Hackers obtain counterfeit TLS certificates for Google and other large services
“While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users,” Google said. “Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.”
It’s not immediately clear what the other affected organizations are, how many unauthorized certificates...
Read more at arstechnica.com