Attackers compromised three top-level domain registrars to mint counterfeit TLS certificates and impersonate Google and other large organizations.