ãµã¼ããã¼ãã£Cookieã®æ´å²ã¨ç¾ç¶ Part1 åæç¥èã®å ±æ
Webéçºè ã®ããã®ãµã¼ããã¼ãã£Cookieãããã©ããã³ã°ããã®åé¡ç¹ã«ã¤ãã¦ä¸åãããã«åãã¦æ¸ãã¾ãã
ãã®æç« ã¯å人çã«æ¸ãã¦ãã¾ãã®ã§ãããããåã®ã¨ããã®ãµã¼ãã¹ããµã¼ããã¼ãã£Cookieã«ä¾åãã¦ããããã¼ãã¨ããããã³ãããããããããªããããããããã¨ãæ°ã«ãã¦ããã¨ãã¤ã¾ã§çµã£ã¦ãå ¬éã§ããªãã¨ããåé¡ãåºã¦ãã¾ãã®ã§ããããªãã¨ã¯ãæ§ããªãã«æ¸ããã¡ãªã¿ã«ä¾å¤ãªãèªç¤¾ãµã¼ãã¹ã«å¯¾ãã¦ããµã¼ããã¼ãã£Cookieã«ä¾åãããªæ»ãã¨è¨ã£ã¦ãããããã¯Webããã°ã©ãã¼è¦³ç¹ã§ãèªåããµã¼ãã¹éçºã«é¢ããä¸ã§ç¥ã£ã¦ãããã°ãªããªãã ããç¥èã¨ãã¦åæ°å¹´éã ãã ãã¨Webãè¦ã¦ãã¦èªç¶ã«ç¥ã£ã¦ãããã®ã¨ããããã¯èå³ãæã£ã¦çå ãã¦èª¿ã¹ããã®ãå«ã¾ãã¦ãããã°ã°ãã¦ç´ãã«åããç¨åº¦ã®ç¨èªã®å®ç¾©çãªãã¨ã¯æ¸ããªããããã¾ã§Webãµã¤ãå¶ä½è å´ããã®è¦³ç¹ãªã®ã§ããã©ã¦ã¶éçºé¢ä¿è ããã®ããã³ããæè¿ãã¾ããåºåæ¥çã®äººã«ã¯åºåæ¥çã®äººã§ç¬èªã®è¦ç¹ããããããããªãããã¨ã¦ã¼ã¶ã¼å´ããã©ã¦ã¶å´ã主ä½ã«ãã¦èªãã®ã§ããµã¼ããã¼ãã£Cookieã®éä¿¡ã¨è¨ã£ãã¨ãã«ã¯ããã©ã¦ã¶ãããµã¼ãã¼ã¸ã®éä¿¡ãã®ãã¨ãæãã¦ããã
ãµã¼ããã¼ãã£Cookieã«ã¾ã¤ãããã©ã¦ã¶ã®ä»æ§ã«ã¤ãã¦
10年以ä¸åã®è©±
ãã¡ã¼ã¹ããã¼ãã£Cookieã¨ãµã¼ããã¼ãã£Cookieã®åºå¥ãç¡ãã£ããWebãµã¤ãã«åãè¾¼ãã å°ããªç»åã«ãã£ã¦Cookieãã»ãããã¦ããã¡ã¤ã³éãè·¨ã£ã¦ã¦ã¼ã¶ã¼ã®è¡åããã©ããã³ã°ãã¢ã¯ã»ã¹è§£æãåºåã«ä½¿ç¨ããã¨ãããã¨ããã©ã¤ãã·ã¼ä¸ã®åé¡ã¨ãªãããã®ãããªä½¿ãæ¹ãæå¶ã§ããããã«ãã©ã¦ã¶å´ã«ãç¾å¨è¡¨ç¤ºä¸ã®ãã¡ã¤ã³åã³ãµããã¡ã¤ã³åã³Public Suffix Listããã®ä»ã®æ¹æ³ã§å¤å¥ãããåä¸éå¶è ã«ãã£ã¦ã»ãããããCookieã¨ãåºåããã©ããã³ã°ã§ç¨ããããç»åãjsããã¬ã¼ã ãªã©å¤é¨ãªã½ã¼ã¹ã®åãè¾¼ã¿ã«ãã£ã¦ç¬¬ä¸è ã«ãã£ã¦ã»ãããããCookieããµã¼ããã¼ãã£Cookieã¨ãã¦åºå¥ããããã«ãªã£ãã
ãã¡ã¼ã¹ããã¼ãã£Cookieã¨ãµã¼ããã¼ãã£Cookieãåºå¥ããã«å½ãã£ã¦ã¯ãããã«ãµã¼ããã¼ãã£Cookieã®ãåä¿¡ã¨éä¿¡ãåºå¥ããå¿ è¦ãããããããããªããgoogleã®ãµã¼ãã¹ã使ã£ã¦ããã¨ãã¦ãgoogle.comã®Cookieã¯ãã¡ã¼ã¹ããã¼ãã£ã®Cookieã¨ãã¦åãå ¥ãããããåãå ¥ããªããã°ãã°ã¤ã³ãå¿ è¦ãªãµã¼ãã¹ã使ããªããªãã®ãèªæã§ããããããGoogle以å¤ã®ãµã¤ããé²è¦§ãã¦ããã¨ãã«ããã¼ã¸å ã«åãè¾¼ã¾ããã*.google.comã®ç»åãscriptãiframeãªã©ã®åãè¾¼ã¿ã«å¯¾ãã¦Cookieãéããããªãã°ãããã¯ãµã¼ããã¼ãã£Cookieã§ããã
web bugã«ãããã©ããã³ã°ãåé¡ã«ãªã£ãé ã®æ¥½è¦³çãªèªèã§ããã°ãåã«è©²å½ãã¡ã¤ã³ã®Cookieãæå¦ãããã¨ã§ãã©ã¦ã¶ã«Cookieãä¿åãããªãã®ã ãããéä¿¡ãè¡ãããªããæã ã®ãã©ã¤ãã·ã¼ã¯å®ããããã¨ãããã¨ã§ãã£ãããããä»æ¥ç¾å¨ãå¤ãã®ãã°ã¤ã³ã¦ã¼ã¶ã¼ãæ±ãããããªå¤§æãµã¤ãããå¤é¨ãã¡ã¤ã³ã«å¯¾ãã¦ç»åãscriptã¿ã°ãiframeãåãè¾¼ããããªãã¼ãããã°ã¤ã³Cookieãä¿æãã¦ãããã¡ã¤ã³ã使ã£ã¦é ä¿¡ããã¨ããè¡çºãåºãè¡ããã¦ãããå¯ä½ç¨ã¨ãã¦ããã¡ã¤ã³ãè·¨ã£ãWebå±¥æ´ã®è¨é²ãè¡ããã¨ãåºæ¥ã(å®éã«ãã£ã¦ãããã©ããã¯ãã¦ãã)ã¨ããç¶æ³ãçºçãã¦ãããã¤ã¾ããå¤ãã®ãã°ã¤ã³ã¦ã¼ã¶ã¼ãæ±ãã¦ãããµã¼ãã¹ããå¤é¨åãè¾¼ã¿ã®ãã¼ããæä¾ããã¨ããã¡ã¼ã¹ããã¼ãã£Cookieã¨ãã¦ã»ãããããCookieãããµã¼ããã¼ãã£Cookieã¨ãã¦éãããã¨ããåé¡ãèµ·ããããããã£ã¦è¨å®ãããCookieã¯ããµã¤ãã®æ©è½ä¸å¿ é ã®ãã®ãªã®ãããã©ããã³ã°ã®ããã«ç¨ãããã¦ããã®ãããããã¯ãã®ä¸¡æ¹ãªã®ããåºå¥ãææ§ã«ãªã£ã¦ããã
å¤ããããã©ã¦ã¶ã«ã¯ãCookieãåãå ¥ãããã©ããã®è¨å®ãããã©ã¤ãã·ã¼ãéè¦ããè¨å®ã«ãã¦ããã¦ã¼ã¶ã¼ã«å¯¾ãã¦ã¯ãCookieãåãå ¥ãããæ¯åã¦ã¼ã¶ã¼ã¸ç¢ºèªããè¨å®ããåå¨ãã¦ãããã10å¹´åã«ããµã¼ããã¼ãã£Cookieãã¨ããåºå¥ãåºæ¥ã¦ä»¥æ¥ãåãå ¥ããCookieããæèã«ãã£ã¦éã£ããéããªãã£ãããããå¿ è¦ãåºã¦ãã¦ãããããããã©ã¦ã¶ã«ãã£ã¦ã¯ããã®ãããã®å®è£ ãã¾ã¡ã¾ã¡ã§ããµã¼ããã¼ãã£Cookieããããã¯ããããã¨ããåä¿¡ã®ã¿ãããã¯ããè¨å®ã§ãã£ãããéä¿¡ããããã¯ããè¨å®ã§ãã£ããããã
IE
- 2001å¹´ IE6ãããã©ã«ãã§ãµã¼ããã¼ãã£Cookieã®éåä¿¡ããããã¯ãã
- P3Pããªã·ã¼ãå°å ¥: æ©æ¢°çã«èªã¿åãå¯è½ãªãã©ã¤ãã·ã¼ããªã·ã¼
- P3Pã³ã³ãã¯ãããªã·ã¼ãã¬ã¹ãã³ã¹ãããã«è¨å®ãããã¨ã§èªåã§åãå ¥ããã®ãããã©ã«ã
- ä»ã形骸å: P3P: CP="Facebook does not have a P3P policy. http://..." ã§ãOK
- ãããã¯P3Pããªã·ã¼ã§ã¯ããã¾ãããã¨ããP3Pããªã·ã¼ã§ãåãå ¥ããããã
Firefox
- bugzillaã§æ´å²ã調ã¹ããã¨ãåºæ¥ãã
- Firefox3以éã§èªåããããã¯ããããã«å¤æ´ããã
- http://forums.firehacks.org/l10n/viewtopic.php?p=8256
- ãµã¼ããã¼ãã£Cookieã¯ããã©ã«ããããã¯ã«ãã(2006-) https://bugzilla.mozilla.org/show_bug.cgi?id=324397
- æ®ã©åæ³çãªç¨éã¯ããã¾ãã â æ£è¦ã®ãµã¤ããã¶ã£å£ãã®ã§ããã©ã«ãã§ãããã¯ã§ãã¾ãã
- åããªããµã¤ããåºããããããã¯ãã¦ã¦ãéä¿¡ããããã«æ»ãã¨ãã話(2008-) https://bugzilla.mozilla.org/show_bug.cgi?id=417800
- localStorageããµã¼ããã¼ãã£Cookieã®è¨å®è¦ã¦ãããã¯ããã¨ãã話(2009-) https://bugzilla.mozilla.org/show_bug.cgi?id=536509
- http://support.mozilla.com/en-US/kb/Disabling%20third%20party%20cookies
- ãã¤ã¯ãã½ããã®ãµã¼ãã¹ããµã¼ããã¼ãã£Cookieã«ä¾åãã¦ãããã¨ãæ¸ããã¦ãã
- Some websites (e.g. Microsoft's Hotmail, MSN, and Windows Live Mail webmail) use third-party cookies
Google Chrome
- Chroniumã®itsã§èª¿ã¹ããã¨ãåºæ¥ãã
- ããã©ã«ãã¯Cookieãå ¨ã¦åãå ¥ããè¨å®
- å°ãåã¾ã§ããµã¼ããã¼ãã£Cookieããããã¯ãã¦ããä¿åæ¸ã¿ã®Cookieãéä¿¡ããç¶æ
ã§ãã£ã
- ãããã¯ãã¦ãéä¿¡ã¯ãã â about:flagsã§éä¿¡ããªãã«ããè¨å®ããã
- æè¿ã«ãªã£ã¦ãabout:flags使ããªãã¦ãéä¿¡ããããã¯ãããããªå¤æ´ãå ¥ã
- http://code.google.com/p/chromium/issues/detail?id=98241
- ãããããã®å¤æ´ã«ãã£ã¦ããµã¼ããã¼ãã£iframeå ã®localStorageã®èªã¿æ¸ãããããã¯ãããããã«ãªã£ã
Safari
- ããã©ã«ãã§ãµã¼ããã¼ãã£Cookieããããã¯ãããã¨ãç¥ããã¦ãã
- http://www.apple.com/jp/safari/features.html ãããªãã®ã¦ã§ãã¢ã¯ãã£ããã£ã«é¢ããæ å ±ãåéãã¦è²©å£²ããããã«ãããªããã¢ã¯ã»ã¹ãããµã¤ãã«ãã£ã¦çæãããCookieã追跡ããä¼æ¥ãããã¾ããSafariã¯ããã®ãããªè¿½è·¡Cookieããããã¯ããããã«è¨å®ãããæåã®ãã©ã¦ã¶ã§ãããªãã®ãã©ã¤ãã·ã¼ããã£ããä¿è·ãã¾ããã¨ãã
- iframeãåãè¾¼ãã ã ãã§ã¯Cookieãä¿åããªãããiframeå ã§ç»é¢é·ç§»ãçºçããå ´åããµã¼ããã¼ãã£ã®Cookieãåãå ¥ãããã¦ãã¾ãã
- ãã®ããããã©ã«ãã®è¨å®ãå¤æ´ããªãã¦ããããããdoubleclick.netãªã©ã®åºåCookieãä¿åããããã¨ã«ãªãã ããã
- ã¾ããä¿åæ¸ã¿ã®Cookieã¯å
¨ã¦ã®Cookieããããã¯ãã¦ãéä¿¡ããã
- ãCookieãããã㯠â 常ã«ãã«è¨å®ããã¨ãµã¤ãã«ãã°ã¤ã³ã§ããªããªãã®ã確èªãã
- ãCookieãããã㯠â ããªããã«è¨å®ãã¦é©å½ãªãµã¤ãã«ãã°ã¤ã³ãã
- ãCookieãããã㯠â 常ã«ãã«è¨å®ãã¦ã訪åããã¨ãããã¯ãã¦ãã¦ãããã°ã¤ã³ç¶æ ãç¶æããã¦ããã®ã確èªã§ãã
- Safariã«ã¨ã£ã¦Cookieã®ãããã¯ã¨ã¯ããµã¼ãã¼ããéããã¦ããCookieãä¿åãããã©ããã®è¨å®ãã§ãæ¢ã«ä¿åããCookieãéä¿¡ãããã©ãããå¶å¾¡ãããã¨ãåºæ¥ãªã
Opera
- 10.50ã§ä¸ç¬ããµã¼ããã¼ãã£Cookieã®ãããã¯ãããã©ã«ãè¨å®ã«ãªã£ãã
- 10.51ã§å ã«æ»ããã http://jp.opera.com/docs/changelogs/windows/1051/
- ãã°ã¤ã³åºæ¥ãªããµã¤ããçãããããã¨èª¬æããã¦ãã
- opera:configã§ã¯å
é¨çã«ã¯9段éã®è¨å®é
ç®ã«ãªã£ã¦ããã
- http://jp.opera.com/support/usingopera/operaini/ Enable Cookiesåç §
- 11.52ã§è©¦ããã¨ããããµã¼ããã¼ãã£Cookieããããã¯ãã¦ããç»åãjsã§ã®Cookieã»ããããããã¯ããã ãã§ãiframeã§Cookieãã»ãããããã¨ãã§ããã
- Cookieãç¡å¹åãã¦ãä¿åæ¸ã¿ã®Cookieã¯éä¿¡ããããSafariã¨åçã
Netscape
- Netscape7ã§P3P対å¿ãé²ãããã¦ããããFirefoxã«ã¯åãè¾¼ã¾ããªãã£ãã
- http://news.mynavi.jp/news/2002/09/18/08.html
ã¾ã¨ã ãµã¼ããã¼ãã£Cookieã®è¨å®
ãã©ã¦ã¶æ¯ã«è¦ãã¨
- IE6以é : ããã©ã«ãã§ãããã¯ãã¦P3Pã¨ããæãéç¨æ
- Firefox, Opera : ããã©ã«ãã§ãããã¯ããããã©åããªããªããµã¤ããåºã¦å°ãã®ã§ãããã¯åºæ¥ãªãã£ã
- Chrome : ãããã¯ãããªãããããã¯ããã°éä¿¡ããããã¯ãããããã«æè¿å¤ãã£ãã
- Safari : ããã©ã«ãã§ãããã¯ãããã©éä¿¡ã¯ããã¨ããç©´ãæ®ã
- Netscape : çµäºãã
ããã©ã«ãè¨å®
- ããã©ã«ãã§ãµã¼ããã¼ãã£Cookieã®åä¿¡ããããã¯ãã IE6以éãSafari(ãã°ãã)
- ããã©ã«ãã§ãµã¼ããã¼ãã£Cookieã®éä¿¡ããããã¯ãã IE6以é
- ä»ã®ãã©ã¦ã¶ã¯ãå ¨ã¦ã®Cookieãåãå ¥ãããéä¿¡ãã
- P3Pã³ã³ãã¯ãããªã·ã¼ããè¨è¿°ããã°ãIEãå ¨ã¦ã®Cookieãéåä¿¡ããã
ãµã¼ããã¼ãã£Cookieéä¿¡ã«é¢ããããªã·ã¼
- Firefoxã¯Firefox3ã«ããã¦ããããã¯ãã¦ããã®ã«éä¿¡ããããã®ã¯ãã°ã ãã¨å¤æãã
- Safariã¯ãµã¼ããã¼ãã£Cookieããããã¯ããããªã·ã¼ãæã£ã¦ããããéä¿¡ã¯ãããã¯ããªãã
- ãã¡ã¼ã¹ããã¼ãã£Cookieã¨ãã¦æ¢ã«åãå
¥ãã¦ããCookieã®éä¿¡ã«ã¤ãã¦ã¯ãP3Pããªã·ã¼ãåãåºãã°ãIE,Firefox,Safari,Chrome,Operaå
¨ã¦ã®ããã©ã«ãè¨å®ã§æå¹ã§ããã
- (å¤é¨ãã¡ã¤ã³ä¸ã§ã®)ã¯ã¦ãªã¹ã¿ã¼ãFacebookã®likeãã¿ã³ãæ®ã©å ¨ã¦ã®ç°å¢ã§åä½ãã¦ããçç±ãããã ã
Microsoftã¨P3Pã«å¯¾å¿ããªãã£ãä»ã®ãã©ã¦ã¶ã®é¢ä¿
- P3Pã®ã³ã³ãã¯ãããªã·ã¼ãIE6ã¨å ±ã«ãµãã¼ããããã
- http://msdn.microsoft.com/ja-jp/library/ms537341(v=vs.85).aspx
- Netscape7ã§ãä¸å®å ¨ãªãããµãã¼ã http://news.mynavi.jp/news/2002/09/18/08.html
- Firefoxã¯P3Pãµãã¼ããããã http://en.wikipedia.org/wiki/P3P#Criticisms https://bugzilla.mozilla.org/show_bug.cgi?id=225287
IEãP3Pã³ã³ãã¯ãããªã·ã¼ããµãã¼ãããæãP3Pã³ã³ãã¯ãããªã·ã¼ãå®ç¾©ããã¦ããã°åçç¡ç¨ã§åãå ¥ãã¦ãã¾ãã¨ããããã©ã«ãè¨å®ãæ¡ç¨ããããã®çµæãä»ã§ã¯ãæã ã¯P3Pããªã·ã¼ããµãã¼ãããªããæã ã®ãã©ã¤ãã·ã¼ããªã·ã¼ã¯ãã¡ããã¨ãã£ãP3Pãããã使ããããªã©ãã¦ãããããã§ãIEã¯ä½ã®è¦åãç¡ãCookieãåãå ¥ããã
æ¬æ¥ç®æãã¦ãããã¸ã§ã³ã¯ãæ©æ¢°çã«èªã¿åãå¯è½ãªP3Pããªã·ã¼ã使ã£ã¦ã¦ã¼ã¶ã¼èªèº«ã®ãã©ã¤ãã·ã¼ããªã·ã¼ã¨ããµã¤ãå´ã®ãã©ã¤ãã·ã¼ããªã·ã¼ãæ¯è¼ããå¿ è¦ã«å¿ãã¦äººéã«èªã¿åãå¯è½ãªããªã·ã¼ãæ示ãã¦ãCookieãåãå ¥ãããã©ããã¦ã¼ã¶ã¼ãå¤æã§ããã¨ãããã®ã ã£ã(ã¨ããèªèãæã£ã¦ãããå½æã®ãã¥ã¼ã¹ã§ããã®ããã«å ±éããã¦ãã)ãIE以å¤ã®ãã©ã¦ã¶ã¯ãP3Pãµãã¼ãã«è¿½éãããªãã£ãã®ã§ãå®è³ªçã«IEã«Cookieãé£ãããããã®ãã¾ããªãã¨ãã¦å½¢éª¸åãã¦ãã¾ã£ã¦ããã
Microsoftã«ã¨ã£ã¦ã¯ãP3Pã³ã³ãã¯ãããªã·ã¼ã«å¯¾å¿ãããã¨ã§ãèªåãã¡ã®ãµã¼ãã¹ã§ã¯å ã ã¨ãµã¼ããã¼ãã£Cookieã使ç¨ãããã¨ãã§ããããã«ãªã£ããä»ã®ãã©ã¦ã¶ã«ã¨ã£ã¦ã¯ãP3Pããµãã¼ãããªãã¾ã¾ããµã¼ããã¼ãã£Cookieãããã©ã«ãã§ãããã¯ããè¨å®ãã«ãããªãã°ãMicrosoftæä¾ã®ãµã¼ãã¹ãããã®ä»P3Pããªã·ã¼ã«ãã£ã¦ãµã¼ããã¼ãã£Cookieã使ãããã¨ãæå¾ ãã¦ãããµã¼ãã¹ã使ããªããªã£ã¦ãã¾ããMozillaã¯åæãã§ãµã¼ããã¼ãã£Cookieãç¡å¹åããã¨Microsoftã®ãµã¼ãã¹ã使ããªããªãã¨æ¸ãã¦ãããSafariã¯Microsoftã®ãµã¼ãã¹ã使ããªãã¦ãæ§ããªãã¨æã£ãã®ãããµã¼ããã¼ãã£Cookieããããã¯ããè¨å®ãæ¡ç¨ãã(ãã ãéä¿¡ã¯ãã)ããsafari hotmail 使ããªãããªã©ã§æ¤ç´¢ããã¨åããã ããã
ãã©ã¦ã¶å´ããããã¨ããã©ã¤ãã·ã¼ã«é æ ®ããããã©ã«ãè¨å®ã«ããããã«ã¯ãè¤éã§å´åã«è¦åããªãã¬ã©ã¯ã¿ã¨åããP3Pããªã·ã¼ã«å¯¾å¿ãããããMicrosoftããã®ä»ãµã¼ããã¼ãã£Cookieã«ä¾åãããµã¤ããæ©è½ããªããªã£ã¦ãæ§ããªãã¨ããããã¨ããäºæãè¿«ããããã¨ã«ãªã£ãã
Webãµã¤ãå´ããããã¨ããããã¯ãã¦ãéä¿¡ã¯è¡ãããããiframeå ã§é·ç§»ãããã°ãããã¯ããã¦ãã¦ãä¿åããããã¨ãã£ãä¸å ·åã ãä»æ§ã ãåãããªãæãéãå©ç¨ãã¦ãSafariã§åä½ãããããªé æ ®ããã¦ããããP3Pã³ã³ãã¯ãããªã·ã¼ãå©ç¨ãã¤ã¤ãåä½ããªãã£ããã¨ã«ããCookieããããã¯ããè¨å®ã解é¤ããããã«æ¡å ããããã¨ã§ããµã¼ããã¼ãã£Cookieã«ä¾åãããµã¼ãã¹ãä½ã£ã¦ãããçµå±Safari以å¤ã®ãã©ã¦ã¶ã¯äºææ§ãéè¦ããããã©ã«ãã§å ¨ã¦ã®Cookieãåãå ¥ãããã¨ããè¨å®ãå¤ãããã¨ãåºæ¥ãªãã£ãã
éè¦ãªãã¸ã·ã§ã³ã«å± ãSafari
ãµã¼ããã¼ãã£Cookieãããã©ã«ãã§ãããã¯ãããSafariã¯ããããã¯ãããã©éä¿¡ã¯ãããã¨ããä»æ§ã«ãã£ã¦ãã¾ãã¾åãã¦ãããµã¤ããå¤ãã¨ããã ãã®ç¶æ ã§ãããããSafariããéä¿¡ããããã¯ãããã¨ããããªã·ã¼ãæ¡ç¨ãããããã°ã¤ã³æ¸ã¿ã®iframeãç»åãjsãåãè¾¼ããã¨ã«ä¾åãã¦ãããµã¼ãã¹ã¯ãSafariã¨iPhoneã§åä½ããªããªããã¨ã«ãªããSafariã¯ã¨ããããiPhoneã¯ã¢ãã¤ã«ã«ã¨ã£ã¦çµæ§ãªã·ã§ã¢ã§ãããããã©ã¦ã¶ã®è¨å®å¤æ´ãä¿ãã®ãé£ããã ããããµã¤ãæ¯ã«æå¹ã«ããæ©è½ãåå¨ãã¦ããªãã
Appleã¯ã追跡Cookieããããã¯ããããããªãã®ãã©ã¤ãã·ã¼ããã£ããä¿è·ãã¾ããã¨æè¨ãã¦ããã®ã§ããµã¼ããã¼ãã£Cookieããããã¯ããã¨ããããã©ã«ãè¨å®èªä½ãå¤æ´ããããã¨ã¯ãã¾ããªãã ãããç¾ç¶ãSafariã¯ãµã¼ããã¼ãã£Cookieã®éä¿¡ããããã¯ãã¦ããªãããã¡ã¼ã¹ããã¼ãã£ã¨ãã¦Cookieãã»ãããããã°ãä»ã®ãã¡ã¤ã³ã§ã¯ããã追跡Cookieã¨ãã¦æ©è½ãããããªããSafariãããã©ã«ãè¨å®ã§ä½¿ã£ã¦ãã¦ããããç¨åº¦æ®éã«ã¤ã³ã¿ã¼ãããããã¦ããã°ãdoubleclick.netã®Cookieãã»ããããããã¨ã«ãªãã ããã
ãµã¼ããã¼ãã£Cookieã®éä¿¡ãæå¹ã§ãããã¨ã«ãã£ã¦çããã»ãã¥ãªãã£ä¸ã®åé¡
ãµã¼ããã¼ãã£Cookieãæå¹ã§ãããã¨ã«ãã£ã¦çºçãã¦ããåé¡ãå¤ããããããã¯Cookieã«ãã£ã¦èªè¨¼ãããç¶æ ã§ä»ã®ãã¡ã¤ã³ã«åãè¾¼ã¾ãããã¨ã«ãã£ã¦ãã¦ã¼ã¶ã¼ãæå³ããªãæ å ±ã®æ¼æ´©ãçºçããããæä½ãè¡ããããããã¨ããåé¡ã ããã®æã®åé¡ã¯ããã©ã¦ã¶å´ã§ããªã¹ã¯ã軽æ¸ãããããã«ä¿®æ£ãããããã¨ãå¤ããããã©ã¦ã¶å´ã§å¯¾å¿ãã¹ãåé¡ãªã®ããWebãµã¤ãå´ã§å¯¾å¿ãã¹ãåé¡ãªã®ããææ§ã«ãªã£ã¦ãããã¯ãªãã¯ã¸ã£ããã³ã°ã¯Webãµã¤ãå´ã§ã®å¯¾å¿ãå¿ è¦ã¨ããããã対çãããã¦ããªã大åã®ãµã¤ããå±éºã«æããã¦ããç¶æ ã«ãªã£ã¦ããã
- Webãµã¤ãã«CSRFèå¼±æ§ããã£ãå ´åãç»åãscriptã¿ã°ãiframeã§æ»æURLãåãè¾¼ããã¨ã§ã¦ã¼ã¶ã¼ã«æ°ä»ãããã«å®è¡ãããã¨ãåºæ¥ã
- Webãµã¤ãã«XSSèå¼±æ§ããã£ãå ´åãiframeã§æ»æURLãåãè¾¼ããã¨ã§ã¦ã¼ã¶ã¼ã«æ°ä»ãããã«å®è¡ãããã¨ãåºæ¥ãã
- ãã£ãã·ã³ã°ãµã¤ãã«ãã°ã¤ã³ç¶æ ã®iframeãåãè¾¼ã¿ãã¦ã¼ã¶ã¼åãã¢ã¤ã³ã³ãªã©ã表示ããäºãã§ãããããã«ãã£ã¦ãã£ãã·ã³ã°ã®æåçãããã
- CSSã使ã£ã¦éæã«ããç¶æ
ã®iframeãåãè¾¼ããã¨ã§ãã¯ãªãã¯ã¸ã£ããã³ã°ã®åé¡ãçºçããã
- æªãã°ã¤ã³ç¶æ ã§ããã°æ³å®ããã被害ã¯è»½å¾®ã«ãªããã¨ãããã¨ãéå»ã«æ¸ãã http://d.hatena.ne.jp/mala/20090306/1236341606
- ç»åã®ã¯ãã¹ãã¡ã¤ã³èªã¿è¾¼ã¿ããWebGLã§ã®ã¯ãã¹ãã¡ã¤ã³ãã¯ã¹ãã£ãªã©ã®åé¡
- æ¬æ¥ãã¼ã¿ã¨ãã¦ã¯èªã¿è¾¼ããªãç»åãèªã¿è¾¼ãã¦ãã¾ãåé¡ã§ãããå¤é¨ãªã½ã¼ã¹ãèªã¿è¾¼ãéã«ã¯èªè¨¼æ å ±ãéããªãã¨ããããªã·ã¼ã«ãã£ã¦å½±é¿ã軽æ¸ã§ãã
- JSONãã¤ã¸ã£ãã¯ã®åé¡
- ãã°ã¤ã³ç¶æ ã§æ©å¯æ å ±ãå«ãJSONã¬ã¹ãã³ã¹ãä»ã®ãã¡ã¤ã³ããèªã¿åºããã¨ãåºæ¥ãåé¡
- HTTPã¬ã¹ãã³ã¹ã®å·®ç°ã«ãã£ã¦ãã°ã¤ã³ç¶æ
ã®å¤å¥ãåºæ¥ãåé¡ http://hacks.mozilla.org/2011/02/an-interesting-way-to-determine-if-you-are-logged-into-social-web-sites/
- ç»åãjsã®ã¬ã¹ãã³ã¹ã§ä½¿ã£ã¦ããµã¼ãã¹ãå¤å¥ãããã¨ãã§ãã¦ãã¾ã
ãã¡ãããCookie以å¤ã§èªè¨¼ãããã£ã¦ããã±ã¼ã¹ãããã®ã§ããã©ã¦ã¶å´ã§ã®å¯¾çãåãããªããã°ãªããªãã®ã ãã
- ã¦ã¼ã¶ã¼æ¯ã«åºæã®ã¬ã¹ãã³ã¹ãè¿ããããªURLã«å¯¾ãã¦ã¯ãã¢ã¯ã»ã¹å¶éããããä¸ã§
- ãªã½ã¼ã¹ãå¤é¨ãã¡ã¤ã³ã«åãè¾¼ã¾ãã¦åç §ãããéã«ã¯ãèªè¨¼æ å ±ãéããªãã=ããµã¼ããã¼ãã£Cookieãéä¿¡ããªãã
ã¨ããã·ã³ãã«ãªã«ã¼ã«ã§ãå°æ¥ã«æ¸¡ã£ã¦ããã®æã®same origin policyãçªç ´ãããã°ã«ããå½±é¿ã軽æ¸ãããã¨ãã§ããã
ç¹ã«ãã°ã¤ã³ç¶æ ã®å¤å®ããã°ã¤ã³ãã¦ãããã©ããã«å¿ãã¦ã¹ãã¼ã¿ã¹ã³ã¼ããå¤ãããã®ãå¿çæéãå¤ãããã®ãªã©ã¾ã§å«ããã¨ãWebãµã¤ãå´ã§ã¯æ®ã©å¯¾å¿ã®ãããããªãã ãããå¤ãã®Webãµã¤ãã¯ãã°ã¤ã³æ¸ã¿ã®ç¶æ ã§å¤é¨ãµã¤ãã«åãè¾¼ã¾ãããã¨ãæ³å®ãã¦ããªãããå¿ è¦ã¨ããã¦ããªãããµã¼ããã¼ãã£Cookieã®éä¿¡ãå¿ è¦ã¨ãã¦ããä¸é¨ã®ãµã¤ãããã¡ã¤ã³ã«ã¾ããã£ããã©ããã³ã°ãè¡ãªã£ã¦ããåºåãã¢ã¯ã»ã¹è§£æããã°ã¤ã³ç¶æ ãå¿ è¦ã¨ããã¦ã£ã¸ã§ããã»ã¬ã¸ã§ããã»ããã°ãã¼ãã¨å¼ã°ãããã®ããã¡ãªä»çµã¿ã®ã·ã³ã°ã«ãµã¤ã³ãªã³ããªã©ã®ããã«ããã©ã¦ã¶ã¯ããã©ã«ãã®è¨å®ãå¤æ´ãããã¨ãã§ããªããããµã¼ããã¼ãã£Cookieã®éä¿¡ãå¿ è¦ã¨ããªã大å¤æ°ã®ãµã¤ãã®ã¦ã¼ã¶ã¼ãæ½å¨çãªå±éºã大ããè¨å®ã§ã¤ã³ã¿ã¼ããããå©ç¨ãã被害ãããããã¨ã«ãªãã
Webãµã¤ãå´ããã¿ãåé¡ç¹
- ãµã¼ããã¼ãã£Cookieããéã£ã¦æ¬²ãããªãããã¨ãæ示ããæ¹æ³ãç¡ãã
- ä¾ãã°ã¯ãªãã¯ã¸ã£ããã³ã°å¯¾çã§ã¯ããµã¤ãéå¶è
å´ããæªãã°ã¤ã³ç¶æ
ã§åãè¾¼ã¾ãããªãã°æ§ããªããã¨èãã¦ãã¦ãããã®ããã«æ示ããæ段ããªã
- X-Frame-Optionsã¯ãã¬ã¼ã å ã§ã®åç §ã丸ãã¨æå¦ãããã¨ã«ãªãã
- æã ã¯ãã©ããã³ã°ãããªããããã°ã¤ã³æ¸ã¿ã®ç¶æ ã§ä»ã®ãã¡ã¤ã³ã«åãè¾¼ã¾ãããã¨ãæãã§ããªããã¨è¡¨æããæ段ããªã
ããã¾ã§ã®ã¾ã¨ã
- ãµã¼ããã¼ãã£Cookieã®è¨å®ã«é¢ããããªã·ã¼ã¯ãã©ã¦ã¶æ¯ã«ç°ãªã
- P3Pã³ã³ãã¯ãããªã·ã¼ãHTTPã¬ã¹ãã³ã¹ãããã«è¿½å ãããã¦ããã°ã主è¦ãªãã©ã¦ã¶å ¨ã¦ã®ããã©ã«ãè¨å®ã§ãµã¼ããã¼ãã£Cookieã®éä¿¡ãè¡ããã
- ãµã¼ããã¼ãã£Cookieã¯ä»ã§ãåºã使ããã¦ãããããã©ã¦ã¶ã¯ããã©ã«ãè¨å®ãå¤ãããã¨ãã§ããªã
- ãã°ã¤ã³ç¶æ ã§å¤é¨ãµã¤ãã«åãè¾¼ã¾ãããã¨ã«ãã£ã¦çºçãã¦ããã»ãã¥ãªãã£ä¸ã®åé¡ãæ°å¤ãããããµã¼ããã¼ãã£Cookieã®éä¿¡ããªãã«ãããã¨ã§å½±é¿ã軽æ¸ãããã¨ãã§ããã
- 大åã®ã¦ã¼ã¶ã¼ã¯ãã®ãããªåé¡ã«ç¡é¢å¿ã§ããã®ã§ãã©ã¦ã¶ãããã©ã«ãè¨å®ã®ã¾ã¾ä½¿ãããããã©ã«ãè¨å®ã«ä¾åãã¦Webãµã¤ãããµã¼ããã¼ãã£Cookieã«ä¾åããè¨è¨ãããã
- èåãªã»ãã¥ãªãã£ç 究è ã§ããã©ã¦ã¶ã®è ã£ãå®è£ ããµã¼ããã¼ãã£Cookieã®å©ç¨ã®å®æ ã«ã¤ãã¦è¯ãç¥ããªã
ããã¯ä¸é¨æ§æã®è¨äºãªã®ã§ã次ã®è¨äºã«ç¶ãã¾ããPart2ã§ã¯Webã¢ããªã±ã¼ã·ã§ã³ã«ãããå©ç¨ãå¤é¨ãã¡ã¤ã³åãã®åãè¾¼ã¿ãã¼ãã§ã®å©ç¨ã¨ãã®åé¡ç¹ã«ã¤ãã¦æ¸ãã¾ãã