ç±³Mozilla Foundationã¯2æ25æ¥ï¼ç¾å°æéï¼ãç±³å½ã®Firefoxã¦ã¼ã¶ã¼ã«å¯¾ãããDNS over HTTPSï¼DoHï¼ããããã©ã«ãã§æå¹ã«ããã¨çºè¡¨ãããåããæ°é±éãããã¦ãã¼ã«ã¢ã¦ãããã主è¦Webãã©ã¦ã¶ã¨ãã¦ã¯Firefoxãåã ã DoHã¯ãå¹³æã§è¡ããã¦ããDNSã¸ã®åãåããã¨å¿çããHTTPSãç¨ãããã¨ã§æå·åãããããã³ã«ãç¾å¨IETFã§æ¨æºåãé²ãã¦ãããMozillaã¯ãDoHãæå¹ã«ããã°ãISPãªã©ãã¦ã¼ã¶ã¼ã®ãã©ã¦ã¸ã³ã°å±¥æ´ãå¶å©ç®çã§ä½¿ããã¨ãã§ããªããªãã¨èª¬æããã DoHãæå¹ã«ããã¨ãDNSã«ãã¯ã¢ããã¯æå·åãããããWebãã©ã¦ã¶ãæ¥ç¶ããDNSãµã¼ãã«ã¯Webãµã¤ãã表示ããããããã§Mozillaã¯ãä¿¡é ¼ã§ããDNSãããã¤ãã¼ã¨ãã¦Cloudflareã¨NetDNSãé¸ãã ã DoHãç±³å½ä»¥å¤ã§ãããã©ã«ãæå¹ã«ããã
ãµã¼ãã¹å 容 IIJ Public DNSãµã¼ãã¹ï¼ä»¥ä¸ãæ¬ãµã¼ãã¹ï¼ã¯DNS over TLSï¼DoT/RFC7858ï¼ãDNS over HTTPSï¼DoH/RFC8484ï¼ãå©ç¨ããåå解決ãµã¼ãã¹ã§ãã DoTãDoHã¯ãå¾æ¥ç¨ãããã¦ããDNSã«å¤ããåå解決ã®ããã®ãããã³ã«ã¨ãã¦éçºãé²ãããã¦ãã¾ãã IIJã§ã¯ãDoTãDoHã«ããåå解決ã®å®ç¨æ§ã®ç¢ºèªãã¾ããDoTãDoHã«å¯¾å¿ããDNSãµã¼ãã®éç¨ãã¦ãã¦ã®ç²å¾ã®ããã試é¨çã«DoTãDoH対å¿ã®åå解決ãµã¼ãã¹ãæä¾ãããã¾ããæ¬ãµã¼ãã¹ã¯public DNSã¨ãã¦ãIIJããå¥ç´ã®æ¹ä»¥å¤ã§ããå©ç¨ããã ããã¨ãã§ãã¾ãã DoTãDoHã«ãèå³ããããæ¬ãã¼ã¸ã§ãæ¡å ã®æ¡é ã«åæããã ããæ¹ã¯ããå©ç¨ä¸ã®ãã½ã³ã³ã»ã¹ãã¼ããã©ã³ã«è¨å®ãè¡ããã¨ã§ãæ¬ãµã¼ãã¹ãå©ç¨ããåå解決ãè¡ããã¨ãã§ãã¾ãã DoTãDoH
æ±ç¨JPãã¡ã¤ã³ã®æ±ãã10æ¥ä»¥å ã«è¿äºããªãã¨â¦â¦ ä»å被害ã«éã£ãã©ãã©ã¤ãï¼å ¬å¼ãµã¤ãã®ãã¡ã¤ã³ã¯ãââ.jpãã¨ããå½¢å¼ã§ããæ±ç¨JPãã¡ã¤ã³ãã¨å¼ã°ããã æ±ç¨JPãã¡ã¤ã³ã®ç»é²ã»ç®¡çã¯æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ï¼JPRSï¼ãè¡ã£ã¦ãããJPRSã¯ãã¤ã³ã¿ã¼ãããã¤ãã·ã¢ãã£ããGMOã¤ã³ã¿ã¼ããããªã©ã®åæå®äºæ¥è ï¼ã¬ã¸ã¹ãã©ï¼ãããã¡ã¤ã³åã®ç»é²æç¶ããªã©ãåããã ãã¡ã¤ã³åãç»é²ãããã¨ã³ãã¦ã¼ã¶ã¼ã¯ãã¬ã¸ã¹ãã©ãå販ã»å次äºæ¥è ï¼ãªã»ã©ã¼ï¼ã«ç³è«ãããã¨ã«ãªãã ãã¡ã¤ã³åã¯è¤æ°ã®ã¬ã¸ã¹ãã©ããªã»ã©ã¼ãç»é²æ¥åãè¡ããããããã¦ã¼ã¶ã¼ããããã¡ã¤ã³åãåå¾ãããã¦ããä»ã®ã¬ã¸ã¹ãã©ã§ãã®ãã¡ã¤ã³åããã§ã«ç»é²ããã¦ããå ´åãããã ãã®å ´åã«çºçããã®ãããã¡ã¤ã³ç§»ç®¡ãã§ãæç¶ãã«é¢ããè¦åã¯JPRSãå®ãã¦ããã JPRSã®ãæ±ç¨JPãã¡ã¤ã³åç»é²ç³è«çã®å次ã«é¢ããè¦å
ãªãä»ã¾ã§ã®DNSã§ã¯åé¡ãããã®ã ã¤ã³ã¿ã¼ãããä¸ã®éä¿¡ã®å¤ãã¯ããã©ã¦ã¶ãå©ç¨ããã¦ã§ãã«ãããã®ã§ãã ã»ãã¥ãªãã£åä¸ã®ãããGoogleãFireFoxã¨ãã£ã大æãã©ã¦ã¶ãã³ãã¼ãå¹³æéä¿¡ã§ããHTTPããæå·éä¿¡ã§ããHTTPSã¸ã®ç§»è¡ãæ¨å¥¨ããçè´ã»æ¹ç«ã»ãªããã¾ãã¨ãã£ãåé¡ã解決ãããã¨ãåºæ¥ã¾ãã ããããªããããã®HTTPSéä¿¡ãããåã®DNSã«ãããã¡ã¤ã³è§£æ±ºã¯æå·åããã¦ãããçè´ã§ã¢ã¯ã»ã¹ãããã¹ãåãææ¡ãããããªããã¾ãã§å½ã®å¿çãè¿ãããã¨ãã£ãå¯è½æ§ãããã¾ãã ãããé²ãããã®æ¹æ³ã®1ã¤ããDNS over HTTPSã§ãã DNS over HTTPSã¨ã¯ ä»ã¾ã§DNSãµã¼ãï¼ãã«ãªã¾ã«ãï¼ã®ï¼ä¸»ã«ï¼UDPãã¼ã53çªã«å¯¾ãã¦è¡ããã¦ããDNSã«ããåå解決ããTCPãã¼ã443çªã«å¯¾ããHTTPS(HTTP/2 over TLS)éä¿¡ä¸ã§è¡ãã
8æ24æ¥ã«éå¬ããããç¥ç財ç£æ¨©æ¬é¨ ã¤ã³ã¿ã¼ãããä¸ã®æµ·è³ç対çã«é¢ããæ¤è¨ä¼è°ã(第5å) ã®è°è«ã«å¯¾ãã¦ã¾ã¨ãããã以ä¸ã® togetter togetter.com ã«ã¤ãã¦ãæãã¨ããããã¤ã¼ããããã¨ããã ãã¯ã³ã´CTOã®è©æ¸ã§å·ä¸éçæ°ãæ¿åºä¼è°ã«æåºããè³æããã³ãã²ã©ããã ãã©ããã¯ã³ã´å ã®è¯èããã¨ã³ã¸ãã¢è«¸æ°ã¯ãããè¯ãã¨ããã®? ãã¯ã³ã´ã¯ã¤ã³ã¿ã¼ããããç ´å£ãã¦éç¾ãä½ãæ°? / âãéå ±ï¼ è§å·ã®ä»£è¡¨åç· å½¹ãå人ãâ¦â https://t.co/sPD3BtT6aEâ KOYAMA Tetsuji (@koyhoge) 2018å¹´8æ30æ¥ å·ä¸éçæ°æ¬äººãã詳細ãæããã«ããã¨ã®ãªãã©ã¤ãæ¥ãã®ã§ãèªåã®èããåé¡ç¹ãã¾ã¨ãã¾ãã OP53B ã«ã¤ã㦠ä¸æ§ã« OP53B ãå®æ½ããã¨ãçµç¹å ã®ãã£ãã·ã¥DNSãµã¼ããããåå解決ã§ããªãã¨ããæ¬æ«è»¢åãªè©±
ä»åã®ã¤ã³ã¿ã¼ããã10åè¬åº§ã§ã¯ãæ°gTLDã®å¤§éå°å ¥ã«ä¼´ãæ°ããªã»ãã¥ãªãã£ãªã¹ã¯ã¨ã㦠æ¸å¿µããã¦ããããååè¡çª(Name Collision)ãã¨å¼ã°ããåé¡ã«ã¤ãã¦ããã®æ¦è¦ã¨å¯¾çã 解説ãã¾ãã å é¨åãã®ãã¡ã¤ã³åã¨æ°gTLDãéè¤ãããååè¡çªãã¨ããåé¡ 2013å¹´å¾åãããã.comãã.netããªã©å¾æ¥ã®gTLD (generic Top Level Domain; åéå¥ãããã¬ãã«ãã¡ã¤ã³)ã«å ãã¦ãæ°ãã«gTLDãå¤æ°è¿½å ããããã¨ã«ãªãã¾ããããããã®ä¸ã«ã¯ãä¾ãã°ã.engineerãã.softwareãã.hostããªã©ããã使ãããæååãä¸å¿ã«ãã¾ãã¾ãªæååãå«ã¾ããä»å¾gTLDã¨ãã¦ç»é²ããããã¨ãã¦ãã¾ãã ãã®ä¸æ¹ã§ãä¼æ¥å ã®ãã©ã¤ãã¼ããããã¯ã¼ã¯ã家åºå ã®LANãªã©ã§ãå é¨åãã«ä»ã¾ã§gTLDã«åå¨ãã¦ããªãååãä¾ãã°ã.corpãã
å¥ã«è¨ã£ã¦ããããã 以ä¸æ³å®åçã ã浸éãä½ãæå³ãã¦ããã®ãããããªãã ãã³ãï¼ ã浸éãããªãã£ã¦è¨ããã¦ãã£ã¦ãã¨ã¯ãéã«è¨ãã¨ãããªãã«åºã使ããã¦ãã£ã¦ãã¨ã§ããã å人çã«ã¯ãDNSã®è¨å®ãå¤æ´ããå¾ãå¾ã ã«æ°ããæ å ±ãè¦ããã¨ãã§ããã¯ã©ã¤ã¢ã³ããå¢ãã¦ããããã¨ã ã¨æã£ã¦ããã ãã©ãããã¨ã¯ç°ãªãæå³ã§ä½¿ããã¦ããããã®ï¼ ã"浸éã«æ°é±éããã" ãªãã¦è¨ãã®ã¯ã¸ã¼ãæ¥è ã®è¨ã訳ã ããã¯åæã ãã©ãã浸éãã¨ããåèªã®åé¡ãããªãããã ã浸éãã¨ããåèªã使ããªãã¦ããã®æ¥è ã¯ã¸ã¼ãã¾ã¾ã§ãæ°é±éãããã®ã¯å¤ãããªãã æ°é±éãããªãã¦ãã浸éã«ã¯5åããããããã¾ããã ã£ããOK? ãè¨å®ãã¹ã£ã¦ãããã«æµ¸éã«æéãããããªãã¦è¨ã訳ãããªããªãããããã©ãã浸éã¨ããåèªã使ããªãã¯ããããã¨æããã浸éãã使ããªããã¨ã§ä½ã解決ããã®ï¼ ã浸éãªãã¦ç¨èªã¯
ä»äºã§å¤é¨ã®ã¨ã³ã¸ãã¢ã«ä¾é ¼ãããã¡ã¤ã³ç§»è¡ãæ£ããåä½ãã¦ããªãã£ããããè¯ãæ©ä¼ã¨æãDNSã«ã¤ãã¦èª¿ã¹ã¾ããã åå解決ã®æ¹æ³ ããããåå解決ã¨ã¯ä½ãã¨ããã¨ããã¡ã¤ã³ã¨IPã¢ãã¬ã¹ãç´ä»ãããã¨ã§ããææ³ã¨ãã¦ä»¥ä¸ã®2ã¤ãä¸ãããã¾ãã /etc/hostsã«ç´æ¥å¯¾å¿ãè¨è¿°ããæ¹æ³ /etc/resolve.confã«DNSãµã¼ãã¼ã®IPã¢ãã¬ã¹ãè¨è¿°ããåãåãããæ¹æ³ ä»åã¯DNSãµã¼ãã¼ã«ããåå解決ã«ã¤ãã¦èª¬æãã¦ããã¾ãã DNSã«ããåå解決 ãã¡ã¤ã³ããªã¼ã«ããè² è·åæ£ å ¨ä¸çã«ç¡æ°ã«åå¨ãããã¡ã¤ã³ã®è§£æ±ºãä¸å°ã®ãã¼ã ãµã¼ãã¼ã§æ å½ããã®ã¯ä¸å¯è½ã§ããããã§DNSã§ã¯ä¸è¨ã®ããã«ãåé層ã«æå³ãæãããä¸ä½ã®ãã¡ã¤ã³ã管çããããã¨ã§åæ£åã®æ§é ãæ§ç¯ãã¦ãã¾ãã ãã¡ã¤ã³ããªã¼ ãã£ãã·ã¥ãµã¼ãã¼ã«ããé«éå ã¯ã©ã¤ã¢ã³ãããDNSãµã¼ãã¼ã«å¯¾ãã¦ãã¡ã¤ã³ãåã
DNS ã®åå解決ã¯éããªãããããã¾ãããããã®å¾ã®æ¥ç¶å ãé ããªã£ã¦é ããªãããããã¾ããã ãã©ã¤ãã·ã¼éè¦ãªãåãæ¿ãã¦è¡ã£ã¦ããããããã¾ããããé度ã®ããã«åãæ¿ããã®ã¯ã¡ãã£ã¨å¾ ã£ã¦ãã ããã Google Public DNS ãåæã®é ã¯åãåé¡ããã£ãã®ã§ãæéãçµã¦ã°è§£æ±ºãããããªæ°ããã¾ãããCDN ã使ã£ã¦ãããµã¤ããé ããªãå¯è½æ§ãããã¾ãã 以ä¸ããããã¹ãããã®å®æ¸¬ã ããã«ã¯çµæãè¼ãã¾ããããtraceroute ããã¦ã¿ãã¨ãé ããªã£ã¦ããã®ããããã¾ãã DNS ã®æ£å¼ã DNS ã®å¿çã¯éãã§ãã ããã¯ãããæå¥éãã§ãã Query time ã®ã¨ãããããã£ãæéã§ãã % dig www.google.com @1.1.1.1 ; <<>> DiG 9.10.3-P4-Ubuntu <<>> www.google.com @1.1.1.1
Cloudflareã1.1.1.1ã§è¶ é«æ§è½DNSå§ãããããã£ã¡ã俺ã®ãã½ã³ã³ãDNS over HTTPSãã¦ã¿ã ã¯ãã©ããï¼ãã¼ãã£ã«Youtuberã®ãã®ãã¡ãã§ãï¼ å æ¥ãCloudflareã 1.1.1.1:53 ã§ãããªãã¯DNSãå§ãããã¨ã話é¡ã«ãªã£ã¦ã¾ããããGoogleã8.8.8.8ã§ãã£ã¦ãããã¨åãã§ãã ããããããè¶ éããã§ããããèªåã®æå ããã ã¨ã8.8.8.8ã®10åéãã 1.1.1.1ã®ä¸»ãªç¹å¾´ ãã°ãä¿ç®¡ããªããç ´æ£ããã IPv6 å¯¾å¿ DNSSEC ã®å¯¾å¿ DNS over HTTPS ã®å¯¾å¿ DNS over SSL ã®å¯¾å¿ ⦠IPã¢ãã¬ã¹ 1.1.1.1 1.0.0.1 2606:4700:4700::1111 2606:4700:4700::1001 è¦ããããã¦ããã§ããã DNS over HTTPS DNS over HT
ãç¥ãã
é害
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}