{"id":41122,"date":"2025-09-04T00:59:32","date_gmt":"2025-09-03T21:59:32","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=41122"},"modified":"2025-09-04T00:59:36","modified_gmt":"2025-09-03T21:59:36","slug":"1-1-1-1-dns-mis-issued-certificates-threaten-internet-security","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/newswire\/technology\/41122\/1-1-1-1-dns-mis-issued-certificates-threaten-internet-security\/","title":{"rendered":"1.1.1.1 DNS Mis-issued Certificates Threaten Internet Security"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\"><summary>\u25bc Summary<\/summary>\n<p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Internet security experts are alarmed by the issuance of three TLS certificates for the widely used DNS service 1.1.1.1 by Cloudflare and APNIC.<br>&#8211; These certificates, issued in May, can decrypt DNS over HTTPS queries and may also affect Cloudflare&#8217;s WARP VPN service.<br>&#8211; The certificates were issued by Fina RDC 2020, a subordinate of Fina Root CA, which is trusted by Microsoft&#8217;s Root Certificate Program.<br>&#8211; Microsoft has engaged the certificate authority and is taking steps to block the certificates, though it did not explain the delay in detection.<br>&#8211; Google, Mozilla, and Apple browsers do not trust these certificates, and the requester of the credentials remains unknown.<br><\/p>\n<\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">A<\/mark> significant <a href=\"https:\/\/digitrendz.blog\/z\/topic\/security-concerns\/\" class=\"acp-topic-link\" data-topic-id=\"406\" title=\"Explore: Security Concerns\" target=\"_blank\" rel=\"noopener noreferrer\">security concern<\/a> has emerged within the <a href=\"https:\/\/digitrendz.blog\/z\/newswire\/artificial-intelligence\/150212\/bots-to-outnumber-humans-online-by-2027-report-says\/\" class=\"acp-article-link\" data-article-id=\"150212\" title=\"Bots to Outnumber Humans Online by 2027, Report Says\" target=\"_blank\" rel=\"noopener noreferrer\">internet infrastructure<\/a> community following the discovery of <strong>three mis-issued <a href=\"https:\/\/digitrendz.blog\/z\/newswire\/technology\/41766\/rising-threat-more-1-1-1-1-certificates-mis-issued\/\" class=\"acp-article-link\" data-article-id=\"41766\" title=\"Rising Threat: More 1.1.1.1 Certificates Mis-Issued\" target=\"_blank\" rel=\"noopener noreferrer\">TLS certificates<\/a><\/strong> for the widely trusted DNS resolver 1.1.1.1. Operated jointly by <a href=\"https:\/\/digitrendz.blog\/z\/entity\/cloudflare\/\" class=\"acp-entity-link\" data-entity-id=\"5730\" data-entity-category=\"Organization\" title=\"Learn more about Cloudflare\" target=\"_blank\" rel=\"noopener noreferrer\">Cloudflare<\/a> and <a href=\"https:\/\/digitrendz.blog\/z\/entity\/apnic\/\" class=\"acp-entity-link\" data-entity-id=\"99453\" data-entity-category=\"Organization\" title=\"Learn more about APNIC\" target=\"_blank\" rel=\"noopener noreferrer\">APNIC<\/a>, this service plays a foundational role in secure domain name resolution, making the improper certification a serious matter.<\/p>\n\n<p class=\"wp-block-paragraph\">These certificates, granted in May by <a href=\"https:\/\/digitrendz.blog\/z\/entity\/fina-rdc-2020\/\" class=\"acp-entity-link\" data-entity-id=\"99454\" data-entity-category=\"Organization\" title=\"Learn more about Fina RDC 2020\" target=\"_blank\" rel=\"noopener noreferrer\">Fina RDC 2020<\/a>, a subordinate authority under <a href=\"https:\/\/digitrendz.blog\/z\/entity\/fina-root-ca\/\" class=\"acp-entity-link\" data-entity-id=\"99455\" data-entity-category=\"Organization\" title=\"Learn more about Fina Root CA\" target=\"_blank\" rel=\"noopener noreferrer\">Fina Root CA<\/a>, could potentially be exploited to intercept and decrypt <a href=\"https:\/\/digitrendz.blog\/z\/topic\/dns-over-https\/\" class=\"acp-topic-link\" data-topic-id=\"78629\" title=\"Explore: dns over https\" target=\"_blank\" rel=\"noopener noreferrer\">DNS over HTTPS<\/a> (DoH) queries. DoH is designed to encrypt communications between a user\u2019s device and the DNS resolver, shielding domain lookups from eavesdropping. The existence of these certificates also raises concerns about their possible misuse in relation to other <a href=\"https:\/\/digitrendz.blog\/z\/topic\/cloudflare-services\/\" class=\"acp-topic-link\" data-topic-id=\"78630\" title=\"Explore: cloudflare services\" target=\"_blank\" rel=\"noopener noreferrer\">Cloudflare services<\/a>, including the <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/warp\/\" class=\"acp-entity-link\" data-entity-id=\"58903\" data-entity-category=\"Technology\" title=\"Learn more about Warp\" target=\"_blank\" rel=\"noopener noreferrer\">WARP<\/a> VPN<\/strong> offering.<\/p>\n\n<p class=\"wp-block-paragraph\">Despite being issued months ago, the certificates only came to public attention recently through an online forum discussion. Fina Root CA is included in the <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/microsoft-root-certificate-program\/\" class=\"acp-entity-link\" data-entity-id=\"99456\" data-entity-category=\"Organization\" title=\"Learn more about Microsoft Root Certificate Program\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Root Certificate Program<\/a><\/strong>, meaning the certificates were trusted by default on <a href=\"https:\/\/digitrendz.blog\/z\/entity\/windows\/\" class=\"acp-entity-link\" data-entity-id=\"284\" data-entity-category=\"Technology\" title=\"Learn more about Windows\" target=\"_blank\" rel=\"noopener noreferrer\">Windows<\/a> systems and in the <a href=\"https:\/\/digitrendz.blog\/z\/entity\/microsoft-edge\/\" class=\"acp-entity-link\" data-entity-id=\"26195\" data-entity-category=\"Technology\" title=\"Learn more about Microsoft Edge\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Edge<\/a> browser, which holds roughly five percent of the global browser market.<\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/digitrendz.blog\/z\/entity\/microsoft\/\" class=\"acp-entity-link\" data-entity-id=\"251\" data-entity-category=\"Organization\" title=\"Learn more about Microsoft\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a> has since acknowledged the issue, stating it has contacted the certificate authority to demand immediate corrective measures. The company also confirmed it is taking steps to add the certificates to its disallowed list to protect users. Notably, the statement did not address why the improper issuance went undetected for such an extended period.<\/p>\n\n<p class=\"wp-block-paragraph\">In contrast, representatives from Google and <a href=\"https:\/\/digitrendz.blog\/z\/entity\/mozilla\/\" class=\"acp-entity-link\" data-entity-id=\"10274\" data-entity-category=\"Organization\" title=\"Learn more about Mozilla\" target=\"_blank\" rel=\"noopener noreferrer\">Mozilla<\/a> clarified that their browsers, Chrome and Firefox, never trusted the certificates in question. Users of those platforms do not need to take any action. Similarly, Apple\u2019s Safari browser does not include Fina in its list of trusted certificate authorities. The identity of the party that requested or obtained the certificates remains unknown, as Fina representatives have not responded to requests for comment.<\/p>\n\n<p class=\"wp-block-paragraph\"><em>(Source: <a href=\"https:\/\/arstechnica.com\/security\/2025\/09\/mis-issued-certificates-for-1-1-1-1-dns-service-pose-a-threat-to-the-internet\/\" target=\"_blank\">Ars Technica<\/a>)<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Three mis-issued TLS certificates for the DNS resolver 1.1.1.1 were discovered, posing a serious security risk to encrypted DNS queries and potentially other Cloudflare services. The certificates, issued by a Microsoft-trusted authority, could have allowed interception of encrypted traffic on Win&#8230;<\/p>\n","protected":false},"author":1,"featured_media":41120,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[6579,3297,3327,3254],"tags":[64174,40408,64171,64176,64172],"entities":[64179,6444,64181,3844,64182,64180,817,3411,904,18419,64183,6081,40219,3565,955],"class_list":["post-41122","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bigtech-companies","category-cybersecurity","category-newswire","category-technology","tag-certificate-authority","tag-dns-over-https","tag-dns-security","tag-internet-infrastructure","tag-tls-certificates","entity-apnic","entity-ars","entity-asia-pacific-network-information-centre","entity-cloudflare","entity-fina-rdc-2020","entity-fina-root-ca","entity-google","entity-may","entity-microsoft","entity-microsoft-edge","entity-microsoft-root-certificate-program","entity-mozilla","entity-warp","entity-wednesday","entity-windows"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/41122","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=41122"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/41122\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/41120"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=41122"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=41122"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=41122"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=41122"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}