկ մարմինները հետևել են կանոններին։
  • Chrome-ն այժմ արգելափակում է այդ սերտիֆիկատները, սակայն Google-ը դոմենների սեփականատերերին հորդորել է հետևել սերտիֆիկատների թափանցիկության մատյաններին և հրապարակել սահմանափակող DNS գրառումներ։
Աղբյուրներ (10)
  1. 1 Hackers obtain counterfeit TLS certificates for Google and other large services arstechnica.com
  2. 2 Attackers obtained counterfeit TLS certificates for Google domains ua.news
  3. 3 Hackers Used Hijacked Country Domains to Forge Real Google TLS Certificates - Startup Fortune startupfortune.com
  4. 4 Michele Chubirka posted this - LinkedIn www.linkedin.com
  5. 5 Verify TLS (or SSL) inspection works - Google Help support.google.com
  6. 6 Chrome: New SSL Certificates Can't Support Client Authentication ... www.thesslstore.com
  7. 7 Google Chrome Root Removal: DigiCert Trusted Root G4, DigiCert ... knowledge.digicert.com
  8. 8 Reminder: Popular Browsers To Distrust Symantec SSL/TLS ... www.wordfence.com
  9. 9 Important SSL Certificate Changes Coming to Chrome in 2026 comlaude.com
  10. 10 Google to distrust Entrust SSL/TLS certificates: What this means for ... www.sectigo.com