Shibuya.XSS techtalk #12 ã®çºè¡¨è³æã§ãã English version is here: https://speakerdeck.com/masatokinugawa/pwn2own2022

Shibuya.XSS techtalk #12 ã®çºè¡¨è³æã§ãã English version is here: https://speakerdeck.com/masatokinugawa/pwn2own2022
è¿å¹´ã®ã½ããã¦ã§ã¢æ¥çã§ã¯ããã¹ãé¢é£æ´»åãæ ãã¨ã³ã¸ãã¢ããQAã¨ã³ã¸ãã¢ãã¨å¼ã¶ããã«ãªã£ã¦ãã¾ãããã QAï¼å質ä¿è¨¼ï¼ã¨ããè¨èã¯ãæ§æ¥ããäºã¤ã®å®ç¾©ãå ±åãã¦ããã»ããæ¥çå ã®éä¾ã§æ´ã«å¥ã®æå³ä»ããè¡ãããçµæãå®ç¾©ãææ§ã«ãªã誤解ãçã¿ãã¡ãªç¶æ ã¨ãªã£ã¦ãã¾ãã ããã§ä»åã¯ãæ¥æ¬èªåã§ãQAï¼å質ä¿è¨¼ï¼ã®è¨èãã©ã®ããã«å®ç¾©ããã¦ããããæ´çãã¦è§£èª¬ãã¾ãï¼çµè«ããããã¨ä¸æµæ´¾ããã¾ãï¼ å½éæ¨æºè¦æ ¼ã§ã®å®ç¾©ï¼å質ããã¸ã¡ã³ãã·ã¹ãã ã®å®è¨¼ IEEEãISOã¨ãã£ãå½éçãªæ¨æºè¦æ ¼ãããã³ããã«æºæ ããç¥èä½ç³»ãæ¨æºã§ã¯ãå¤ãããä½ç³»ç«ã¦ã¦å質ããã¸ã¡ã³ããå質ä¿è¨¼ãå質管çã®å®ç¾©ãè¡ã£ã¦ãã¾ãã æåãªæç®ã¨ãã¦ãå質ããã¸ã¡ã³ãã®æ¨æºè¦æ ¼ã§ãããISO 9000ï¼2015ã®å®ç¾©ãç´¹ä»ãã¾ãã ã¾ãISO 9000ã§ã¯ãå質ä¿è¨¼ã®åæã¨ãã¦å質ããã¸ã¡ã³ãã¨ããç¨èªã使ã£ã¦
åæ ãã®è¨äºã¯å 製éçºããã¦ããSaaSã®ä¸ã®äººã§ããã¨ã³ã¸ãã¢ããSaaSã®å 製ã½ããã¦ã§ã¢éçºãããä¸ã§ã®è©±ã¨ãã¦æ¸ãã¦ãã¾ãã åãµã ãã¹ã¯ã©ã ã§çç£æ§ã¯ä¸ãããªãããªãªã¼ã¹ã¹ã±ã¸ã¥ã¼ã«ãçãã¾ãããªãã§ããã ãä½ãåå ãªãã§ããï¼ã©ãããã°ãããã§ããï¼ã ã¨ããç¸è«ãåãã¾ããã NDAãæ¸ãã¦ãããã©ãã©ãã¨ãã¼ã ã®ç¶æ³ãè¦ã¦ã¿ã¾ããã 該å½ãã¼ã ã®ã¹ããªã³ãã´ã¼ã« 該å½ãã¼ã ã®ã¹ããªã³ãã´ã¼ã«ã¯ãããªæãã§ããã QAãã§ã¼ãºã®ããã¸ã§ã¯ãAããQAä½æ¥ãå®äºãã¦ãªãªã¼ã¹ã§ããç¶æ ã¾ã§é²ãã å®è£ ãã§ã¼ãºã®ããã¸ã§ã¯ãBãããã£ã¼ãã£ã¼ã®å®è£ çã50%ã¾ã§é²ãã è¨è¨ãã§ã¼ãºã®ããã¸ã§ã¯ãCããè¦ç¢ºèªãªç¹ãé¤ãã¦å®è£ ã¬ãã£ã¼ãªç¶æ ã¾ã§é²ãã ã¹ããªã³ãã´ã¼ã«ã3ã¤ããã¾ãããã¨ã¦ãé¢ç½ãã§ããã æãããã³ãã«ãå¿ã¿ãããªåå¿ãããããªãã¾ããããã¯å ã«é²ã¿ã¾ãããã
ã¾ãå¾åã®ã¤ã³ãã«ã®ã¢ãã«ã«ãªãã¨åãCPUã§ãç±è¨è¨ã§æ§è½ã大ããå¤ãã£ããããã¼ã¹ãæã®æ§è½ã ã£ãããããããããã®ã§ããã¾ã§ãæ°åã¯ç®å®ã§ãããç¡è¦ã§ããªãã»ã©å¤§ãããªã£ã¦ããã®ããããã¾ããç¹ã«ãRyzenãå æ°ãªãã5-6å¹´ã®ç«¶äºã«ããé²åããããã§ãã ãªã5-6åãæ§è½ãä¸ãã£ãã®ããã¨ããã®ãããã«è¨èã§ãã¡ãã¨èª¬æã§ãã人ã¯ãã¾ãããªãã¨æãã¾ããæè¿ãæ´æ°ããªããªã£ã¦ãã¾ããFacebookï¼ãªããåéã«ãã¦ããã ãã)ä¸ã§ãæ´»åãã¿ãããªãã¦ãæ²ããã®ã§ãããå¾è¤å¼èã®Weeklyæµ·å¤ãã¥ã¼ã¹ã®é£è¼ããã£ã¨èªãã§ãã人ã§ããã°ããå½ä»¤ãã³ã¼ãã¼ãå¢ããã®ããã¨ããªãã¨ãªãå¼·ããªã£ãé¨åã®ã¤ã¡ã¼ã¸ãã¤ãã¨ã¯æãã¾ããããã®ãªããã¨ããã®ã«ãå®é¨ä»ãã§æ°å¤ã®æ ¹æ ãå«ãã¦ãããããã説æãã¦ããã¦ããã®ãæ¬æ¸ã§ãã CPUå®é¨ããããããæ¬æ¸ã¯ãè±å¯ãªå³ã§(LambdaNo
ããã³ãã¨ã³ããã¹ãã«ãããç¥è¦ã®å®åº«ãçºè¦ï¼ãjavascript-testing-best-practicesãJavaScriptãã¹ãããã³ãã¨ã³ã ã¯ããã« JavaScriptã«ããããã¹ãã®ãã¹ããã©ã¯ãã£ã¹ãã¾ã¨ãããjavascript-testing-best-practicesãã¨ããGitHubã¬ãã¸ããªã大å¤åå¼·ã«ãªã£ããããç¹ã«åèã«ãªã£ãå 容ãã¾ã¨ãã¦å ±æãããã¨æãã¾ãã ï¼è£è¶³ï¼æ¬ã¬ãã¸ããªã«ã¯frontendã®ã¿ãªããbackendã®ãã¹ãã«é¢ããæ å ±ãããã¾ãããä»åã¯frontendã«ç¦ç¹ãå½ã¦ã¦å ±æãã¾ãããã®ããæ±ãSectionã¯ä»¥ä¸ã®4ã¤ã§ãã Section 0: The Golden Rule Section 1: The Test Anatomy Section 3: Frontend Section 4: Measuring Test
ããã«ã¡ã¯ï¼éç¬å· ( https://twitter.com/gyakuse ) ã§ãã ä»æ¥ã¯è±èªè«æããµã¯ãã¨ç¿»è¨³ããæ¹æ³ãå ±æãã¾ãã ç´ æ´ãããäºåå¦ç¿æ¸ã¿ã¢ãã«ã®æ©æµã§ç´ 人ã§ã1æéç¨åº¦ã§å®è£ ã§ãã¦ãã¾ãã¾ãã ãªããå®è£ ãã¡ãæ±ãã®ã§ããããã®ãããã¯ã容赦ãã ããã è«æ以å¤ã®æååãè¾¼ã¿ã®ãªãpdfã翻訳ãããå ´åã¯ãã¡ããåèã«ãã¦ãã ãã: è«æå ¨ä½ã®èªåè¦ç´ã«ã¤ãã¦ã¯ãã¡ã: æ¦è¦ 翻訳ã¢ãã«ãã¬ã¤ã¢ã¦ãæ¤ç¥ã©ã¤ãã©ãªã¨pdfãæä½ããã©ã¤ãã©ãªãç¨ãã¦å¤å½èªã§æ¸ãããpdfãã¡ã¤ã«ã翻訳ãã¾ãã 翻訳ã«ã¯ããªã¼ã®ãã¥ã¼ã©ã«æ©æ¢°ç¿»è¨³ã¢ãã«FuguMTã使ç¨ãã¾ãã ãã®ææ³ã®å¬ãã DeepLããã³DeepL APIã§ã¯pdf翻訳ããµãã¼ãããã¦ãã¾ãããè¡ã®åãæ¿ããã§å¥ã®æç« ã¨èªèããããã¨ãå¤ããéä¸ã¾ã§ã®æç« ã§ç¿»è¨³ããããã精度ãè½ã¡ã¦ãã¾ãã¾ã ãã®ææ³ã§
å æ¥ãè²å ãªã©å®¶åºã®è²ã ããã£ã¦èªåã®æéã確ä¿ã§ããªããªã£ããæè¡åãé«ããããã®åå¼·ãã§ããªãã¦ä¸å®ããã¿ãããªè©±ãèãã ãã®æ©ã¿ã®ç´æ¥çãªè§£æ±ºæ¹æ³ã¨ãã¦ã¯å 人ã®æ§ã ãªä½é¨è«ããã³å¯¾çã¿ãããªãã®ãä¸ã«åºåã£ã¦ããããã家åºã®ç¶æ³ã«å¿ãã¦åç §ããã°ããæã åè²ã¦ã¨éçºã両ç«ããã³ãã¯ãç¡çãããªããã¨ããããï¼ããã¨ã³ã¸ãã¢ã®åãæ¹ã¨ã¯ åè²ã¦ãæ¯ããæè¡ â ãã«ã¹ã¿ãã¯ãç¶ããã¨ã¨ã³ã¸ãã¢ã¨ãã¦ã®æé·ã両ç«ãããã«ã¯ ITã¨ã³ã¸ãã¢ã¨åè²ã¦ã¨å強㨠ããããããæè¡åãé«ããããã®åå¼·ãã§ããªãã¦ä¸å®ãã¨ããç¹ãå人çã«ã¯æ°ã«ãªã£ã æè¡åã¨ã¯ä½ãï¼æè¡åãé«ããªãã¨ãªãä¸å®ãªã®ãï¼ã¿ãããªè©± æè¡åã¯ç¹ã«æ確ãªå®ç¾©ãããããã§ã¯ãªã ä¾ãã°èåãªOSSã«ã³ããããã¦ããã¨ãä½ã¬ã¤ã¤ã¼ã®ãããã³ã«ãã¤ã³ãã©ãããªããªå®è£ ãã¦ãã¨ã競ããã§ä¸ä½å¢ã ã¨ããæãå§ãããããªããªããã
ã¿ãªããããã¯ãããããã¾ãï¼ CARTA fluct ã¨ã³ã¸ã㢠㮠ãªã£ãã¼@konsent_nakka ã§ãã CARTA TECH BLOG ã¢ããã³ãã«ã¬ã³ãã¼ 12/14ã¨ãããã¨ã§ãæ®æ®µDBã®ããã¯ã«ã¤ãã¦ãã¾ãæèãããã¨ããªã人ã«åããå®ã¯è¦ãã¦ããããããã¯ã«ã¤ãã¦ã®ç¥èããã£ã¨ã¾ã¨ãã¦ã¿ã¾ããã ã¨ããããããã ãèªãã§ããã°æä½éã¯å°ããªããããä½ãå°ã£ãæã«ã¯ãããã§åºã¦ããå 容ãããå°ãæ·±ã調ã¹ã¦è¦ãããã¨ãããã£ããã«ãªãã°è¯ããªã¨æãã¾ãã å³å¯ãªå®ç¾©ãããæ®æ®µDBãæ±ãä¸ã§ããã¯ã«ã¤ãã¦ãã¾ãæèãããã¨ããªããããªäººã«ããã£ã¨å ¥ã£ã¦ããããã«ç°¡åãªè¡¨ç¾ãåªå ãã¦æ¸ãã¦ãã¾ãããäºæ¿ãã ããã ç®æ¬¡ çæäºé æä»ããã¯ã¨å ±æãã㯠ãã©ã³ã¶ã¯ã·ã§ã³åé¢ã¬ãã« SELECTã®ããã¯ã¬ãã«ãå¤æ´ãã å ±æããã¯: LOCK IN SHARE MODE æä»ã
ã¯ããã«SHIFT DAAE ã® shinagawa ã§ãã表é¡ã®éãNode.jsã§ä½æããã³ã³ããã®ã¤ã¡ã¼ã¸ãµã¤ãºã®è»½éåã«ææ¦ãã¾ããã èæ¯è¿å¹´ã®å¤æ§åã»é«éåãããã¸ãã¹ã«å¯¾å¿ããITã·ã¹ãã ã®æ§ç¯ãå®ç¾ãããã¯ã©ã¦ããã¤ãã£ããã®æ§æè¦ç´ ã®ä¸ã¤ã¨ã㦠ãã³ã³ãããã¨ããä»®æ³åæè¡ãåå¨ããå½é¨éã§ãæ´»ç¨ãé²ãã¦ããã¾ãã ãã®ã³ã³ããã¤ã¡ã¼ã¸ãä½æããã«ã¯ã¢ããªã±ã¼ã·ã§ã³ã³ã¼ããã©ã¤ãã©ãªã»ã¢ã¸ã¥ã¼ã«ãªã©ã®ä¾åç©ãã©ã³ã¿ã¤ã çã1ã¤ã®ã¤ã¡ã¼ã¸ã¨ãã¦çµã¿ç«ã¦ã¦ä½æãã¾ããã ãã®æ§æè¦ç´ ãå¢ããã¨ã¤ã¡ã¼ã¸ãµã¤ãºãè¥å¤§åãä¿ç®¡æã®ã¹ãã¬ã¼ã¸ã®ã³ã¹ãã®å¢å ãã¤ã¡ã¼ã¸ã®è»¢éãç°å¢ã¸ã®å±éã«æéãããããã¨ã«ãªãã¾ãã å¾ã£ã¦ã¤ã¡ã¼ã¸ã®ãµã¤ãºãåæ¸ãããã¨ã¯ããããã®ç¹ãæ¹åãããã¨ã«ã¤ãªããã¾ãã ããã§ã¯ãããä¸ã§ç´¹ä»ããã¦ãããããããæã¡æãçµã¿åããã¦ã³ã³ããã¤ã¡ã¼ã¸ã®è»½éåã«
12æ10æ¥ã®2022ã½ããã¦ã§ã¢ãã¹ãã¢ããã³ãã«ã¬ã³ãã¼ã§ãã Launchable社ã§ã¨ã³ã¸ãã¢ã¨ãã¦åãã¦ããcvuskã¨ç³ãã¾ããæ©æ¢°å¦ç¿çéã§ã¯æ©æ¢°å¦ç¿ãå®ç¨åããããã®ã·ã¹ãã éçºã®æ¬ãæ¸ãã¦ããã¾ããããè¯ãã£ããèªãã§ã¿ã¦ãã ããã ãæ©æ¢°å¦ç¿ã·ã¹ãã ãã¶ã¤ã³ãã¿ã¼ã³ã ãæ©æ¢°å¦ç¿ã·ã¹ãã æ§ç¯å®è·µã¬ã¤ãã æ¬ããã°ã§ã¯æ©æ¢°å¦ç¿ãç¨ãã¦ãã¹ãå®è¡ãå¹çåããææ³ã¨ãã¦ãPredictive Test Selectionã«ã¤ãã¦èª¬æãã¾ãããã¹ãå®è¡æéãã³ã¹ãã§èª²é¡ãæ±ãã¦ããã¨ã³ã¸ãã¢ã«å½¹ã«ç«ã¤ã¨å¹¸ãã§ãã æ¨ä»ã®éçºã«ããããã¹ãäºæ 2002å¹´ã«ããã¹ãé§åéçºããä¸ã«åºã¦ãã½ããã¦ã§ã¢éçºã§ãã¹ããæ¸ããã¨ã常èã«ãªã£ã¦æ©20å¹´ãçµã£ã¦ãã¾ãããã®éã«ã¯ã©ã¦ãã®ç»å ´ãDevOpsã®æ®åã«ããããã¹ããCI/CDãã¤ãã©ã¤ã³ã§èªåå®è¡ããã³ã¼ãã¨ãããã¯ãå質ãç¶æã
ã¿ãªããããã«ã¡ã¯ã@ryuzeeã§ãã 2022å¹´12æ9æ¥ã«è¡ãããã¤ãã³ããDevelopers CAREER Boostãã®ç»å£è³æãå ¬éãã¾ãã ä»åã¯ããããã¼ã¸ã£ã¼ãã¨åã®ã¤ãè·ç¨®ãåé¡ãã¦ãããããã®è·åãå®ç¾©ã確èªããä¸ã§ãæå¹ãªããã¼ã¸ã£ã¼ã§ããã«ã¯ã©ããããããããæ´çãã¦ã¿ã¾ããã è³æãä½ãã«ããã£ã¦ãéå»ã®æ¥è¨ãèªã¿è¿ãããè¨æ¶ãæãèµ·ãããããã¦ãå½æã®æ´»åãåºæ¥äºãæ©ã¿ãæ´çãã¦ã¿ãã®ã§ãããèªåã¯ãã£ã±ãããã¼ã¸ã£ã¼ã«åãã¦ããªããå¿åãã¦ããªããã¨ãå確èªã§ãã¾ããï¼ç¬ï¼ã å ¨å¡ãããã¼ã¸ã£ã¼ã«ãªããªããã°ãããªããªãã¦ãã¨ã¯ãªããèªåãæ¥ã 楽ããéããããã£ãªã¢ãé¸æããã°ããã¨æãã¾ãããè³æãå°ãã§ãå½¹ã«ç«ã¦ã°ããããéãã§ãã
ã¡ãã£ã¨æã¾ã§ã¯ãã¼ã¿åºç¤ã®ç®¡ç人ã»ã¢ã¼ããã¯ã, ç¾å¨ã¯æãã£ããã¯ã©ã¦ãã¢ã¼ããæ±ãã³ã³ãµã«ã¿ã³ãã«ãªã£ããã³ã§ã. ç§èªèº«ã®çµé¨ã»ã¹ãã«ã»ãã®ããã°ã«æ¸ãã¦ããã³ã³ãã³ãã®é¢ä¿ã§, ããã¼ã¿åºç¤ã£ã¦ä½ã使ã£ã¦ä½ãã°ããã®?ãçãªHowï¼ãããã¯Whereï¼ã®ç¸è«. ãGoogleã®ããã°ã¯ã¨ãªã¼ã£ã¦ãã¤ãããã¨èãããã©ä½ãã§ããã®?ãçãªåå¥ã®ãµã¼ãã¹ã«å¯¾ãããç¸è«. ãã¶ã£ã¡ãããããããããã¾ããð¸ãã¨ããHow much?ãªè©±. æãé£ãããã®ãããªã話ããããåããã¦ãã¾ã. ã, ï¼ä»äºä»¥å¤ã®å¶ã¿ã«ãããï¼å人ã¨ãã¦ã¯æ¯åº¦åã話ãããã®ã¯ã¾ãã¾ãç²ããã®ã§, ãã¼ã¿åºç¤ã«ãããã¡ãªãä½ã使ã£ã¦ä½ãã°ãããï¼ãã¨ããåãã«å¯¾ããå¦æ¹ç® ã¨ãããã¼ãã§, ã¯ã©ã¦ãä¸ã§ãã¼ã¿åºç¤ãæ§ç¯ããéã®ãµã¼ãã¹ã®é¸ã³æ¹ ï¼ãã¼ã¿åºç¤ã«éããï¼ã¯ã©ã¦ãæéã®åºæ¬çãªèãæ¹ ãGoogle
JJUG CCC 2022 Fallã§ãJavaã®å ¥éãçµãã£ããä½ã®åå¼·ãããã°ããã®ï¼ãã¨ããå 容ã§çºè¡¨ãè¡ãã¾ããã åºæ¬çãªãã®ãä½ããããã«ãªã£ããã©ããã¤ãã¤ãããã°ã©ã ãçµããªãã¨ããã¨ãã«ãä½ãåå¼·ããã°ããããã¾ã¨ãã¾ããã å ¥éãçµãã£ã¦ä½ããããã®ãããã°ä½ã£ã¦ããã¾ããããæ¥åã§è¨ããããã®ãä½ã£ã¦è¡ãããã§ããªãã ãã¡ããã¨ãããã®ãä½ããªããªããã£ã¨ã¡ããã¨ãããã®ãä½ãããã次ã®ã¹ãããã«é²ã¿ããã¨ããã¨ãã«åå¼·ãã¦ããæãã§ãã è³æã¯ãã¡ãã§ã ã¨ããããæ¬ã«ã¤ãã¦ã¾ã¨ãã¦ããã¾ãã éçºä½æ¥ã«ã¤ã㦠æ¦è¦ ããã°ã©ãã³ã°è¨èª ã¢ã¼ããã¯ã㣠ããã«ã¦ã§ã¢ ãããã¯ã¼ã¯ ããã㤠çè« éçºææ³ éçºããã»ã¹ ã¾ã¨ã ãã¬ã¼ã ã¯ã¼ã¯ã¯å ¥éã§ãã£ã¦ãåæã§ããJavaå ¥éæ¸ãããã«ãªãJavaãã§ã¯Javaã®åºæ¬ããç°¡åãªDBæä½ãSpring Bootã¾ã§
ã¯ããã« TwitterãQiitaãZenn...ã¨ããããªã¨ããããæ å ±åéããã®ã¯ããã®ã§ãããããããã®æçãªæ å ±ãããããã®ãµã¤ãã«ãæ°ã«å ¥ãã¨ãã¦ä¿åãã¦ããã®ã§ãå¿ è¦ãªæ å ±ãæ¢ãã ãã§ä¸è¦å´ã§ãã ããã§ä¸è¦§ã«ãã¦ã¾ã¨ãã¦ãããã¨ã«ãã¾ããã ãã ããç¹å®ã®è¨èªã«ä¾åãããããªè¨äºã¯ããã¦æé¤ãã¦ãã¾ãã çããã«ã¨ã£ã¦ãæçãªæ å ±ãããã¨ããã®è¨äºãå ¬éãã¦è¯ãã£ããªã¨æãã¾ãã ã¾ããçããã®ãªã¹ã¹ã¡ã®è¨äºãããã¾ããããã³ã¡ã³ããªã©ã§æãã¦ãã ããã ã³ãã¥ãã±ã¼ã·ã§ã³ 質å 質åã¯æ¥ã§ã¯ãªããå½¹ã«ç«ã¤ https://qiita.com/seki_uk/items/4001423b3cd3db0dada7 æ°åããã®è³ªåãã½ã·ã£ã²ã£ã½ãä»çµã¿ã«ãããæã£ã話 https://qiita.com/ysktsuna/items/fced3a9515c8f585ca50 ä¼
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}