Disclaimer æ¬ã¨ã³ããªã¼ã¯ããã®å¤ blackhat usa 2016ã§è¡ãããäºå®ã®è¬æ¼ãNONCE-DISRESPECTING ADVERSARIES: PRACTICAL FORGERY ATTACKS ON GCM IN TLSã ã®ãã¿ãã¬ãå«ãã§ãã¾ããç¾å°ã§ç´æ¥èãæ¹ã¯èªã¾ãªãããæ°ãã¤ãã¦ä¸ããã 0. çãã¾ã¨ã ä»åã¯çãã«ã¨æã£ãã®ã§ããããã£ã±ããããªãã®åéã§ããããªã®ã§çãã¾ã¨ããæ¸ãã¦ããã¾ãã 4åä¸ä»¥ä¸ã®ãµã¤ã対ãã¦AES-GCM使ã£ãTLSéä¿¡ã®åæãã¯ãã«(IV)ãã¼ã¿ã®ãµã¼ãã¤ãè¡ããã7ä¸ç¨ã®ãµã¤ãã§IVã®å¤ãåå©ç¨ãããå¯è½æ§ããããã¨ããããã¾ãããIVãåå©ç¨ãããå ´åãAES-GCMã®å®å ¨æ§ã¯è´å½çãªå½±é¿ãåãã¾ããIVã®åå©ç¨ãå¤æããå¹¾ã¤ãå®è£ ããæ¢ã«èå¼±æ§ã®ã¢ãã¦ã³ã¹ãåºã¦ãã¾ãã IVãåå©ç¨ãããå ´åãç¾å®çã«HTTPS
{{#tags}}- {{label}}
{{/tags}}