What happened?

In a Tuesday statement, Google said attackers hijacked three country-code top-level domains (ccTLDs): .gh, .sl and .as. The attackers launched a series of attacks on the registries that operate those domains and then modified the DNS records for selected domains.

How were the counterfeit certificates created?

With control over the DNS records, the attackers could receive and send traffic from those domains. Using that ability, they created unauthorized certificates for "several Google domains" and "several leading global brands and widely used online services."

Why TLS certificates matter

TLS certificates are the cryptographic credentials that underpin authentication and encryption for websites, mail servers and other internet infrastructure. These x.509 certificates use a digital signature to bind an identity, such as Google, to a public key, and the certificate is bound to a specific domain. The public key is publicly available, while the private key is held only by the site operator. When the keys match, the visitor knows they are connected to the authentic site rather than an impostor.

The takeaway

Possession of unauthorized certificates allows attackers to cryptographically impersonate the affected infrastructure. Google said it updated Chrome to block all certificates it identified as counterfeit and worked with other certificate authorities to ensure other browsers did the same.