4. äºåå¦ç¿ãæ¯ãè¿ã ⢠HSTSãå ã«æ¬¡ã®ãããªåé¡ç¹ãèå¯ãã ãã®æè¡ã§ã¯è§£æ±ºã§ããªãåé¡ ç«¯æ«æå»ã®æ¹ããã«ããHSTSã®å¼·å¶å¤±å¹ ãã®æè¡ã®å°å ¥ã«ããæ°ãã«çããåé¡ HSTSãç¨ããã¦ã¼ã¶ã¼è¿½è·¡ (HSTS Supercookies) å®è£ ã®èª¤ãã«èµ·å ããåé¡ æå®ã誤ãã¨HTTPSé対å¿ã®ãµããã¡ã¤ã³ãã¢ã¯ã»ã¹ä¸è½ã« ä»æ§ä¸æ¢å®ããã¦ããªãæ¯ãèã HSTSã¯WebSocket(ws:)ã«ãé©ç¨ãããã®ãï¼ CVE-2015-1244: Chrome ã§WebSocketã«HSTSãé©ç¨ãããªã HSTSã¯ãã©ã¤ãã·ã¼ã¢ã¼ãã«ãå¼ãç¶ãã®ãï¼ ã¾ããã®éã¯ï¼ 7. ç§ã®æ¦æ´(åè) ⢠次ã®ãããªä»æ§ä¸åãèå¼±æ§ã¨ãã¦ææãã¦ãã Chromeã®CSPéåã¬ãã¼ãã®éä¿¡å ã<base>ã§å¶å¾¡ã§ãã https://crbug.com/431218 Chromeã®HTML
{{#tags}}- {{label}}
{{/tags}}