æ¥æ¬å½å ã§ã®LINEå©ç¨ãéå½å½å±ãååãããã¨ã¯å°é£
æåFACTA7æå·ã§ãLINEãéå½ã®å½å®¶æ
å ±é¢ã«éä¿¡ååããã¦ããã¨ãã記事ãæ²è¼ããããããã«å¯¾ãã¦LINEã®æ£®å·äº®ç¤¾é·ããå½éåºæºãæºãããæé«ã¬ãã«ã®æå·æè¡ã使ã£ã¦éä¿¡ããã¦ãã¾ãã®ã§ãè¨äºã«æ¸ããã¦ããååã¯å®è¡ä¸ä¸å¯è½ã§ããã¨反論ãããã«FACTAã®é¿é¨ç·¨éé·ãããããç ´ããã¦ããã¨ããã®ãæ¬èªã®èªèãã¨再反論ãã¦ããããã®å¾LINEã¯ITMediaの取材ã«å¯¾ããæå·åå¾ãã¼ã¿ã¯ç¬èªå½¢å¼ã解èªã¯ä¸å¯è½ãã¨åçããã
LINEの開発者向けブログã«ããã¨LINEã¯ãµã¼ãã¼ã¨ã®éä¿¡ã«é常TLS/SPDYã使ã£ã¦ãããã3Géä¿¡ãªã©ã§é
延ã大ããå ´åã«ã¯å©ç¨è
ã®æä½æ§ãåªå
ãã¦æå·åããã«éä¿¡ãè¡ãå ´åãããã¨æ¸ããã¦ããããã¼ã¿ã»ã³ã¿ã¼ã¯æ¥æ¬ã«ããã¨ã®ãã¨ãªã®ã§ãFACTAã®è¨äºã«ããéå½æ¿åºã®ãµã¤ãã¼ã»ãã¥ãªãã£é¢ä¿è
ã®çºè¨ãä»®ã«äºå®ã§ãã£ãã¨ãã¦ãå°ãªãã¨ãéå½å½å
ã§ã®é
延ã®å¤§ããª3Gåç·çãçµç±ããLINEã®å¹³æéä¿¡ã¯é©æ³ãã¤å®¹æã«ååã§ããã¨èããããã
We allow for non-encrypted connections. SPDY is usually used with TLS, but this slows down connection times and transfers-especially over mobile connections. Thus we decided to allow for non-encrypted connections over a mobile network.
LINEäºæã¯ã©ã¤ã¢ã³ãéçºè
ã®ã¾ã¨ãã解析結果ã«ããã¨ãLINEã¯ã©ã¤ã¢ã³ãã¯gd2.line.naver.jp:443ã«æ¥ç¶ããã¡ãã»ã¼ã¸ã¯Apache Thrift TCompactProtocolã§ç´ååããã¦ããããã ãæ¥ç¶å
ã確èªããã¨ãããµã¼ãã¼è¨¼ææ¸ã¯2014å¹´4æ17æ¥ã«çºè¡ãããGeoTrustã®2048bit RSAå½¢å¼ã®ãã®ã§ãSSL Heartbleedåé¡ãåãã¦åçºè¡ããããã¨ã確èªã§ããã
Cipherã«ã¯DHE-RSA-AES128-SHAã使ã£ã¦ãããããã¯Googleが2011年にOpenSSLコミュニティーに寄付ããåæ¹ç§å¿æ§ããµãã¼ãããéµäº¤æãããã³ã«ã§ãLavabit事件ã®ããã«å½å±ããSSLç§å¯éµã®æåºãè¦æ±ãããããHeartbleedã§SSLç§å¯éµãæ¼æ´©ããã¨ãã¦ããéå»ã«é¡ã£ã¦éä¿¡ã復å·ãããªããã対çããã¦ãããä¸è¬ã®ISPãæä¾ããé»åã¡ã¼ã«çã¨æ¯ã¹ã¦ãå¼·åãªã»ãã¥ãªãã£ã¼å¯¾çãæ½ããã¦ããã¨ãããã
å
¬è¡¨ããã¦ããæ
å ±ãç·åãã¦æ¥æ¬å½å
ã®LINEå©ç¨è
ã«ããéä¿¡ãé©æ³ã«éå½å½å±ãååãããã¨ã¯é£ãããã¨ã¯ããæã
ã¯ã¹ãã¼ãã³äºä»¶ã®æè¨ãããæ
å ±æ©é¢ãåå½ã®æ³å¾ãç¡è¦ãã¦å½å
å¤ã®æ
å ±åéãè¡ãå ´åããããã¨ãç¥ã£ã¦ãããå½å®¶æ©é¢ã«ããéæ³ãªæ
å ±åéæ´»åã«å¯¾ãã¦æ°éäºæ¥è
ã®ã§ãã対çã«ã¯éçããããååããã¦ããªããã¨ãç«è¨¼ããã®ã¯æªéã®è¨¼æã ãååã¯ä¸å¯è½ã¨å¼·å¼ããããã¯ãæ¤è¨¼å¯è½ãªäºå®ãç©ã¿ä¸ãã¦ãæè¡çãªåãçµã¿ã説æããæ¹ããªã¹ã¯ã¯å°ããã ããã