é«æ¨æµ©å ããã®ã¦ã¼ã¶ã¼ãã¼ã¸ã§ãã
On Wed, 3 Jun 2009, Rik van Riel wrote: > > Would anybody paranoid run their system without SELinux? You make two very fundamental mistakes. The first is to assume that this is about "paranoid" people. Security is _not_ about people who care deeply about security. It's about everybody. Look at viruses and DDoS attacks - the "paranoid" people absolutely depend on the _non_paranoid people being secu
大å¤ãç¡æ²æ±°ã§ããç´1å¹´åã¶ãã®æ´æ°ã§ãã æ¨æ¥ãããã°ãè¨ç½®ãã¦ãããµã¼ãã§OSã®ã¢ãããã¼ãã«åé¡ãçºçããããããããæ©ã«æ°ãµã¼ãã»æ°OSã«ä¹ãæãããã¨ã«ãã¾ããã ç¾å¨ã®ããã°ããã«ããµã¤ãã®ããããã®ã¾ã¾ã§ã¯æ°ãµã¼ãã®æ§ç¯ã«è¦æ¦ããã¨äºæ³ããããããä»ã®ããã°ã®è¨äºãçµ±åãã¾ããã çµ±åå 容ã¯ä»¥ä¸ã®éãã§ãã ã»C-Production ã»ã»ã» ã¡ã¤ã³ãµã¤ãã®ãããä»ã®ããã°ãå¸åãã¦ç¶ç¶ã ã»âª8thNote⪠ã»ã»ã» ã¡ã¤ã³ãµã¤ãã«çµ±åæ¸ã¿ã ã£ãã®ã§ãåé¤ã ã»ã¢ãã¤ã«é ã»ã»ã» ã¡ã¤ã³ãµã¤ãã«è¨äºãå¼ãç¶ãã並è¡ç¨¼åä¸ã ã»ç¡ç·ã®ããã¥ã¡ã³ã ã»ã»ã» ãã¨ãã¨ééäºå®ã ã£ãã®ã§ããã®ã¾ã¾åé¤ å¤é¨SNSã®ã¢ã«ã¦ã³ãã«ã¤ãã¦ã¯ãã®ã¾ã¾ç¶ç¶ãã¾ãã ä»å¾ã¨ããããããé¡ããã¾ãã
ã¤ãã¼ã®ç»åã¯ãªãyimg.jpãã¡ã¤ã³ãªã®ãï¼ ãµã¤ãé«éåã®ææ³ã¨ã¤ãã¼ã®å¤±æä¾ ã§ã¤ãã¼ããªããã¡ã¤ã³ãå¤ãã¦ç»åãµã¼ããéç¨ãã¦ããããæ¸ããã¦ãã.ãéçãªã³ã³ãã³ãã«å¯¾ãã¦ã¯ããã¼ããªã¼ãã¡ã¤ã³ã使ããã¨ã«ãã£ã¦é度åä¸ãçããã¨ããã®ãçç±ã¨ãã£ã¦,ããã¯ããã§ãã¡ããæ£ããã®ã ããã©,ããã¯ã©ã¡ããã¨ããã¨å¯æ¬¡çãªçç±ã§æ¬å½ã®çç±ã¯éã. ã¯ããã¼ããªã¼ãã¡ã¤ã³ã使ããã¨ã§æªæããFlashã³ã³ãã³ããªã©ããèªç¤¾ãã¡ã¤ã³ã®ã¯ããã¼ãå®ãããã¨ããã®ãæ¬å½ã®çç±ã§,ããã¯ãã¡ãã¡ã§ä½¿ããã¦ãããã¯ããã¯ã .Flashã³ã³ãã³ãã¯å¤é¨ã®æ¥è ããã«ä½ã£ã¦ããã£ãã,åºåã®å ¥ç¨¿ç´ æã¨ãã¦å ¥ã£ã¦ããã®ã§,ä¿¡é ¼ã§ããªããã¼ã¿ã¨ãã¦åãæ±ãå¿ è¦ããã,ä¸ä¸ã¾ãããã¼ã¿ãã¢ããããããã¨ããã£ã¦ã大ä¸å¤«ã«ãã¦ããå¿ è¦ããã. æè¿ã¦ã¼ã¶ããã®ä»»æã®ã³ã³ãã³ããåãã¤ãã¦åä¸ãã¡ã¤ã³ã§é ä¿¡ã
YUI Blog Development Crockford Speaks on "Fixing the Web" and Appears on Channel 9 Crockford Speaks on "Fixing the Web" and Appears on Channel 9 Frequent YUIBlog contributor Douglas Crockford gave a keynote at the AjaxWorld East 2008 conference in New York City last week. As ever, Douglas was pulling no punches â his title: "Can We Fix the Web?" The browser, Douglas says, was behind the times when
(Last Updated On: 2008å¹´1æ18æ¥)GNUCITIZENã¯éè¦ãªã»ãã¥ãªãã£åé¡ã次ã ã«å ¬éãã¦ããã®ã§ã»ãã¥ãªãã£ã«èå³ãããæ¹ã¯ãã§ãã¯ãã¦ããã®ã§ãåç¥ã¨ã¯æãã¾ããã Hacking The Interwebs http://www.gnucitizen.org/blog/hacking-the-interwebs ã«é常ã«ã¯æ·±å»ãªã»ãã¥ãªãã£åé¡ã解説ãã¦ããã¾ããå ·ä½çãªæ»ææ¹æ³ãªã©ã¯GNUCITIZENãåç §ãã¦ãã ãããæ¥æ¬ã§ãããããæ¸ãããããªãã¨æã£ã¦ããã®ã§ããäºæ³ããå°ãªãã®ã§ããã°ã«æ¸ããã¨ã«ãã¾ããããã§ã¯éè¦ãªé¨åã ãè¦ç´ãã¦æ¸ãã¾ãã æ»æ Flashãå©ç¨ããUPnPã«ã¼ã¿ã®æ»æã·ããªãªã¯ä»¥ä¸ã«ãªãã¾ãã UPnPãæå¹ãªã«ã¼ã¿ããã æªæã®ããFlashãWebãã©ã¦ã¶ã§åç §ãã UPnPã«ã¼ã¿ã®è¨å®ãå¤æ´ããSOAPãªã¯ã¨ã¹ãã
Firefox2ã§ãhttponlyã使ããã¨ãã話ãè³ã«ãã¾ããã httpOnly - Firefox Add-ons*1 httponlyãããããæ®åãããï¼ ã¨ããã®ã§ãã¿ã«ãã¦ã¿ã¾ãã ãªãããã®æ¥è¨ã¯ãWinXPï¼IE6SP2ç°å¢ãåæã¨ãã¦æ¸ãã¾ããã ã¯ããã« httponlyã¯ãXSSèå¼±æ§ãããç¶æ³ã«ããã¦ããcookieãçªåãããªãããã«ãããã¨ãçã£ãIEã®ç¬èªæ©è½ã§ãã MSDN - Mitigating Cross-site Scripting With HTTP-only Cookies ãã®æ©è½ãæå¹ã«ããããã«ã¯ãçºè¡ããcookieã«httponlyå±æ§ãä»ãã¾ãã Set-Cookie: key=value; domain=example.com; HttpOnly httponlyå±æ§ãä»ããããcookieã¯ãJavaScriptã®docume
å é±ã¯IETF 70ã«è¡ã£ã¦ãããæ¬æ¥ã®ä»¶ã§ããã¸ã§ã¯ãã¡ã³ãã¼éã¨ãIETFã«åå ããã®ã¯ä»åãåãã¦ãåæ¥ã®ã¬ã»ãã·ã§ã³ã§ã¯ããããã®æ¥æ¬äººãè¦ããããé¢èã®ãªãæ¹ã ãã»ã¨ãã©ã ã£ããèªåéãåå ããHTTPã®åéã¨TLSã®åéã§ã¯æ¥æ¬äººã¯ã»ã¨ãã©ã¿ãããªãã£ãããããã¯ã¼ã¯ç³»ã®äººã ã大åãªã®ã ãããã æ¬æ¥ã®ãã¨ã¯ããã«ã¯ãã¾ãæ¸ããªãããªã·ã¼ã ããå°ãæ¸ãã¨ãè¡ã£ã¦ã¿ã¦æãããã¨ã¯ãã³ãã¥ããã£ã®åæã phishingã®åé¡ã¯æ¥æ¬ã®ç¶æ³ã¨ã¯æ¯è¼ã«ãªããªãã»ã©è±èªåã§ã¯æ·±å»ãªã®ã ããããã£ã¨çãé£æºãããªããã¦å¤æ¹é¢ãã解決ãããã¨ãã¦ããã®ã§ã¯ãªããã¨æ¨æ¸¬ãã¦ããããã©ãããããªæããããªãã10æã«APWGã«è¡ã£ãã¨ãã«æããã®ã¯ãAPWGã®äººãã¡ã¯æè¡ã«ãã解決ã«ã¯ãã¾ãé¢å¿ããªãããã§ãç¯äººéãåæãããã¨ã被害è ã®è¡åãåæãããã¨ã«æ³¨è¦ãã¦ããæ§åã ã£ããã¾ãããã¯ãã
ååã¯Consumerãµã¤ããå®éã«ä½ãéã®ããã°ã©ãã³ã°ã«é¢ãã¦ã話ããã¾ããããä»åã¯OpenIDã«é¢ããã»ãã¥ãªãã£ã«ã¤ãã¦èãã¦ã¿ã¾ãã ä»ååãä¸ãããããã¯ã¨ãã¦ã¯ã ãªã©ã段éçã«èª¬æãã¦ããã¾ããIdPã®æ§ç¯æ¹æ³ãç¥ãåã«OpenIDãããã³ã«ã®ã»ãã¥ãªãã£ã«é¢ãã¦çç¥ãã¦ããã¾ãããã OpenIDãããã³ã«ã«ãããéä¿¡çµè·¯ã®ã»ãã¥ãªã㣠ããã¾ã§è©³ç´°ã«è§£èª¬ãã¦ãã¾ããã§ãããOpenIDèªè¨¼ãããã³ã«ã®ãã§ã¤ãºã«ããã¦ãã©ã®ããã«ã»ãã¥ãªãã£ä¸ã®å®å ¨æ§ãæ ä¿ãã¦ãããã解説ãã¾ãããã ã¾ãã¯associateã¢ã¼ããæ£å¸¸ã«å®è¡ããSmartã¢ã¼ãã®å ´åã§ãã Consumerã¯ã¦ã¼ã¶ã¼ããã®Claimed Identifierãåãåãã¨ãassociateã®ãã£ãã·ã¥ãåå¨ããªãå ´åã¯æ°è¦ã«IdPã«å¯¾ãã¦associateã¢ã¼ãã®ãªã¯ã¨ã¹ããè¡ãã¾ãã第3åã§ãas
ããã¯é¢ç½ã yohei-y:weblog: ã¹ãã¼ãã¬ã¹ã¨ã¯ä½ã ã§ã¯ãã¹ãã¼ãã¬ã¹ãªå ´åã¯ã©ããªã®ãã 客: ããã«ã¡ã¯ åºå¡: ããã£ãããã¾ããââãã¼ã¬ã¼ã¸ãããã 客: ãã³ãã¼ã¬ã¼ã»ããããé¡ããã¾ã åºå¡: ãµã¤ãã¡ãã¥ã¼ã¯ä½ã«ãªããã¾ãã? 客: ãã³ãã¼ã¬ã¼ã»ããããããã§ãé¡ããã¾ã åºå¡: ããªã³ã¯ã¯ä½ã«ãªããã¾ãã? 客: ãã³ãã¼ã¬ã¼ã»ããããããã¨ã¸ã³ã¸ã£ã¼ã¨ã¼ã«ã§ãé¡ããã¾ã åºå¡: +50åã§ããªã³ã¯ãLãµã¤ãºã«ã§ãã¾ãããããã§ãã? 客: ãã³ãã¼ã¬ã¼ã»ããããããã¨ã¸ã³ã¸ã£ã¼ã¨ã¼ã«(M)ã§ãé¡ããã¾ã åºå¡: 以ä¸ã§ããããã§ãã? 客: ãã³ãã¼ã¬ã¼ã»ããããããã¨ã¸ã³ã¸ã£ã¼ã¨ã¼ã«(M)ã§ãé¡ããã¾ããä»¥ä¸ åºå¡: ãããã¾ãã¾ãã å¼ç¨å ã«ã¯æè¨ããã¦ããªããã客ã®å»¶ã ã¨ããç¹°ãè¿ãé¨åã¯ããã¹ãããhiddenãã£ã¼ã«ãã§æ¸¡ããã¦ãããã®ãè¿ã
Security is the one area where the WS-* world has developed a set of standards that provide significantly more functionality than has so far been standardized in the REST world. I don't believe that this is an inherent limitation of REST; I'm convinced there's an opportunity to standardize better security for the REST world. So I've been giving quite a lot of thought to the issue of what the REST
ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼ å æ¥ãTwitterã§å£°ãããã¦ããã£ã¦ã 第ä¸å Port801 ã»ãã¥ãªãã£åå¼·ä¼ã£ã¦ããã®ã«åå ãã¦ãããï¼ï¼ (âpw: security) ããã§ããããåã£ãæã®ãããªãé ããã®ã§ããã£ãããªãã®ã§å ¬éãã¡ããã¾ããï¼ ãã¬ã¼ã³ã ã¨ãããããã®æ £ãã¦ãªãã¦ããã ãã ãªæãã ãã©ã ããã£ããä½ãã®åèã«ããããæ©ã飯ã®ãããã«ãã¦ãã ããï¼ï¼ Port801 ã»ãã¥ãªãã£åå¼·ä¼ - Hamachiya2 ãã®1 (httpç·¨) Port801 ã»ãã¥ãªãã£åå¼·ä¼ - Hamachiya2 ãã®2 (CSRFç·¨1) Port801 ã»ãã¥ãªãã£åå¼·ä¼ - Hamachiya2 ãã®3 (CSRFç·¨2) Port801 ã»ãã¥ãªãã£åå¼·ä¼ - Hamachiya2 ãã®4 (XSSç·¨1) Port801 ã»ãã¥ãªãã£åå¼·ä¼ - Hamachiya2 ãã®5
ã1.åãã«ã è¦æãããã¾ããã®ã§ãä»åã¯Linuxï¼å®éã¯Redhatç³»Linuxï¼ã§ããããå®å ¨ãã¤æ¥½ã«ãµã¼ããç«ã¦ãéã®æé ãè¨ãã¦ã¿ã¾ãã â»ä¸å¿æ³¨æï¼ä»åã¯ã試ãã«ãµã¼ããç«ã¦ãç¨åº¦ã§ããã°ãã®ãããã§ååã§ã¯ãªããã¨æãã¬ãã«ãæ³å®ãã¦ãã¾ãããµã¼ãã¹ã«æå ¥ãããµã¼ãã§ã¯ç§ã¯ãã£ã¨ç´°ããã¨ããã¾ã§æãå ¥ãã¦ãã¾ãã ã2.ããããå®å ¨ãã¤æ¥½ã«ãµã¼ããç«ã¦ãæé ã ãã¦ãããããæ¬é¡ã§ãããµã¼ããç«ã¦ãéã¯ãä¸å¿ è¦ãªãã®ãå ¨ã¦åãé¤ãã¦ããå¿ è¦ãªãã®ã追å ãã¦ããã¨ããã®ãåºæ¬ã«ãªãã¾ãã以ä¸ã®æé 1ï½5ã§ã¯ä¸è¦ãªãã®ã®é¤å»ãæé 6ï½7ã§å¿ è¦ãªãã®ã追å ã確èªãã¦ãã¾ãããããè¸ã¾ãã¾ãã¦ã â æé 1. OSãã¤ã³ã¹ãã¼ã«ãã¾ãã(ç§ã¯Linuxã§ããã°CentOSãå ¥ãããã¨ãå¤ãã§ãããã®éç§ã¯ã¤ã³ã¹ãã¼ã«ã®ç¨®é¡ãã«ã¹ã¿ã ã«ãããã±ã¼ã¸ã°ã«ã¼ãã®é¸æã§ã¯éçºãã¼ã«ä»¥å¤å ¨é¨ã
Internet Explorer ã®æªåé«ã Content-Type: ç¡è¦ã¨ããä»æ§ãå©ç¨ããã¨ãAtom ã RDF/RSS ãå©ç¨ãã¦XSSãçºçã§ãããã¨ãããã¾ããæ¡ä»¶çã«å¯¾è±¡ã¨ãªãWebã¢ããªã±ã¼ã·ã§ã³ã¯å¤ãã¯ãªãã¨æãã¾ãããããã§ãããã¤ã該å½ããWebã¢ããªã±ã¼ã·ã§ã³ãå®å¨ãããã¨ã確èªãã¾ããã以ä¸ã®ä¾ã§ã¯ Atom ã®å ´åã«ã¤ãã¦æ¸ãã¦ãã¾ãã RDF/RSS ã§ãåæ§ã§ãã ä¾ãã°ãhttp://example.com/search.cgi?output=atom&q=abcd ã¨ãã URL ã«ã¢ã¯ã»ã¹ããã¨ããabcdãã¨ããæååã®æ¤ç´¢çµæã Atom ã¨ãã¦è¿ãCGIããã£ãã¨ãã¾ãã GET /search.cgi?output=atom&q=abcd Host: example.com HTTP/1.1 200 OK Content-Type: ap
Ruby on Railsã§DBã®ãã¹ã¯ã¼ããdatabase.ymlã®å¤ã«æ¸ãæ¹æ³ãSubversionã«ãã¹ã¯ã¼ããã³ãããããã®ãå«ã ã£ãã®ã§èª¿ã¹ãã database.ymlã¯ERBã§å¦çãããã¨ããã®ãç¥ããªãã£ãã http://skwp.wordpress.com/2006/08/28/encrypted-db-passwords-for-rails-with-databaseyml-and-erb/ ã¨ããããã§ããããªé¢¨ã«ãã¦ã¿ã¾ãããæå·åã¯åãããããªãã production: adapter: mysql database: db username: user password: <%= File.read("#{RAILS_ROOT}/pass/to/passwordfile").strip %> host: 127.0.0.1
ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ã¨ããè¨èã¯å ã ï¼Webã¢ããªã±ã¼ã·ã§ã³ã®HTMLã¨ã³ã³ã¼ãæ¼ããªã©ãå©ç¨ãããã¨ã«ãã£ã¦ç¬¬ä¸è ã«JavaScriptãå®è¡ãããææ³ãæããåºç¾©ã§ã¯ï¼HTMLã®ã¨ã³ã³ã¼ãã«ããç»é¢æ¹å¤ãªã©ãå«ããã¨ãããã ååè¿°ã¹ãããã«ï¼ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ã®ããå¼±æ§ã¯Webã¢ããªã±ã¼ã·ã§ã³ã«è¦ä»ããããå¼±æ§ã®åå以ä¸ãå ãããæ°å¹´åããææããã¦ããã«ããããããï¼ä¸åã«ãªããªããªãããã®çç±ã¨ãã¦ï¼ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°å¯¾çãããã¯HTMLã¨ã³ã³ã¼ã注1ï¼ã«å¯¾ãããç¥è©±ããããï¼æ£ãã対çã®æ®åãé ããã¦ããããã«æãããã®ãç¥è©±ãã®æ°ã ã«ã¤ãã¦èª¬æãããã 注1ï¼å®ä½åç §ï¼entity referenceï¼ã¨ããã®ãæ£å¼ã ãï¼ãã¾ãæ®åãã¦ããªãç¨èªãªã®ã§ï¼HTMLã¨ã³ã³ã¼ãã¨ããç¨èªãç¨ãã ããã¹ãããHTMLã¨ã³ã³ã¼ããã¹ãããéå HTM
Abstract OpenID Authentication provides a way to prove that an end user controls an Identifier. It does this without the Relying Party needing access to end user credentials such as a password or to other sensitive information such as an email address. OpenID is decentralized. No central authority must approve or register Relying Parties or OpenID Providers. An end user can freely choose which Ope
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}