Google Warns Of Fake Digital Certificates

It has come to notice their that NIC has issued several unauthorized SSL certificates to various Google domains. These unauthorized certificates can be used to bluff and pretend as legit Google website on different servers and can put user’s information at risk. With the use of such dodgy SSL certificate, it is easy to spy on or fiddle with user’s encrypted communication.

The major concern kicks in when the issuer is holding a number of intermediate CA certificates that are trusted by India CCA as well as by some western companies. Although no evidence of Windows using these fake certificates has come up so far, however, an investigation is ongoing to find if there are any. Required steps were taken by authorities to protect user’s information. Not only this, but India CCA is investigating the issue to find the root cause as it happened earlier too.

Fake Certificate Security Issues:

Various issues that have been raised so far are listed below:

• A warning was issued by Microsoft over ‘improper issued’ SSL certificate which could have resulted in a phishing attack.

• Apple also got alerted about the critical SSL flaw in Mac OS and iOS

• Google has warned CNNIC, an intermediate certificate authority, about the issuing of unauthorized digital certificates.


Certificate Transparency:

Google accepts that it is a serious breach of CA system and such incidents indicate that Google’s Certificate Transparency efforts are critical for protecting the security of certificates in the future. Certificate transparency will help in:

  • Eliminating security flaws as it will provide an open framework to monitor and audit SSL certificate in near real time.
  • Detect fake SSLs.
  • Identifying CAs attempt to issue unauthorized SSL certificates
  • Pinning public key can specify authorized SSL certificates.

Google Logging System:

Google engineers have come up with logging system that brings together CAs (ones that are trusted) and CAs working hard to build its goodwill.

The main mission of this system is to:

• Protect its user from fake and illegally issued SSL certificates

• Provide public record information of the certificates issued for specific domains.