Skip to main content

Google, Mozilla blacklists China’s web registrar over breach

some chinese websites to be banned in firefox chrome browsers after security breach chinainternetsecurity
Nmedia/Shutterstock
Google and Mozilla have just announced that they will blacklist digital certificates from the China Internet Network Information Center, the country’s main Internet agency.

CNNIC oversees China’s Internet infrastructure. This means that Google Chrome and Mozilla Firefox will soon stop accepting certificates from most websites with the .cn domain. With the ban, Chrome and Firefox users will receive a pop-up that alerts them to possible security risks.

Recommended Videos

The move comes about two weeks after a security breach that involved unauthorized digital certificates for Google domains such as Gmail. On March 20, Google found that MCS Holdings, an Egyptian IT company, misused certificates. MCS Holdings obtained its intermediate certificate from CNNIC.

Please enable Javascript to view this content

Google said that MCS used the certificates for a man-in-middle proxy. According to CNNIC, they had agreed to issue a certificate to MCS with the condition that the company would only issue certificates for the domains they have registered. MCS instead intercepted connections by pretending to be the intended destination for users. Google called the incident “a serious breach” because all major browsers and operating systems recognized CNNIC certificates.

“This explanation is congruent with the facts. However, CNNIC still delegated their substantial authority to an organization that was not fit to hold it,” said Adam Langley, a security engineer at Google.

To help users adjust to the changes, Google has provided a grace period. The company said that it will recognize CNNIC’s existing certificates for a “limited time.” This exemption will only be extended to websites that are included in Google’s “whitelist.”

CNNIC, which conducted an investigation of its own after the breach, criticized Google’s move. “The decision that Google has made is unacceptable and unintelligible to CNNIC, and meanwhile CNNIC sincerely urge that Google would take users’ rights and interests into full consideration,” the agency wrote in its website.

In spite of the ban, Google has indicated that it would be willing to reinstate CNNIC at a later time. “While neither we nor CNNIC believe any further unauthorized digital certificates have been issued, nor do we believe the misissued certificates were used outside the limited scope of MCS Holdings’ test network, CNNIC will be working to prevent any future incidents,” Google wrote. “We applaud CNNIC on their proactive steps, and welcome them to reapply once suitable technical and procedural controls are in place.”

Christian Brazil Bautista
Christian Brazil Bautista is an experienced journalist who has been writing about technology and music for the past decade…
PayPal vs. Venmo vs. Cash App vs. Apple Cash: which app should you use?
PayPal, Venmo, Cash App, and Apple Wallet apps on an iPhone.

We’re getting closer every day to an entirely cashless society. While some folks may still carry around a few bucks for emergencies, electronic payments are accepted nearly everywhere, and as mobile wallets expand, even traditional credit and debit cards are starting to fall by the wayside.

That means many of us are past the days of tossing a few bills onto the table to pay our share of a restaurant tab or slipping our pal a couple of bucks to help them out. Now, even those things are more easily doable from our smartphones than our physical wallets.

Read more
How to change margins in Google Docs
Laptop Working from Home

When you create a document in Google Docs, you may need to adjust the space between the edge of the page and the content --- the margins. For instance, many professors have requirements for the margin sizes you must use for college papers.

You can easily change the left, right, top, and bottom margins in Google Docs and have a few different ways to do it.

Read more
What is Microsoft Teams? How to use the collaboration app
A close-up of someone using Microsoft Teams on a laptop for a videoconference.

Online team collaboration is the new norm as companies spread their workforce across the globe. Gone are the days of primarily relying on group emails, as teams can now work together in real time using an instant chat-style interface, no matter where they are.

Using Microsoft Teams affords video conferencing, real-time discussions, document sharing and editing, and more for companies and corporations. It's one of many collaboration tools designed to bring company workers together in an online space. It’s not designed for communicating with family and friends, but for colleagues and clients.

Read more