Web over HTTPS DevFest Tokyo 2016 #devfest16 2016/10/0
æ¬ç¨¿ã¯CodeZineã«2015å¹´12æ28æ¥ã«æ²è¼ãããè¨äºã®åæ²ã¨ãªãã¾ãã ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°(XSS)ã¯ãå¤ãããåå¨ãéçºè ã«ãã£ã¨ãããç¥ãããã»ãã¥ãªãã£ä¸ã®åé¡ã®ã²ã¨ã¤ã§ãããªãããOWASP Top 10ã§ã2010å¹´ã«å¼ãç¶ã2013å¹´ã§ã3ä½ã¨ãæªã ã«æ ¹çµ¶ã§ãã¦ããªãèå¼±æ§ã§ãã æ¬è¨äºã§ã¯ãWebã¢ããªã±ã¼ã·ã§ã³ã®éçºã«ããã¦XSSãæ ¹çµ¶ããããã«å¿ è¦ãªå¯¾çã®åºæ¬ãæ¬æ°ã§ãä¼ããã¾ãã ã¯ããã« OWASPã§ã¯éçºè ã«åããã»ãã¥ãªãã£å¯¾çã®ããã®ããã¥ã¡ã³ãããã¼ãã·ã¼ããå¤æ°ç¨æãã¦ãããXSSã¸ã®å¯¾çã¨ãã¦ããXSS (Cross Site Scripting) Prevention Cheat Sheetãã¨ããããã¥ã¡ã³ããç¨æããã¦ãã¾ãã ãã ãããã®XSS Prevention Cheat Sheetã¯ã·ã³ãã«ãªã«ã¼ã«ãå®ãããã¼ãã·ã¼ãã§
ã»ãã¥ãªãã£ã»ãã£ã³ãå ¨å½å¤§ä¼2015ã®è¬ç¾©ã§ä½¿ç¨ãããè³æã®ã¾ã¨ããå ¬éããã¦ããªãè¬ç¾©ãå¤ãã®ã§ããã¹ã¦ã®è¬ç¾©è³æãããããã§ã¯ããã¾ãããéæ追å ã é«ã¬ã¤ã¤ã¼ãã©ã㯠Webãã©ãããã©ã¼ã ã®ã»ãã¥ãªã㣠JavaScripté£èªåèªçµ HTTP/2, QUICå ¥é SSL/TLSã®åºç¤ã¨ææ°åå ãã¬ã¼ã ã¯ã¼ã¯ã«è¦ã Web ã»ãã¥ãªãã£å¯¾ç(ããããã®Webã»ãã¥ãªãã£) ããããã®Webã»ãã¥ãªã㣠ããã³ãã¨ã³ãç·¨ ã¯ã©ã¦ãã»ãã¥ãªãã£åºç¤ ãã°ãã³ãã£ã³ã°å ¥é 解æãã©ã㯠仮æ³åæè¡ãç¨ãããã«ã¦ã§ã¢è§£æ è¬ç¾©å 容 TOMOYO / AKARI / CaitSith ãã³ãºãªã³ï¼ã¢ã¯ã»ã¹è§£æåç´ã»ä¸ç´ï¼ ã»ãã¥ãªãã£ã»ãã£ã³ãå ¨å½å¤§ä¼2015ã§ã®ãã«ã¦ã¨ã¢åæè¬ç¾©(2015-09-10) ãã¥ã¼ã¿ã¼çºè¡¨ ãèå¼±æ§ãã¿ã¤ããããããèå¼±æ§ããªããã㸠ã«ã¼ãã«ç©ºéããã®ã»
ããã«ã¡ã¯ãäºå³¶å¤å¤ã§ãï¼ æ®æ®µã¯ããªã¼ã©ã³ã¹ã¨ãã¦ã¤ã©ã¹ãã¬ã¼ã¿ã¼ãã¢ãã«ã®ãä»äºããã¦ããç§ã§ãããä»æ¥ã¯NO MORE æ å ±æ¼ããããã¸ã§ã¯ãã®ä¸å¡ã¨ãã¦ãä¸æ¥ã¤ã³ã¿ãã¥ã¢ã¼ã«ææ¦ãã¾ãï¼ çªç¶ã§ããçããã¯ãæ¯æ¥ã®çæ´»ã®ä¸ã§ãã»ãã¥ãªãã£ãã«ã¤ãã¦ã©ããããæ°ãã¤ãã¦ãããã¨ãããã¾ããï¼ ç§ãTwitterãFacebookãããå©ç¨ãã¾ããããä»äºãã¡ã¼ã«ã§åãã¦ãã¾ããPCã使ãæ©ä¼ãå¤ãã®ã§æ å ±ã®ç®¡çã«ã¯æ°ãã¤ããªããã¨æã£ã¦ããã®ã§ããããå ·ä½çã«ä½ãã©ãæ°ãã¤ããã°ããã®ãããããªãï¼ãã¨ãã人ã¯ç§ã ãã§ã¯ãªãã¯ãã§ãã ã¨ãããã¨ã§ä»åã¯ãã»ãã¥ãªãã£ã®ãããã§ãã·ã§ãã«ã¨å¼ã°ãã徳丸 浩ï¼ã¨ãã¾ã ã²ããï¼å çã«å¯çåæï¼ ãããã©ããªã¨ããã«æ°ãã¤ãã¦ããã®ããç§ãã¡ã®çæ´»ã«ãæ´»ãããããªãã¯ããã¯ãçãã§ãããã¨æãã¾ãï¼ å¾³ä¸¸ 浩ï¼ã¨ãã¾ã ã²ããï¼å ç HA
æè¿ã¯ã¯ã©ã¦ãä¸ã®ãµã¼ãã¼ãå©ç¨ããäºãå¤ããªã£ã¦ããã ãµã¼ãã¼ã®ç¨æããããã¯ã¼ã¯å¨ãã®è¨å®ã¯ã¤ã³ãã©é¨éããã£ã¦ããããã©ãã¢ããªã®ãããã¤ï¼è¨å®ã¯éçºè ãããäºãå¤ãã®ã§ãéçºã¡ã¤ã³ã§ãã£ã¦ãã¨ã³ã¸ãã¢ã§ãæä½éSSHã®ç¥èã¯å¿ è¦ã«ãªãã ã¾ããVagrantçã§ãã¼ã«ã«ç°å¢ã«VMãä½æããäºãããã®ã§ããã¼ã«ã«ç°å¢å ã§SSHã使ç¨ããã±ã¼ã¹ãå¢ãã¦ããã ã¨ããããã§ã¤ã³ãã©ã¨ã³ã¸ãã¢ãããªãã¦ãSSHã¯ã©ã¤ã¢ã³ãã®ç¥èã¯å¿ é ã«ãªã£ã¦ãã¦ããã®ã§ãæ¹ãã¦SSHã®åå¦ç¿ããã¦ã¿ããã¨ã«ããã SSHã¨ã¯ æå·ãèªè¨¼ã®æè¡ãå©ç¨ãã¦ãå®å ¨ã«ãªã¢ã¼ãã³ã³ãã¥ã¼ã¿ã¨éä¿¡ããããã®ãããã³ã«ã SSHã§ã¯ä»¥ä¸ã®ç¹ã§å¾æ¥ã®Telnetããå®å ¨ãªéä¿¡ãè¡ããã1 ãã¹ã¯ã¼ãããã¼ã¿ãæå·åãã¦éä¿¡ããã ã¯ã©ã¤ã¢ã³ãããµã¼ãã¼ã«æ¥ç¶ããæã«ãæ¥ç¶å ãæå³ããªããµã¼ãã¼ã«èªå°ããã¦ããªããå³å¯ã«
Web ãµã¤ãã常æ SSL åããå ´åã«ãæä½éç¥ã£ã¦ãããªããã°ãªããªãç¥èãã注æç¹ãå®éã®è¨å®æ¹æ³ã¾ã§ãã²ã¨éãã¾ã¨ãã¦ã¿ã¾ãããã¡ãªããããã¡ãªããã証ææ¸ã®ç¨®å¥ãããªãã¤ã¬ã¯ãè¨å®ãªã©ã«ã¤ãã¦ã解説ãã¦ãã¾ãã HTTPS ãã©ã³ãã³ã°ã·ã°ãã«ã«ä½¿ç¨ãã¾ã㨠Google ãå ¬å¼ã«çºè¡¨ããããããããWeb ãµã¤ãã® SSL 対å¿ãç¹ã« Google ãæ¨å¥¨ãã¦ãã Web ãµã¤ãããã¹ã¦ HTTPS ã§é ä¿¡ãããæè¬ ã常æ SSL åã ã«ã¤ãã¦ã®è©±ãèããããå®éã«ã客æ§ããç¸è«ããããããã±ã¼ã¹ãå¢ãã¦ãã¾ããã ããã§ãããæ©ä¼ã ããã®è¾ºã«é¢ããæ å ±ãã¾ã¨ãã¦ãããããªï½ ã¨æã£ã¦æ¸ãã¦ã¿ããæä¾ã® ï¼ï¼ï¼ 5åã§ãããã·ãªã¼ãºãæ¸ãçµãã£ã¦è¦ãã¨ãã絶対㫠5åããç¡çã£ã¦ããæç« éã«ãªã£ã¦ã¦ã©ããããããªãã¨ãæã£ããã§ãããæ°ã«ããå ¬éãã¦ã¿ã¾ãã 常æ SSL
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}