æè¿ã®ãããããã«ã¤ãã¦
- ã½ã¼ã¹ãããã«ç¢ºèªããã«åãæ¢ããæ¡æ£ãã
- èªåã®çºè¨ã®è²¬ä»»ãå¸èã«ãªãããã«è¨ç®ããããã³ãã¬ã¼ã
- 詳細ã¯ãªã³ã¯å ã§
- çå½ä¸æã§ããåãæ¢ããæ¡æ£
- èªå·±è²¬ä»»ã§
- å æ å ±ãè¨æ£ããã¦ããæ¡æ£ãã誤æ å ±ã¯æ¶ããªã
ãããªãã®Gmailããã¹ã¦çã¾ãããåé¡
- http://b.hatena.ne.jp/entry/jp.techcrunch.com/archives/20101120whoa-google-thats-a-pretty-big-security-hole/
- http://topsy.com/jp.techcrunch.com/archives/20101120whoa-google-thats-a-pretty-big-security-hole/
- http://disqus.com/guest/84d6bff45c2112e083c425e39f954f5e/
- http://twitter.com/yomoyomo/status/6692549821464576
ãã¡ã¼ã«ã¢ãã¬ã¹ãããã¡ã¼ã«ãã¨èª¤è§£ããã®ã¯ã¨ãããããã¹ã¦ãã¯ã©ã£ããåºã¦ãããã ããã¹ã¦ãã¯ãé¢ç½ãããã大ããã«ãããã¦ããã¨ãã¦ããããããããã¨ã«ãªãããããªãã®ãï¼ãã®æ å ±ãæ¡æ£ãããã«ã©ãã¯ãï¼ç·¨éé¨ããã®ä¿®æ£ã¨ãè©«ã³ï¼è¨äºã®è¦åºãã«ãGmailããã¹ã¦çã¾ãããã¨ããã¾ãããæ£ããã¯Googleã«ãã°ã¤ã³ãã¦ããï¼Gmailã®ï¼ã¡ã¼ã«ã¢ãã¬ã¹ãçã¾ãããæ£ãã表ç¾ã§ãããä¿®æ£ãã¦ãè©«ã³ãããã¾ããï¼2010å¹´11æ27æ¥ï¼ãã¨ããæè¨ãèªã¿ã¾ãããï¼
mixiã¢ããªã§å人æ å ±æ¼æ´©ããé¨å
- 12/06æ¥ç¾å¨ twitterã§ã®è¨å ç´6500件 http://topsy.com/mixi.jp/manage_acl.pl
- 12/06æ¥ç¾å¨ mixiå 1276件 http://mixi.jp/search_diary.pl?keyword=http%3A%2F%2Fmixi.jp%2Fmanage_acl.pl&x=0&y=0&submit=search&type=dia
ã¡ã¼ã«ã¢ãã¬ã¹ããmixiã¢ã«ã¦ã³ããæ¤ç´¢ã§ããæ©è½ãåé¡ã«ãªã£ãã®ã¯è¨æ¶ã«æ°ãããã
- ã¡ã¼ã«ã¢ãã¬ã¹ãç¥ã£ã¦ãããããã®æã¡ä¸»ãç¥ããªã
- ã¡ã¼ã«ã¢ãã¬ã¹ã¨ããã®æã¡ä¸»ãç¥ã£ã¦ããããmixiã¢ã«ã¦ã³ããç¥ããªã
ã¨ããã±ã¼ã¹ãã¤ã¾ãæååã¯ç¥ã£ã¦ãããé¢ä¿æ§ãç¥ããªããã¨ããã±ã¼ã¹ã§ãéå ¬éã®æ å ±ããããã©ã«ãã§å ¬éã«ãªã£ããã ããåé¡ãèµ·ããã
ããã«å¯¾ãã¦ãã http://mixi.jp/manage_acl.pl 㯠å ã ã(mixiå ã§å ¨ä½)å ¬éããã¦ããæ å ±ããAPIçµç±ã§åå¾ã§ããããã«ããããã¨ããè¨å®ã ããã®ã¦ã¼ã¶ã¼ã®ãã¤ãã¯ä¸è¦§ãããã¤ãã¯ä¸è¦§ãã辿ã£ã¦åå¾ã§ããå ¨ä½å ¬éããã¦ãããããã£ã¼ã«ããmixiã¢ã«ã¦ã³ããæã£ã¦ããã°èª°ã§ãã¢ã¯ã»ã¹ã§ããæ å ±ã ã(å®éã«å¤§éã«åå¾ãããã¨ããã足ãã¨ä»ãã¾ãã£ã¦ã¢ã¯ã»ã¹å¶éãåããã ããã)
ä»ã®ãµã¼ãã¹ã¨æ¯è¼ãã¦ã¿ãã
- twitterã¯protected(許å¯ãã人ã«ã®ã¿å ¬é)ã«ãã¦ãã¦ã(ããªãã®ãã©ãã¯ã¼ã許å¯ããã°)OAuthã§ç¬¬ä¸è ããèªã¾ãããããããæå¦ãããã¨ã¯åºæ¥ãªãã
- twitterã®DM(ç¹å®ç¸æã«ã®ã¿å±ãã¡ãã»ã¼ã¸)ã§ãã£ã¦ã(éä¿¡å ã®ç¸æã許å¯ããã°)OAuthã§ç¬¬ä¸è ããèªã¾ãããããããæå¦ãããã¨ã¯åºæ¥ãªãã
- ããªããéã£ãã¡ã¼ã«ã第ä¸è ã«è¦ãããããªãã¨æã£ã¦ãã¦ãGmailã¯(ããªãã®å人ã許å¯ããã°)OAuthã§ã¢ã¯ã»ã¹ãããã¨ãåºæ¥ã http://code.google.com/intl/ja/apis/gmail/oauth/
- ããªããã¡ã¼ã«ã¢ãã¬ã¹ã第ä¸è ã«ç¥ãããããªãã¨æã£ã¦ãã¦ã(ããªãã®å人ã許å¯ããã°)Google Contacts APIãéãã¦åå¾ãããã¨ãåºæ¥ã http://code.google.com/intl/ja/apis/contacts/
mixiã¯ãããªãã®å人ã許å¯ãã¦ããå ¨ä½å ¬éã§ã¯ãªãæ å ±ã«ã¯ã¢ã¯ã»ã¹åºæ¥ãªããã¨ããä¸ççã«æåãã¦ããã°ãã¼ãã«ãªãµã¼ãã¹ã¨æ¯è¼ãã¦è¦ãã¨æ¥µãã¦æ¶æ¥µçã§éå®çãªã¢ã¯ã»ã¹ãã許å¯ãã¦ããªã(åè: http://developer.mixi.co.jp/appli/spec/pc/permission_model )
ãã®ããã©ã«ãè¨å®ãæ¬æ°ã§ä¸é©åã ã¨æã£ã¦ãã人ã¯ãä»ããTwitterã¨ãGoogleã¨ã使ãã®ãããæ¹ãããããgmail使ã£ã¦ã人ã«ã¡ã¼ã«éãã®ãæ¢ããæ¹ãããããã¢ãã¬ã¹å¸³ã«å ¥ããªãããã«é¢ããã®ãé¿ããã»ãããããTwitterä¸ã§è¨åãã¦ãã人éã¯æ»ç¨½ã ã
ãã®è¨å®ã¯å±éºã ããä»ããå¤ãã¾ãããããªã©ã¨è¨ããã¦ãã¤ãã¤å¤ãã人éã¯éã®è¡åã容æã«èµ·ããã®ã§ãä¾ãã°
- å®å ¨ã®ããã¨è¨ããã¦å½ã»ãã¥ãªãã£ã½ãããã¤ã³ã¹ãã¼ã«ããã
- ãã¹ã¯ã¼ãã®å¤æ´ããã»ããè¯ãã¨ä¿ããã¦å½ãµã¤ãã«ãã¹ã¯ã¼ããå ¥åããã
- PCãé«éåããã³ãã³ãã ã¨è¨ããã¦HDDããã©ã¼ãããããã³ãã³ããå ¥åããã
- ä½ã«è¯ãã¨è¨ã£ã¦æ°´éãã´ã¯ã´ã¯é£²ãã ãããç¯ä»ã§äºæ¸æ°´ã«æ°´éãå ¥ããããã
ã¤ã¾ã人éã大éã«æ»ã¬ãæ´åãèµ·ããæ ¸æ¦äºã§äººé¡ãæ» ã³ãã
ããããããé²ãããã«ä»ãæã ãåºæ¥ããã¨
ãã®ãããªäººéãå¿å¹´ä¼ã«èªãã®ãæ¢ããï¼