YAPC::Hakodate 2024ã§ã®çºè¡¨å 容ã§ãã https://yapcjapan.org/2024hakodate/
ãã®ã³ã¼ãã¼ã§ã¯ã2014å¹´ããå 端ãã¯ããã¸ã¼ã®ç 究ãè«æåä½ã§è¨äºã«ãã¦ããWebã¡ãã£ã¢ãSeamlessãï¼ã·ã¼ã ã¬ã¹ï¼ã主宰ããå±±ä¸è£æ¯ æ°ãå·çãæ°è¦æ§ã®é«ãç§å¦è«æãå±±ä¸æ°ãããã¯ã¢ãããã解説ããã Xï¼ ï¼ shiropen2 ãçµç¹ã¯ã¦ã¼ã¶ã¼ã«å®æçãªãã¹ã¯ã¼ãå¤æ´ãè¦æ±ãã¦ã¯ãªããªããââç±³å½æ¿åºæ©é¢ã®ç±³å½ç«æ¨æºæè¡ç 究æï¼NISTï¼ãããããªå 容ãå«ããæ°ããã¬ã¤ãã³ã¹ãSP800-63Bããçºè¡¨ããããã¹ã¯ã¼ãã®å 容ã¯ãã»ã¯ã·ã§ã³3.1.1ã«è¨ããã¦ããã å¤ãã®äººã ãæ°ãããã¹ã¯ã¼ããèãåºãããããè¦ãããã¨ã«è¦å´ãã¦ãããã»ãã¥ãªãã£ä¸ã®çç±ãããå¤ãã®çµç¹ãã¦ã¼ã¶ã¼ãå¾æ¥å¡ã«å®æçãªãã¹ã¯ã¼ãã®å¤æ´ãè¦æ±ãããããã¯ç¾©åä»ãã¦ããããããä»ãç±³å½æ¿åºã¯ã½ããã¦ã§ã¢ããªã³ã©ã¤ã³ãã¼ã«ãä½æã»éç¨ããçµç¹ã«ãã®æ £è¡ããããããå¼ã³ããã¦ããã ããã¯ãWebãµã¤ã
2024/10/5 YAPC::Hakodate 2024
20å人è¿ã人ãã¡ãã°ã¼ã°ã«ã®ç¡æã¡ã¼ã«ãµã¼ãã¹Gmailãå©ç¨ãã¦ãããå½ç¶ãªãããã°ã¼ã°ã«ã¯ã¦ã¼ã¶ã¼ã®ãã©ã¤ãã·ã¼ãå®ããæªè³ªãªè¡çºããã¢ã«ã¦ã³ããä¿è·ããããã«ãã¾ãã¾ãªå¯¾çãè¬ãã¦ããã æ¯æ¥3000åé以ä¸ã®ã¡ã¼ã«ãåãµã¼ãã¹ãéãã¦è¡ã交ãä¸ãã¡ã¼ã«ã¢ãã¬ã¹ä½æã«ããããã£ã1ã¤ã®åç´ãªãã¹ã§ãããªãã®ã¡ã¼ã«ã赤ã®ä»äººã«ããããã¦ãã¾ãå¯è½æ§ããããããã«ãã®ãã¹ã¯ããªãã®ãã©ã¤ãã·ã¼ãå±éºã«ãããã ãã§ãªããGoogleã¢ã«ã¦ã³ãå ¨ä½ã«æªå½±é¿ãä¸ããå¯è½æ§ãããã®ã ã Gmailã®ã»ãã¥ãªãã£ã¯ä¸æµ ããªãã®ã¡ã¼ã«ãè ããã®ã¯ããµã¤ãã¼ç¯ç½ªè ãããã«ã¼ããããã¯å®¶æã ãã§ã¯ãªããæ大ã®æµã¯ãããªãèªèº«ãããããªããGmailã¯ä¸çã®ã¡ã¼ã«ãããã¤ãã¼ã®ä¸ã§æãå¤ã使ããã¦ãããããããªãã®ãã°ã¤ã³èªè¨¼ããå人æ å ±ã¾ã§ããããããã®ãçããã¨ãã¦ããè ã«ã¨ã£ã¦ãã®åä¿¡ãã¬ã¤ã¯æ ¼
Firebaseã§ãµã¼ãã¹ãå ¬éããã¨ãã«ãæä½éå¿ è¦ãªã»ãã¥ãªãã£ã¼ã®ãã¤ã³ããã¾ã¨ãã¦ãã¾ãã Firebaseã¯ãç¾å¨ããããå¢ãã§éçºãé²ãã§ããã®ã§ãã»ãã¥ãªãã£ã¼ã«é¢ãããã¤ã³ãããã¦ãã¦ãæ¥ã æ´æ°ããã¾ããææ°ã®ããã¥ã¡ã³ãããå¤æ´ç¹ã調ã¹ããã¨ããããããã¾ãããã®è¨äºãå«ãããããã®è¨äºã¯å¤ãå¯è½æ§ãããã¾ãã2022å¹´åå¾ã§ããApp Checkå°å ¥ãCross service Rulesã®å°å ¥ãAuthenticationã®Identity Platformå°å ¥ãWorkload Identityé£æºã®å°å ¥ãªã©ãæ¥ã æ´æ°ããã¦ãã¾ãã å ¬å¼ã®Firebaseã®ã»ãã¥ãªãã£ãã§ãã¯ãªã¹ãã¯å¿ ãç®ãéãã¾ãããã GCPã¤ã³ãã© Firebaseã§ä½¿ãGoogle Accountã¯å人ã®ã¢ã«ã¦ã³ãã使ããªãã§Google Workspace/Cloud Identityã®
IPA(Information-technology Promotion Agency, Japanï¼æ å ±å¦çæ¨é²æ©æ§)ã¯7æ5æ¥ããPHPã®èå¼±æ§ï¼CVE-2024-4577ï¼ãçãæ»æã«ã¤ãã¦ï½æ å ±ã»ãã¥ãªãã£ï½IPA ç¬ç«è¡æ¿æ³äºº æ å ±å¦çæ¨é²æ©æ§ãã«ããã¦ã2024å¹´6æã«å ¬éãããPHPã®èå¼±æ§ãæªç¨ãããããã¯ã¼ã¯è²«éåæ»æã確èªãããã¨ãã¦æ³¨æãåèµ·ãããIPAã¯å½å ã®è¤æ°ã®çµç¹ã«ããã¦Webã·ã§ã«ãè¨ç½®ããããªã©ã®è¢«å®³ã確èªããã¨èª¬æãã¦ããã PHPã®èå¼±æ§ï¼CVE-2024-4577ï¼ãçãæ»æã«ã¤ãã¦ï½æ å ±ã»ãã¥ãªãã£ï½IPA ç¬ç«è¡æ¿æ³äºº æ å ±å¦çæ¨é²æ©æ§ ãããã¯ã¼ã¯è²«éåæ»æã¨ã¯ ãããã¯ã¼ã¯è²«éåæ»æã¨ã¯ãã«ã¼ã¿ãVPN(Virtual Private Networkï¼ä»®æ³ãã©ã¤ãã¼ããããã¯ã¼ã¯)æ©å¨ã®ãããªã¤ã³ã¿ã¼ãããã«ç´æ¥æ¥ç¶ãããããã¤ã¹ã侵害ãã¦ã
ç±³ã»ãã¥ãªãã£ä¼æ¥ã®Phylumã¯7æ3æ¥ï¼ç¾å°æéï¼ãJavasScriptã©ã¤ãã©ãªãjQueryãã®ç¹å®ãã¼ã¸ã§ã³ãããã¤ã®æ¨é¦¬åãããGitHubãªã©ã§æ¡æ£ãã¦ããã¨è¦åããã å社ã¯5æ26æ¥ãããã±ã¼ã¸ç®¡çã·ã¹ãã ãnpmãã§ããã¤ã®æ¨é¦¬åãããjQueryã確èªãå°ãªãã¨ã1ã«æã«ããã£ã¦ãæ°åã®ããã±ã¼ã¸ã§âæ±æâããããã¼ã¸ã§ã³ãå ¬éããã¦ããã®ã確ããããããã«ãGitHubãCDNãµã¼ãã¹ãjsDelivrãã§ãæ¡æ£ãã¦ãããã¨ãåãã£ãã¨ãã¦ããã 対象ã®ããã±ã¼ã¸ã«ã¯ãæªæããã³ã¼ãã追å ãããjQueryã®ã³ãã¼ãå«ã¾ãã¦ãããæ±æããããã¼ã¸ã§ã³ã¯Webãµã¤ãã®ãã©ã¼ã ãã¼ã¿ãæ½åºããå¤é¨ã«éä¿¡ããã¨ããã Phylumã¯ããã«ã¦ã§ã¢ãä½åãããããã«å¿ è¦ãªæ¡ä»¶ã¯éããã¦ããããããã±ã¼ã¸ãåºãé å¸ããã¦ãããã¨ãããæ½å¨çãªå½±é¿ã¯åºããå¤ãã®éçºè ã«å½±é¿ãä¸
jQuery Attack Hits NPM and GitHub; Can Extract Web Form Data The trojanized jQuery attack has been spread on npm, GitHub and elsewhere since May. A trojanized version of jQuery has been spreading on the npm JavaScript package manager, GitHub and elsewhere, for use in a jQuery attack, security researchers have discovered. Phylum researchers said they have been monitoring the âpersistent supply chai
ã¦ã§ããã©ã¦ã¶ã®ãã¼ã¸ã§ã³éã®éããç¡å¹åããJavaScriptã©ã¤ãã©ãªãPolyfill.ioããã2024å¹´2æã®ããã¸ã§ã¯ããªã¼ãã¼å¤æ´å¾ããã«ã¦ã§ã¢ãæ··å ¥ããã¦ãµãã©ã¤ãã§ã¼ã³æ»æã«å©ç¨ããã10ä¸ä»¥ä¸ã®ãµã¤ãã«å½±é¿ãåºã¦ãã¾ãã Polyfill supply chain attack hits 100K+ sites https://sansec.io/research/polyfill-supply-chain-attack ãPolyfill.io(polyfill.js)ãã¯ã¢ã³ããªã¥ã¼ã»ãããæ°ãéçºããJavaScriptã©ã¤ãã©ãªã§ããã¦ã§ããã©ã¦ã¶ã®ãã¼ã¸ã§ã³éã§æ©è½ã®éããããã¨éçºæã«è¦å´ãã¾ãããPolyfill.ioãå©ç¨ããã°ãæ°ãããã¼ã¸ã§ã³ã«ãããªãæ©è½ãå¤ããã¼ã¸ã§ã³ã§å©ç¨ã§ããããã«ãªãããããã¼ã¸ã§ã³ã®éããæ°ã«ãããã¨ãªãéçºãé²ãããã¨
2024 å¹´ 6 æ 14 æ¥ãGoogle æ¸è°·ãªãã£ã¹ã«ã¦ Chrome Tech Talk Night #16 ã ãã¹ãã¼ ãéå¬ããã¾ããã CTTN #16 ã¯ãéçºè ã®ã¿ãªããããã¹ãã¼ã®åºæ¬ã«ã¤ãã¦å¦ã³ãããããçåã解決ã§ãããã¨ãç®æããã¤ãã³ãã§ãã FIDO Alliance ã¡ã³ãã¼ä¼æ¥ã§ã¢ã¯ãã£ãã«ä»æ§çå®ã«åå ãã¦ããã¨ãã¹ãã¼ãã®çæ§ããç»å£ããã¾ããã è³æã¯ãã¡ãã«å ¬éããã¦ãã¾ãï¼Chrome Tech Talk Night #16 ãã¹ã㼠以ä¸ã¯Claude Sonnet 3.5 ã«ããã¾ã¨ãã¨Notta.ai ã«ããã¾ã¨ãããã¨ã«è¥å¹²æãå ¥ãããã®ã§ãããªããç§ã¯ãã®åéã¯ç´ 人ãªã®ã§ãééããããã¨æãã®ã§ããã®å ´åã¯ãææããã ããã°å¹¸ãã§ãã Chromeããã¯ãã¼ã¯16 â ãã¹ãã¼ã«ã¤ã㦠#passkeys_jp 1. ã¤ã³ãããã¯ã·ã§
ç±³DigiCertï¼ãã¸ãµã¼ãï¼ã®æ¥æ¬æ³äººã§ãããã¸ãµã¼ãã»ã¸ã£ãã³ã¯2024å¹´5æ8æ¥ããã¸ãµã¼ããçºè¡ãããµã¼ãã¼è¨¼ææ¸ã®ä¸é¨ã«è¨è¼ãã©ã¼ãããã®èª¤ãããã£ãã¨çºè¡¨ãããããã«ä¼´ããå½è©²è¨¼ææ¸ã¯5æ12æ¥åå1æï¼æ¥æ¬æéï¼ã«å¼·å¶å¤±å¹ãããå社ã¯å¤±å¹å¯¾è±¡ã®è¨¼ææ¸ãå©ç¨ããä¼æ¥ã«å¯¾ãã¦ã証ææ¸ã®åçºè¡ã¨å ¥ãæ¿ããå¼ã³ããã¦ããã ãµã¼ãã¼è¨¼ææ¸ã¨ã¯ãWebãµã¤ãã«ã¢ã¯ã»ã¹ããHTTPSéä¿¡ã§éä¿¡å 容ã®æå·åãæ¹ããæ¤ç¥ãªã©ãè¡ããTLSãã¨ããä»çµã¿ã§å¿ è¦ãªè¨¼ææ¸ããã¸ãµã¼ããªã©ãèªè¨¼å±ãã¨å¼ã°ããæ©é¢ãçºè¡ããããµã¼ãã¼è¨¼ææ¸ã失å¹ããã¨ãæ£è¦ã®Webãµã¤ãã§ãã£ã¦ãWebãã©ã¦ã¶ã¼ãå®å ¨æ§ã確èªã§ããªããµã¤ãã¨ãã¦è¦åã表示ããã 大æåå°æåãåºå¥ãã¹ãã¨ãããå°æåã§èª¤è¨ 失å¹ã®æããããã®ã¯2023å¹´9æããåå¹´12æä¸æ¬ã¾ã§ã«çºè¡ããEVãµã¼ãã¼è¨¼ææ¸ã¨å¼ã°ãã証ææ¸ã®ä¸é¨ã
ããããã§ãã ç¾å¨éå¬ããã¦ããAWS re:Inforce 2024 ã®Keynote ã«ã¦ãAWS IAMã®rootã¦ã¼ã¶ã¼ããã³IAMã¦ã¼ã¶ã¼ã®MFA(å¤è¦ç´ èªè¨¼)ã¨ãã¦Passkeyã®ãµãã¼ããçºè¡¨ããã¾ããã AWS What's newããã°ãAWS Blogã®ä¸¡æ¹ã§çºè¡¨ããã¦ãã¾ãã æ¦è¦ æ¬ã¢ãããã¼ãã«ãã£ã¦ãAWSã®rootã¦ã¼ã¶ã¼ãIAMã¦ã¼ã¶ã¼ã®MFAããã¤ã¹ã¨ãã¦Passkeyãå©ç¨ã§ããããã«ãªãã¾ãï¼ AWSå´ã§çºè¡ããPasskeyãGoogleã¢ã«ã¦ã³ãã1passwordãªã©ã®ã¯ã©ã¦ããµã¼ãã¹ã«ç»é²ãããã¨ã§ãMFAèªè¨¼ã¨ãã¦Passkeyãå©ç¨ãã¦AWSã¢ã«ã¦ã³ãã«ãã°ã¤ã³ã§ããããã«ãªãã¾ãã AWS Blogã«ä»¥ä¸ã®ããã«è¨è¼ããããããååã®ãªãªã¼ã¹æã¯Passkey+ãã¹ã¯ã¼ãèªè¨¼ã®ã¿ã§ãã¹ã¯ã¼ãã®å©ç¨ã¯å¿ é ã§ããããã§ããä»å¾ã®ãªãªã¼ã¹ã§P
ã³ã³ãã³ããããã¯ãæå¹ã§ãããã¨ãæ¤ç¥ãã¾ããã ãã®ãµã¤ããå©ç¨ããã«ã¯ãã³ã³ãã³ããããã¯æ©è½ï¼åºåãããã¯æ©è½ãæã¤æ¡å¼µæ©è½çï¼ãç¡å¹ã«ãã¦ãã¼ã¸ãåèªã¿è¾¼ã¿ãã¦ãã ããã â
GitHubãèå¼±æ§ã®ããã³ã¼ããå®éã«ãããã°ãã¦å¦ã¹ããSecure Code Gameãã·ã¼ãºã³2ãã¹ã¿ã¼ã ãSecure Code Gameãã¯ãã²ã¼ã ã¨åä»ãããã¦ãã¾ãããå®éã®ã³ã¼ããæé60æéç¡æã§æä¾ãããGitHub Codespacesã®æ©è½ãé§ä½¿ãã¦ä¿®æ£ããã¦ããããã¹ããéãã¦å®æãããæé ã¨ãªã£ã¦ãããå®è·µã«è¿ãå 容ã¨ãªã£ã¦ãã¾ãã æ¨å¹´ï¼2023å¹´ï¼3æã«éå§ãããã·ã¼ãºã³1ã¯ãPythonã¨Cè¨èªã§ã®ã»ãã¥ã¢ãªã³ã¼ãã£ã³ã°ãå¦ã¹ãå 容ã§ãããä»åã®ã·ã¼ãºã³2ã§ã¯ãããã«å ãã¦JavaScriptãGoãããã¦GitHub Actionsã®Yamlãã¡ã¤ã«ãªã©ãå«ã¾ãã¦ããããããã®ã³ã¼ãã®ãã°ãä¿®æ£ãããã¨ã«ãªãã¾ãã Secure Code Gameã®å§ãæ¹ ãSecure Code Gameãã®å§ãæ¹ã¯æ¬¡ã®éãã§ãã ã¾ããSecure Code G
Gmailããã¡ã¼ã«éä¿¡è ã®ã¬ã¤ãã©ã¤ã³ããæ¹è¨ãããªããã¾ãã¡ã¼ã«ã¸ã®å¯¾çãå¼·åããæ¨ãçºè¡¨ãã¦ãã¾ããä»ã¾ã§ã¯ååããªããã¾ãã¡ã¼ã«å¯¾çã®æç¡ã«ããããããã¡ã¼ã«ã¯ãã¡ããã¯å±ãã¦ãã¾ããããããä»å¾ã¯ããªããã¾ãã¨ã¿ãªãããã¡ã¼ã«ã¯å±ããªããªãæ¹åã«åããã¤ã¤ããã¾ãã ãªããã¾ãã¡ã¼ã«ã¨ã¿ãªãããªãããã«ããããã«ãã¡ã¼ã«éä¿¡è ã«ã¯ããã¡ã¼ã«éä¿¡ãã¡ã¤ã³èªè¨¼ãã¸ã®å¯¾å¿ãæ±ãããã¾ããã¡ã¼ã«éä¿¡ãã¡ã¤ã³èªè¨¼ã®æè¡ã«ã¯ã主ã«ä»¥ä¸ã®3ã¤ãããã¾ãã SPF: Sender Policy Framework (RFC 7208) DKIM: DomainKeys Identified Mail (RFC 6376) DMARC: Domain-based Message Authentication, Reporting, and Conformance (RFC 7489) SPFã¯å¾æ¥
2023 å¹´ã¯æå¥ãªãããã¹ãã¼å å¹´ãã«ãªãã¾ãããé常ã«ããããã®ãµã¼ãã¹ããã¹ãã¼ã«å¯¾å¿ãã2024 å¹´ã¯ãããããã¹ãã¼æ®åã®å¹´ã«ãªãããã§ãã æ¬è¨äºã§ã¯ããã¹ãã¼ã®åºæ¬ãæ¯ãè¿ã£ãããã§ããã¹ãã¼ã§ã¿ãªãããåéãããããç¹ã«ã¤ãã¦è§£èª¬ãã¾ãã 2023 å¹´ã¯æ¬å½ã«ããããã®ã¦ã§ããµã¤ãããã¹ãã¼ã«å¯¾å¿ãã¾ãããä¾ãæãã¾ã: Adobe Amazon Apple eBay GitHub Google KDDI Mercari Mixi MoneyForward Nintendo NTT Docomo PayPal Shopify Toyota Uber Yahoo! JAPAN ãã¡ãããã®ãªã¹ãã§ãã¹ã¦ã§ã¯ãªãã§ããããããã ãã§ããä¸ç人å£ã®ããªããã«ãã¼ã§ããã¯ãã§ãã¾ãã«å¤§èºé²ã¨è¨ãã¾ããããã¾ã ãã¹ãã¼ãä½é¨ãã¦ããªãã¨ããæ¹ããããããã²ãã®æ©ä¼ã«ã試ããã ããã
ã¯ããã« å æ¥ãµã¨ Auth0 ã®ããã·ã¥ãã¼ããçºãã¦ããã¨ãèå³æ·±ãé ç®ã表示ããã¦ãã¾ããã Passkey ããã!!! ãªã®ã§ãä»å㯠Auth0 ã«æè¼ããããã¹ã¯ã¼ãã¬ã¹èªè¨¼æ¹å¼ã§ãã Passkey ã®èª¬æããã¦ããã¾ãã ãªããAuth0 ã®è¨å®æ¹æ³ã«ã¤ãã¦ã¯Auth0 ãããªãªã¼ã¹ãããè¨äºãåèã«ãã¦ãè¨è¼ãã¦ãã¾ãã ãã¹ã¯ã¼ãèªè¨¼ã®èª²é¡ Passkey ã®èª¬æãããã¾ãã«ããã¹ã¯ã¼ãèªè¨¼ã®èª²é¡ã«ã¤ãã¦è¦ã¦ããã¾ãã èªè¨¼æ¹æ³ã¨ãã¦å½ç¶ã¨ããã¦ãããã¹ã¯ã¼ãèªè¨¼ã§ããã以ä¸ã® 3 ã¤ã®èª²é¡ãæã£ã¦ãã¾ãã â ãã¹ã¯ã¼ãã®ä½¿ãåã â¡ æ¨æ¸¬ããããããã¹ã¯ã¼ãã®ä½¿ç¨ ⢠ãã£ãã·ã³ã°ã¢ããªã¸ã®ãã¹ã¯ã¼ãå ¥å ããããè¦ã¦ããã¾ãããã â ãã¹ã¯ã¼ãã®ä½¿ãåã ãã°ã¤ã³ãå¿ è¦ãªã¢ããªã«ã¯ããããç°ãªããã¹ã¯ã¼ãã使ç¨ããã¨ããã®ã¯çãããåç¥ã ã¨ã¯æãã¾ãã ã¨ã¯ã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}