ã翻訳ãASan Nightly Project ã®ç´¹ä»
ãã®è¨äºã¯ã2018 å¹´ 7 æ 19 æ¥ä»ã§ Mozilla Security Blog ã«æ稿ããã Introducing the ASan Nightly Project ï¼çè ï¼decoderï¼ã®ç¿»è¨³ã§ãããã®ç¿»è¨³ã¯å ¬å¼ãªãã®ã§ã¯ããã¾ããã詳ãã㯠ãã¡ã ãã覧ãã ããã
ã¦ã¼ã¶ã®æå ã¸å®å®ãã¤å®å ¨ãª Firefox ã確å®ã«å±ããããã å¤ãã® Mozillian ãé·ãæéãããã¦æ¥ã ãã¹ããè¡ã£ã¦ãã¾ãã ããããæ®å¿µãªãã¨ã«ãã°ã®ç¡ããããã¯ããªã©åå¨ããªãããã ã©ãã»ã©ãã¹ãã«åã注ãã§ãæã¨ãã¦ãã©ã¦ã¶ã¯ã¯ã©ãã·ã¥ãã¦ãã¾ãã¾ãã å®éã«ã¯ã©ãã·ã¥ã¬ãã¼ãã調æ»ãã¦ã¿ãã¨ã ä¸ã«ã¯å¤å ¸çãªã»ãã¥ãªãã£ãã°ï¼è§£æ¾å¾ä½¿ç¨ã«ä»£è¡¨ãããã¡ã¢ãªç ´å£ãªã©ï¼ã«è¦ãããã®ãããã¾ãã ãããããã®ãããªã¬ãã¼ãããå¾ããããã¼ã¿ã¯ã ããåç¬ã§ã¯ä½ãæå³ããªããªãç¨åº¦ã«ä¸ååï¼ã¤ã¾ããéçºè ãåé¡ãç¹å®ã»ä¿®æ£ããã®ã«ååã§ãªãï¼ãªãã¨ããã°ãã°ã§ãã ãã®å¾åã¯ã解æ¾å¾ä½¿ç¨ã¨ãã£ãã¡ã¢ãªç ´å£ã®åé¡ã«ããã¦ã åå ã¨ãªãã¢ã¯ã»ã¹éåãèµ·ãã¦ããå®éã®ã¯ã©ãã·ã¥ãèµ·ããã¾ã§ã«ããªãæéã空ãã±ã¼ã¹ã§ç¹ã«é¡èã§ãã
Mozilla ã¯çµåãã¹ãã¨ãã¡ã¸ã³ã°ãèªååãã¦ãã¾ããããã®ããã»ã¹ã§ AddressSanitizer (ASan) ã使ç¨ãã¦ãã¾ãã ASan ã¯ã³ã³ãã¤ã«æã«çµã¿è¾¼ããã¼ã«ã§ããããã 5 å¹´éã§å¤§ããªææãæãã¦ãã¾ããã 解æ¾å¾ä½¿ç¨ãä¾ã«ããã¨ãASan ã¯ã¡ã¢ãªã®ã¢ã¯ã»ã¹éåãèµ·ããã¿ã¤ãã³ã°ã®ã¿ãªããã ãã®ã¡ã¢ãªã以å解æ¾ããå ´æãåæã«å ±åãã¦ãããããã é常ã®ã¯ã©ãã·ã¥ã¬ãã¼ãããã ASan ã¯éçºè ã«ã¨ã£ã¦ããæçãªæ å ±ãæä¾ãã¦ããã¾ãã
Nightly ã®ãã¹ã㧠ASan ã®æ©æµãããå¾ããããããç§éã¯ä¸¡è ã ASan Nightly Project ã«çµ±åãããã¨ã«ãã¾ããã ç¹æ®ãª ASan ã¬ãã¼ã¿ã¢ããªã³ãçµã¿è¾¼ãã ASan Nightly ãã«ããç¬èªã«ä½æãã ã¢ããªã³ã ASan ã®ã¨ã©ã¼ãæ¤ç¥ã»åéã㦠Mozilla ã«éä¿¡ã§ããããã«ãã¾ããã ãã®ããã¸ã§ã¯ãã¯æ¢ã«å®ç°å¢ã¸å±éããã¦ããã å®éã«è¦ã¤ãã£ã ASan ã¨ã©ã¼ã®ã¬ãã¼ããå©ç¨ãã¦ã åç¾ã®é£ããåé¡ãç¹å®ã»ä¿®æ£ã§ããããã«ãã¦ãã¾ãã ç¾å¨ã¯ Linux çãã«ãã«ã®ã¿å°å ¥ãã¦ãã¾ãããWindows ç㨠Mac çã®ãã«ãã«å¯¾ãã¦ãéæåãè¾¼ãã§ãã¾ãã
å½ç¶ãªãããã®ã¢ããã¼ãã«ã¯æ¬ ç¹ãããã¾ãã ASan ã®æç¡ã¯ã³ã³ãã¤ã«æéã«ã¯ãã»ã©å½±é¿ãä¸ãã¾ãããã 解æ¾å¾ä½¿ç¨ãæ¤ç¥ããã«ã¯ ASan ã解æ¾æ¸ã¿ã®ã¡ã¢ãªãä¿æãã¦ããå¿ è¦ãããããã ï¼æ¢ã«éã®å¤ãï¼ã¡ã¢ãªä½¿ç¨éãããã«å¢å¤§ããã«ã¤ãã¦ããã©ã¦ã¶ã®å®è¡æéãããé·ããªã£ã¦ãã¾ãã®ã§ãã ãããã£ã¦ãASan Nightly ãã«ããåããã«ã¯ååãªéã® RAM ãå¿ è¦ã¨ãªãï¼æä½ 16 GB 以ä¸ãæ¨å¥¨ï¼ã ã¾ãã¡ã¢ãªã解æ¾ããããã« 1 æ¥ã« 1 ~ 2 åãã©ã¦ã¶ãåèµ·åãããå¿ è¦ãããã¾ãã
ããããæ°ãã Firefox ç°å¢ã§ã® web ãã©ã¦ã¸ã³ã°ããã¨ããªãã®ãªãã ããªãã¯ãã°ãã¦ã³ãã£ã®å ±å¥¨éãåãåãè³æ ¼ãããããããã¾ããã ããªãã® Firefox ããèªåçã«éä¿¡ãããã¬ãã¼ãã¯ã Bugzilla ã«å ±åããããã¹ãã±ã¼ã¹ç¡ãã® bug ã¨åãããã«æ±ããã¾ãã ããªãã¡ããã®åé¡ã 1) é©åãªã»ãã¥ãªãã£ãã°ã§ãããã㤠2) Mozilla ã®éçºè ã«ãã£ã¦ä¿®æ£å¯è½ãªå ´åã ãã°ãå ±åããããªãã«ãã°ãã¦ã³ãã£ã®å ±å¥¨éãæ¯æããã¾ãï¼Mozilla Bug Bounty Program ã®è¦åã¯ãã¹ã¦é常éãé©ç¨ããã¾ãï¼ã ãã®ããã¸ã§ã¯ãã«åå ãã¦ã¬ãã¼ããèªåå義ã®ãã®ã«ããå ´åã¯ã Bug Bounty ã®ã»ã¯ã·ã§ã³ãããèªãã ä¸ã§ãè¨å®é ç®ãæ£ããã»ãããã¦ãã ããã
ãã®ããã¸ã§ã¯ããææãæããããã«ã¯ãååå¤ãã®äººããã®ããã¸ã§ã¯ãã«åå ãã¦ãããå¿ è¦ãããã¾ãã åå è¦ç´ãç解ãã¦ããã ããæ¯éããªããåå ãã¦ããã ãããã¨ããå¾ ã¡ãã¦ãã¾ãã
Mozilla web ã»ãã¥ãªãã£ãã¦ã³ãã£ããã°ã©ã ã®å·æ°
ãã®è¨äºã¯ã2017 å¹´ 5 æ 11 æ¥ä»ã§ Mozilla Security Blog ã«æ稿ããã Relaunching Mozillaâs Web Security Bounty Program ï¼çè ï¼April Kingï¼ã®ç¿»è¨³ã§ãããã®ç¿»è¨³ã¯å ¬å¼ãªãã®ã§ã¯ããã¾ããã詳ãã㯠ãã¡ã ãã覧ãã ããã
ãã®åº¦ Mozilla 㯠web ã»ãã¥ãªãã£ãã°ãã¦ã³ãã£ããã°ã©ã ãå·æ°ãã web ã»ãã¥ãªãã£ãã°ã®å ±å¥¨éã«ãããéææ§ãåä¸ããã¾ããã
æ´å²
ãã°ãã¦ã³ãã£ããã°ã©ã ã¯ä½å¹´ãåã« Netscape ã åã㦠åµè¨ãããã®ã§ãããMozilla 㯠2004 å¹´ 8 æã« ãã°ãã¦ã³ãã£ããã°ã©ã ãéå§ãã¾ããã å½æ㯠Linspire, Inc. 㨠Mark Shuttleworth ããè³éæä¾ãåãã Firefox ã¨ä»ã® Mozilla ã½ããã¦ã§ã¢ã§è¦ä»ãã£ãé大ãªã»ãã¥ãªãã£èå¼±æ§ã«å¯¾ã㦠$500 ãæ¯æã£ã¦ãã¾ããã ç¾å¨ã®ãã°ãã¦ã³ãã£ã§ã¯ éé¡ã 6 æ¡ã«éãã ãã¨ããããããå½æã®éé¡ã¯ç§æçã«è¦ããããããã¾ãããã å¥ã®è¦ç¹ã§ã¯ã»ãã¥ãªãã£ãã°ã®çºè¦ã«å¯¾ãããã¯ããã¸ã¼ä¼æ¥ã®å§¿å¢ã大ããåé²ããã¨ãè¦ããã¨ãã§ãã¾ãã
ãããã 6 å¹´å¾ã® 2010 å¹´ 12 æã Mozilla 㯠web ãµã¼ãã¹ã«ãã¦ã³ãã£ããã°ã©ã ãå°å ¥ããæåã®ä¼ç¤¾ã® 1 ã¤ã¨ãªãã¾ããã å ±å¥¨éé¡ã®å¹ 㯠$500 ãã $3000 ã¨å¤§ããåé²ã§ãã¾ããããå½æ㯠web ã»ãã¥ãªãã£ã®ç¶æ æ¹åã«ç¦ç¹ãåããã¦ãã¾ããã
æåã«å ±å¥¨ããã web ã»ãã¥ãªãã£ãã°ï¼addons.mozilla.org ã® XSS èå¼±æ§ï¼ããç¾å¨ã«è³ãã¾ã§ã èªèº«ã®å°éæ§ãç§ãã¡ã®ã¦ã¼ã¶ã®ä¿è·ã«å½¹ç«ã¦ã¦ãã ãã£ãä¸çä¸ã®ãã°ãã³ã¿ã¼ã«ã延ã¹æ°åä¸ãã«ããæ¯æããã¦ãã¾ããã
åé¡ã¨è§£æ±ºç
ãã°ãã¦ã³ãã£ããã°ã©ã ã®éç¨ã¯ãç¹ã« Mozilla ã®ãããªä¼æ¥ã«ã¨ã£ã¦ã¯å¸¸ã«å°é£ãä¼´ãã¾ãã ããã¾ã§ç´ 20 å¹´ã®é web ãæ¯ãç¶ãã¦ãããã¹ã¿ãããã³ã³ããªãã¥ã¼ã¿ã¼ããããã¨ã«å ãã ç§ãã¡ã® web ãµã¤ãã®ç¨®é¡ã¯é£èºçã«å¢ãã¦ãã¾ããã www.mozilla.org ãã www.bugzilla.org ã arewefastyet.com ã«è³ãã¾ã§æ°å¤ãããã¾ããã ãããã®ãµã¤ãã®ä¸ã«ã¯ Mozilla ã®ãªãã¬ã¼ã·ã§ã³ã«å¯¾ã㦠ä»ã®ãã®ããã é¥ãã«å¤§ããªãªã¹ã¯ ãæ±ãã¦ãã¾ãã
ããã¦åé¡ã¯ãã®ãªã¹ã¯ç¹æ§ããã°ãã³ã¿ã¼ã«èª¬æããéã«çãã¾ãã Bugzilla ã«ãããéå®ç㪠SQL ã¤ã³ã¸ã§ã¯ã·ã§ã³ã¯ã Observatory ã§ã® XSS æ»æãã³ãã¥ããã£ããã°ã§ã®ãªã¼ãã³ãªãã¤ã¬ã¯ã¿ã¨ã¯ Mozilla ã«å¯¾ãããªã¹ã¯ãç°ãªãã¾ãã ãããããã°ãã³ã¿ã¼ã«ã¨ã£ã¦ã¯ãªã¹ã¯ã®åº¦åãã«èå³ããªããã¨ããã°ãã°ã§ãã å½¼ããç¥ããããã¨ã¯ãç´ç²ã«ãã®ãµã¤ãã®ãã°ãå ±å¥¨å¯¾è±¡ãã©ããã¨å®éã«æ¯æãããéé¡ã§ãã
æ¦ãå ±å¥¨å¯¾è±¡ã® web ãµã¤ãã¯åççã«ãªã¹ãåããã¦ããã¨æãã¾ãããå®éã®æ¯æéé¡ã¯ã±ã¼ã¹ã«ãã£ã¦ç°ãªãã¾ãã ããã«ããªã¹ãã«æ示çã«è¼ã£ã¦ããªããµã¤ãã®ãã°ã«å¯¾ããéé¡ã®å¤æã¯ããé£ãããªãã¾ãã
éé¡ããã°ãã³ã¿ã¼ã®æå¾ ã¨åçããããã¯è¶ ããããã§ããã°ä½ãåé¡ããã¾ããã ãããæå¾ ãä¸åã£ã¦ãã¾ã£ãå ´åããã°ãã³ã¿ã¼ã®æ¹ã¯ãã£ãããã¦ãã¾ãããããã¾ããã ããã«ã¯ãç¹å®ã®ãµã¤ãã«å¯¾ãã¦éé¡ã®ä¾å¤ãè¨ãã¦ãã¾ãã¨ã ä»ã«ãä¾å¤ãããã®ã§ã¯ã¨æå¾ ããã¦ãã¾ãå¯è½æ§ãããã¾ãã
ç¾å¨
ããã§ç§ãã¡ã¯å ã®ãããªå¤ãã®åé¡ã解決ããã¹ããã¦ã³ãã£ããã°ã©ã ãå·æ°ãã åæã«å ±å¥¨å¯¾è±¡ã¨ãªã web ãµã¤ãã¨ãã°ã®ç¨®é¡ãå¢ããã¾ããã ããã«ãããããã®ãã°ã¨ web ãµã¤ãã®ç¨®é¡ã«å¯¾å¿ããæ¯æéé¡ããªã¹ã¯ç¹æ§ã«åºã¥ã㦠æ示çã«ãªã¹ãåãã¾ããã
ï¼è©³ãã㯠表ã®å ¨ä½ã åç §ãã¦ãã ããï¼
æ確ã§ç´æçãªæ¯æéé¡ã®è¡¨ãä½æãããã¨ã§ã ãã°ãã³ã¿ã¼ã®æ¹ã ã¯å ±å¥¨éãåãåããã¨åãã£ã¦ãããã°ã®çºè¦ã«æéã¨å´åã注ããããã«ãªãã åãã£ã¦å®éã®æ¯æéé¡ãç¥ããã¨ãã§ãã¾ãã å ãã¦ããã°ãã¦ã³ãã£ã® Hall of Fame ã«ç»é²ããããã°ã®ç¨®é¡ãæ¡å¤§ãã¦ãã¾ãã ãããã®ãã°ã«ééçãªå ±é ¬ã¯ããã¾ãããã ãã°ãã³ã¿ã¼ã«ãã web ã®å®å ¨æ§ã«å¯¾ããå績ãåºãæè¬ããç§ãã¡ãªãã®æ¹æ³ã¨ãã¦è¡ã£ã¦ãã¾ãã
ç§ãã¡ã® ãã´ ãã 製å ã«è³ãã¾ã§ãMozilla ã¯å ¬éæ§ã«èªè² ãæ±ãã¦ããä¼æ¥ã§ãã å ±å¥¨éé¡ã«å¯¾ããå ¬éæ§ã¯ä¸ã®ä¸ã§ã¾ã é²ãã§ããªãé åã§ããã ä»åã®å·æ°ã«ãã£ã¦ web å ¨ä½ã«ããããã°ãã¦ã³ãã£ããã°ã©ã ã®å ¬éæ§åä¸ã«è²¢ç®ã§ãããã¨ãé¡ã£ã¦ãã¾ãã
web ãã°ãã¦ã³ãã£ããã°ã©ã ã«æ¢ã«è²¢ç®ãã¦ããã ãã¦ããçããã«ã¯ã ãã®ä»çµã¿ãçããã®å´åãéä¸ããããã¨ã«ç¹ããã°å¹¸ãã§ãã åãã¦éããªãçããã«ã¯ããã²ä¸ç·ã«ã¤ã³ã¿ã¼ããããããå®å ¨ãªå ´æã«ãã¦ããã¾ãããï¼
ã翻訳ãCA Certificate Policy ãã¼ã¸ã§ã³ 2.4 ãªãªã¼ã¹
ãã®è¨äºã¯ã2017 å¹´ 4 æ 4 æ¥ä»ã§ Mozilla Security Blog ã«æ稿ããã Mozilla Releases Version 2.4 of CA Certificate Policy ï¼çè ï¼Kathleen Wilsonï¼ã®ç¿»è¨³ã§ãããã®ç¿»è¨³ã¯å ¬å¼ãªãã®ã§ã¯ããã¾ããã詳ãã㯠ãã¡ã ãã覧ãã ããã
ç§ãã¡ Mozilla 㯠Mozilla’s CA Certificate Policy ã®ãã¼ã¸ã§ã³ 2.4.1 ããªãªã¼ã¹ãã Mozilla 製åã«å梱ããã¦ãã ã«ã¼ã証ææ¸ãææãã èªè¨¼å±ï¼CAï¼ ã«å¯¾ãã¦ãè¦ä»¶ã«é¢ããä»åã®å¤æ´ç¹ãªã©ã CA Communication ã¨ãã¦éç¥ãã¾ããã Network Security Services (NSS) ã¨ã¯ãã»ãã¥ãªãã£æ©è½ãæã£ãã¯ã©ã¤ã¢ã³ãã»ãµã¼ãã¼ãéçºããéã«ã ã¯ãã¹ãã©ãããã©ã¼ã ãªã¢ããªã±ã¼ã·ã§ã³ã¨ãã¦éçºã§ããããè¨è¨ãããã ãªã¼ãã³ã½ã¼ã¹ã®ã»ãã¥ãªãã£ã©ã¤ãã©ãªç¾¤ã§ãã Mozilla’s CA Certificate Program ã¯ã ãã® NSS ã«ã«ã¼ã証ææ¸ã追å ããéã®æç¶ããéç¨ããå½¹å²ãæ ã£ã¦ãã¾ãã NSS ã®ã«ã¼ã証ææ¸ã¯ Firefox ãã©ã¦ã¶ã¼ã¨ãã£ã Mozilla 製åã®ã¿ãªããã ä»ã®ä¼æ¥ããªã¼ãã³ã½ã¼ã¹ããã¸ã§ã¯ããæ§ã ãªã¢ããªã±ã¼ã·ã§ã³ã§å©ç¨ãã¦ãã¾ãã
Mozilla’s CA Certificate Policy ã«ãããä»åã®æ¹è¨å 容ã¯ä»¥ä¸ã®éãã§ãã
- ç£æ»å ±åæ¸ã«å ãã証ææ¸ããªã·ã¼ï¼CPï¼ã¨èªè¨¼å±éç¨ããªã·ã¼ï¼CPSï¼ã Mozilla ã¸æ¯å¹´éä»ãããã¨
- 2017 å¹´ 6 æ 1 æ¥ãããç£æ»å ±åãCPãCPS ã¯è±èªã§æ示ãããã¨ï¼å¿ è¦ã«å¿ãã¦ç¿»è¨³ãããã¨ï¼
- ãã¹ã¦ã®æåºè³æã«ãªã¼ãã³ãªã©ã¤ã»ã³ã¹ãä»ä¸ãããã¨ï¼è©³ç´°ã¯ã©ã¤ã»ã³ã¹ã®é¸æè¢ã¨æ¡é ãåç §ï¼
- Mozilla’s CA Certificate Policy ãã¼ã¸ã§ã³ 2.4 ãã Common CCADB Policy 㨠Mozilla CCADB Policy ãåç §ããããã«
- æ°ãã Common CA Database (CCADB) ã«ãããCCADB ã«é¢ãã¦ä»ã¾ã§æé»ã ã£ãæå¾ äºé ãææå
- åçãããç£æ»åºæºã®ä¸è¦§ãæ´æ°
- OCSP ã¬ã¹ãã³ã¹ã«é¢ããè¦ä»¶ã追å
- 証ææ¸ã®ã·ãªã¢ã«ãã³ãã¼ã«å¯¾ã㦠64 ãããã®ã¨ã³ãããã¼ãè¦ä»¶ã¨ãã¦æå®
Mozilla’s CA Certificate Policy ã«ããã ãã¼ã¸ã§ã³ 2.4 㨠2.3 ï¼2016 å¹´ 12 æå ¬éï¼ã®å·®åã¨ã ãã¼ã¸ã§ã³ 2.4 㨠2.2 ï¼2013 å¹´ 7 æå ¬éï¼ã®å·®åã¯ããããã GitHub ã§åç §ã§ãã¾ãã ãã¼ã¸ã§ã³ 2.4.1 ã¯ãã¼ã¸ã§ã³ 2.4 ã®è¦ç¯çãªå 容ãå¤ããã«æ§æãä¸æ°ãããã®ã§ãã
ä»åã® CA Communication ã¯é¢ä¿ããå CA ã® Primary Point of Contact (POC) ã¸ã¡ã¼ã«ã§éä¿¡ããã14 ã®èª¿æ»é ç®ã«å¯¾ããè¿çãæ±ãã¦ãã¾ãã 調æ»é ç®ã®ä¸è¦§ã¯ ãã¡ã ãã確èªã§ãã¾ãã ãã®èª¿æ»ã«å¯¾ããè¿ç㯠Common CA Database ãéã㦠èªåã§éããã«å ¬é ããã¾ãã
ãã®èª¿æ»ã«å ãã mozilla.dev.security.policy ãã©ã¼ã©ã ã«ãããè°è«ã«å¾ããã¨ã追å è¦ä»¶ã¨ãã¦æ¤è¨ä¸ã§ãããã¨ã CA ã«éç¥ãã¾ããã ãã®ãã©ã¼ã©ã ã§ã¯ã Mozilla’s CA Certificate Policy ã§äºå®ããã¦ããå¤æ´ããããªã·ã¼ã¨æå¾ ã«é¢ãã質åãæ確åã ã«ã¼ã証ææ¸ã®è¿½å ã»å¤æ´ç³è«ã CA/Browser Forum’s Baseline Requirements ãä»ã®è¦ä»¶ã«æºãã¦ããªã証ææ¸ã«é¢ããè°è«ãªã©ãè¡ããã¦ãã¾ãã ãã©ã¼ã©ã ã§ã®è°è«ã«åå ãããã¨ã¯ CA ã«è¦æ±ãã¾ãããã è°è«ã®å 容ãèªèãã¦ãããã¨ã®ã¿è¦ä»¶ã¨ãã¾ãã ããããªãããå°æ¥ã® Mozilla’s CA Certificate Program ãããè¯ããã®ã¨ããããã å CA ãè°è«ã«åå ãã¦ããã ãããã¨ãæãã§ãã¾ãã
ãã® CA Communication ã¯ãCA ã Mozilla’s CA Certificate Program ã«åå ã§ãããã©ããã¯ç§ãã¡ã®å¤æ ã®ã¿ã§æ±ºã¾ããã¨ãã¾ãç§ãã¡ã®ã¦ã¼ã¶ãä¿è·ããããã«ã¯ãããªãæ段ããè¬ãããã¨ãã ä»ä¸åº¦ç¹°ãè¿ã強調ãããã®ã§ãã ã¨ã¯ãããã»ãã¥ãªãã£ãç¶æããæ¹æ³ã¨ãã¦æãè¯ãã®ã¯ã ãã¼ããã¼ã¨ã㦠CA ã¨ååãã¦ãããã¨ã ãªã¼ãã³ã§çç´ãªã³ãã¥ãã±ã¼ã·ã§ã³ãä¿ãã¦ãããã¨ã ç¾ç¶ã®ãããªãæ¹åæ¹æ³ãæ¢ãããã«åªåãã¦ãããã¨ã 㨠Mozilla ã¯èãã¦ãã¾ãã
Mozilla Security Team