The latest news and insights from Google on security and safety on the Internet
GoogleãOpenSSLããã©ã¼ã¯ãããBoringSSLãã¨ãã¦å ¬éãã(ImperialVioletããã°ã®è¨äºã Ars Technicaã®è¨äºã æ¬å®¶/.)ã Googleã¯ä½å¹´ãã®éãOpenSSLã«æ°å¤ãã®ããããå½ã¦ã¦ä½¿ç¨ãã¦ããã¨ãããä¸é¨ã®ãããã¯OpenSSLã®ã¡ã¤ã³ãªãã¸ããªã«åãè¾¼ã¾ãããã大åã¯APIãABIã®å®å®æ§ã®åé¡ããããªã©ã®çç±ã§åãè¾¼ã¾ãã¦ããªãã£ããAndroidãChromeãªã©ã®è£½åã¯ãããã®ä¸é¨ãå¿ è¦ã¨ãããããããã¯70以ä¸ãããããã«ä½æ¥ãè¤éã«ãªã£ã¦ããããã ããã®ãããOpenSSLããã©ã¼ã¯ãã¦ãOpenSSLå´ã®å¤æ´ãã¤ã³ãã¼ãããæ¹å¼ã«å¤æ´ããã¨ãã¦ãããBoringSSLã¯è¿ããã¡ã«Chromiumã®ãªãã¸ããªã«è¿½å ãããäºå®ã§ããããAndroidãå é¨çã«ã使ãããããã«ãªãããã ããBoringSSLã§ã¯APIãABI
ä¸æ¨æ¥æ¸ããè¨äºã«å¯¾ããè£è¶³ã§ãã ã¾ããæåã«BGPãã¤ã¸ã£ãã¯ãã®ãã®ã¯ãä¸çåæã§æ¯æã®ããã«çºçãã¦ãããå¥ã«çããããªã話ã§ãã ãã®ã»ã¨ãã©ããæå³çã«ãã©ãã£ãã¯ãä¹ã£åãç®çã§è¡ããããã®ã§ã¯ãªããåãªããªãã¬ã¼ã·ã§ã³ãã¹ã§ããã¨è¨ããã¦ãã¾ãã BGPãã¤ã¸ã£ãã¯ã§æåãªã®ãã2008å¹´ã«YouTubeã¸ã®ãã©ãã£ãã¯ãããã¹ã¿ã³ã®ISPãå¸ãè¾¼ãã§ãã¾ã£ãäºä»¶(åèï¼RIPE-NCC: YouTube Hijacking: A RIPE NCC RIS case study)ã§ããããããæå³çã«ãã£ãã®ã§ã¯ãªããããã¹ã¿ã³å½å åãã®ãããæ¤é²è¨å®ãå¤é¨ã«æ¼ãã¦ãã¾ã£ãã¨ãããªãã¬ã¼ã·ã§ã³ãã¹ã ã£ãã¨æããã¾ãã ãªãã¬ã¼ã·ã§ã³ãã¹ã¯ãæ¼ããã¦ãã¾ã£ãå´ã ãã§ã¯ãªãå¯è½æ§ãããã¾ãã ããããã/32ãªã©ã®ãã¬ãã£ãã¯ã¹é·ãæã¤çµè·¯ã¯ãã£ã«ã¿ããã¦ãããã¨ãå¤ãã®ã§ãæ®
ãã©ã¸ã«ã¨ãããºã¨ã©ã®ãããã¯ã¼ã¯ã§ãGoogle Public DNSãéç¨ããã¦ãã8.8.8.8ããæ大22åéBGPãã¤ã¸ã£ãã¯ãããã¨BGPmonãTwitterã§è¡¨æãã¦ãã¾ãã https://twitter.com/bgpmon/status/445266642616868864/photo/1 BGPmonã®Tweetã«ããã¨ããããºã¨ã©ã«ããAS7908(BT LATAM Venezuela,S.A.)ã8.8.8.8/32ãåºåãããã¨ãåå ã®ããã§ãã ãã©ã¸ã«ã¨ããã°ããã©ã¸ã«å½æ°ã®ãã¼ã¿ããã©ã¸ã«å½å ã«çãããã¨ãæ±ããæ³å¾ãæç«ãããã¨ã«ãã£ã¦ãæ¨å¹´10æã«åå½ããGoogle Public DNSãæ¤éãã¦ãã¾ã(Renesys: Google DNS Departs Brazil Ahead of New Law)ã å®éã®ã¨ããã¯ç¥ãã¾ãããããã®æ¤éã«
Googleã®èå¼±æ§å ±é ¬å¶åº¦ã®å ±é ¬ãã¢ããããã¾ãããï¼ Googleãèå¼±æ§æ å ±ã«æ¯æãå ±å¥¨éãå¤§å¹ ã¢ãã - ITmedia ã¨ã³ã¿ã¼ãã©ã¤ãº http://www.itmedia.co.jp/enterprise/articles/1306/10/news027.html Googleã¢ã«ã¦ã³ããã¼ã¸ã«åå¨ããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼XSSï¼ã®èå¼±æ§æ å ±ã«ã¤ãã¦ã¯3133.7ãã«ãã7500ãã« accounts.google.comã®XSSã¯$7,500 ã ããã§ããã¿ã¤ãããã§ããï¼ ã¿ã¤ããã®ã¯ããªãå³ããã¨æãã¾ããããã¤ã¦2ã¤ã¿ã¤ãããã¨ãããã¾ãã ä»æ¥ã¯ãã®ãã¡1ã¤ãç´¹ä»ãããã¨æãã¾ãã oeãã©ã¡ã¼ã¿ã使ã£ãXSS 2012å¹´12æ27æ¥ã«å ±åãä¿®æ£ãããåé¡ã§ãã Googleã¯ãä¸é¨ã®ãµã¼ãã¹ã§ãoeãã¨ããã¯ã¨ãªãã©ã¡ã¼ã¿ãä»å ãããã¨ã§ããã¼ã¸ã®è¡¨ç¤ºã«
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}