åå®ç¾©ã§ããªãä¸çã«ãªãã¤ã¤ãããããã®æ°ç§©åº
å人ã§EV SSL証ææ¸ã欲ãã話 - Speaker Deckãèªãã§é©ãããã ãã©ããã¤ã®éã«ãFirefoxã«ã¯EVSSL証ææ¸ã®ã«ã¼ãèªè¨¼å±ããã¼ãã³ã¼ãã£ã³ã°ããã¦ããããæ¸ãæããã«ã¯ãã©ã¦ã¶ããã«ããç´ãå¿ è¦ãããããããï¼ã¨ããããªãã«ããã¦ã追å ãã証ææ¸ã§ã¢ãã¬ã¹ãã¼ãç·è²ã«ãªããªãã£ãã¿ãããä½ã足ããªãã®ããªï¼ï¼ã«ã¼ã証ææ¸ãã®ãã®ã¯å¾ãã足ããã®ã ãæ¢ãã¦ãã¼ãã³ã¼ãããçç±ã¯æ³åã§ãããã«ã¼ã証ææ¸ãªãã¦å¾ããä¾µå ¥è ãªããã«ã¦ã§ã¢ãç°¡åã«è¶³ããã¨ãã§ããããç¾ã«ãããã£ãæ»æã¯ããã¾ã§è¡ããã¦ããããã ã
ã¤ãã§ã«Firefoxãè¿ã DHCPã§éã£ã¦ããDNSãä¿¡ç¨ããã®ãæ¢ãã¦ãDNS over HTTPSã§Cloudflareã«åãåãããã¨ããããããã¾ãDNSå±¥æ´ãç£è¦ããå½ã ã¨ããæ¥æ¬ãå«ãã¦Webæ¤é²ã®ããã«DNSãããã£ã¦ãå½ããã£ã¦ããããã£ãå½±é¿ãæé¤ãããã¨ããã®ã ãããã¾ã éçºç¨ã®Firefoxã§æ§è½ãªã©ã®çµ±è¨ãåã£ã¦ãã段éã ããé ãããå®è£ ããããã ã  ungleich Blog - Mozilla's new DNS resolution is dangerous ï¼è¿½è¨ï¼ãªã³ã¯å ã¯TRRãããã©ã«ãã§æå¹ã¨ããããã¨ãåæã«æ¸ããã¦ããããç¾æç¹ã§Mozilla財å£ãããã®ãããªã¢ãã¦ã³ã¹ã¯ãªãï¼
å ã ã®ã¤ã³ã¿ã¼ãããã¯ãªã¼ãã³ã«ã¤ãããã¦ãã¦ãä½ã§ããå¾ããåæã«è¨å®ãç½®ãæãããã¨ãã§ãããIPã¢ãã¬ã¹ã§ãããDNSã§ãããThe Internetã«ç¹ãããã«ã¯ã«ã¼ã«ãå®ãå¿ è¦ãããããã©ããéããä¸çã§ããã°å¥½ãåæã«ããããã¨ãã§ãããSSLãã§ãã¦ããããã®ã«ã¼ã«ãè¸è¥²ãã¦ããã©ã¦ã¶ã«æ¨æºãã³ãã«ããã¦ããã«ã¼ãèªè¨¼å±ã¯æ±ºã¾ã£ã¦ããããã©ããå©ç¨è ã®æä½ã§å¾ããæãå·®ãã§ããããã«ãªã£ã¦ããã
ããããªãããããã¯é åçãªæ»æçé¢ã§ããã£ã¦ããã«ã¦ã§ã¢ãhostsãããã£ã¦æ¥ç¶å ãæ²ããã¨ããMITMæ»æã®ããã«ä½è¨ãªã«ã¼ãèªè¨¼å±ãã¤ã³ã¹ãã¼ã«ããã¨ãã£ãæ»æãæãç«ã¤æ¸©åºã§ããã£ããä¿¡é ¼ã§ãã証ææ¸ããã¼ãã³ã¼ããã¦ãDHCPã§ã©ããªã¢ãã¬ã¹ãéã£ã¦ãã¦ããä¸çä¸ã§æ±ºã¾ã£ããªã¾ã«ãã«å¯¾ãã¦åãåãããè¡ãã°ããããã£ãæ»æãåé¿ãããã¨ãã§ããã
ç¾å®åé¡ã¨ãã¦åãå©ç¨è ã®å¤§åã¯ä¿¡é ¼ã§ããã«ã¼ãèªè¨¼å±ãèªåã§é¸ã¶è½åããä¿¡é ¼ã§ããDNSãµã¼ãã¼ãèªåã§é¸ã¶è½åãæã¡åããã¦ãªããè¨å®ãå¤ãã¦ã¬ã¹ãã³ã¹ã®éãé ãã«ä¸åä¸æããããããããã³ã°ãè¿åããããã«æµ·å¤ã®DNSãè¿åããããããé¢ã®å±±ã ãããéè¦ãªãã©ã¡ã¼ã¿ã¼ãæ¸æå¯è½ã¨ãããã¨ã®ãªã¹ã¯ã¨ãããã£ãããæ¯è¼è¡¡éãã¦ãä»ã¨ã¯å¥ã®ãã©ã³ã¹ã«å¾ãã¤ã¤ããããã ã
é ããéããGoogleãä¼¼ããããªå¤æã§ãChromeã®åãåããå DNSãµã¼ãã¼ãGoogle決ãæã¡ã¨ããããç¥ããªãããã®æ¹ãéããã¦ã¼ã¶ã¼ã®ãã©ã¤ãã·ã¼ãä¿è·ããããã¨èãã¦ããããããªããMicrosoftã¯ããã¡ãã£ã¨è¤éã§ãæ³äººé¡§å®¢ãæã£ã¦ããã¨Active Directoryã®åå空éã¨ã®é¢ä¿ãã©ãããããèããå¿ è¦ããããGoogleã§ããMicrosoftã§ããMozillaã¨æ¯ã¹ãã°åå½å½å±ã¨ã®çªå£ãæã£ã¦ãã¦ãããã¡ãã£ã¨æè»ã«æãåããä»ãããã¨ããã ãããAppleãã©ãèãããã¯äºæ¸¬ãé£ããã
Mozillaã¯æ±ºãæã¡ã§åç §ããDNS over HTTPSãµã¼ãã¼ã®ãã¨ãTrusted Recursive Resolverã¨å¼ãã§ãã¾ãã¯Cloudflareã«åããããã§ãããä½ãTrustedãã¨ããã¨Mozillaãä¿¡ãã¦ãã¨ãããã¨ã ãããDHCPã§æ¸¡ãããIPã¢ãã¬ã¹ã«èãã«è¡ãããã¯ãHTTPSã ãããµã¼ãã¼ã®çæ£æ§ã確èªãããã¨ãç°¡åã ãã©ããã®å½ã®ISPã®ããã«å©ç¨è ãç£è¦ããããé½åã®æªããµã¤ãã«ã¤ãã¦å¿çãè¿ããªãã¨ãã£ãæåãããªããã¨ãæå¾ ã§ãããããã¾ã§ã®å®ç¸¾ãããã£ã¦ãåå½ã®ISPããã¯ç©ºæ°ãèªã¾ããå½å®¶æ¨©åããã®å¹²æ¸ãåããã«ãä¸ç«çãªãµã¼ãã¹ãæä¾ããã®ã ãããã
ãããCloudflareã§ããGoogleã§ããç±³å½ã®ä¼æ¥ã§ããã¾ãã¾ä»ã®ã¨ããç±³å½ä»¥å¤ã®ISPã¨æ¯ã¹ã¦èªç±ã謳æãã¦ããããã«è¦ããããã©ãããã¤ä½æã©ããªããªã·ã¼å¤æ´ãèµ·ãããåãã£ããã®ã§ã¯ãªããç½®ãæãå¯è½ãªç¶æ ã§ISPã®DNSãµã¼ãã¼ãåç §ãããã®ã¨ããã©ã¦ã¶ã«ãã¼ãã³ã¼ãããã¦ç¹å®ã®DoHãµã¼ãã¼ã«åç §ãããã®ã¨ã§ã¯ãã ãã¶æå³åããç°ãªããããæ¥çªç¶ãæ·±å»ãªãã«ã¦ã§ã¢ã®C&Cãµã¼ãã¼ãªãããæ¯æ´çµç¹ã¨åæãããã誰ãã®DNSåãå¼ããªããªã£ã¦ããããç¥ããªã訳ã ããããå©ç¨è ãæ°ä»ããªãããã¡ã§ã
ãã¤ã¦ã¤ã³ã¿ã¼ãããã¯ã¬ã¤ã¤ã¼åããããªã¼ãã³ãªãããã¯ã¼ã¯ã§ãOSãæ¯é ããããããã©ã¦ã¶ãæ¯é ããããããããå ¨ä½ãæä¸ã«åãããã¨ã¯ã§ãããä¸å½ãéç¾ãç¯ãããã米海è»ã®é ã£ãTorã§DarkWebã®ä¸çãåºãã£ãããã¦ãã訳ã ãã¨ãããæ°ä»ãããWebãPKIãDNSã¨ãã£ãã¬ã¤ã¤ã¼ã飲ã¿è¾¼ãã§ãå½ããã£ãªã¢ã«å·¦å³ãããªãä¸çãã¤ãããã¨ãã¦ããããããOSã¨ã¯ã©ã¦ããæ¡ã£ã¦ããGoogleãMicrosoftã§ã¯ãªããã©ã¦ã¶ããæã£ã¦ãªãFirefoxãçå ãã¦é²ãã¦ããã®ã¯ã©ããããã¨ã ãããï¼ã¨èãã¦ã¿ãã¨é¢ç½ãã
ããä»®ã«ã¬ã¤ã¤ã¼æ¯ã«ã¢ã¸ã¥ã¼ã«åããã¦åãã¬ã¼ã¤ã¼ãå½ãç¥èã¨æãåããã¨ã®ã§ãããªã¼ãã³ãªã¤ã³ã¿ã¼ãããããããã©ã¦ã¶ãèªè¨¼å±ãDNSãµã¼ãã¼ãªã©æ±ºãæã¡ã§ã³ã³ããã¼ã«ã§ããªãå ç¢ãªWebã¸ã¨ä¸ã®ä¸ã移ã£ãå ´åãåå½æ¿åºã¯ã©ãåããåãã®ã ãããï¼Bugzillaã«è¦æãåºãã¦ããã®çãã«ä¸åä¸æããã®ã ãããï¼ããã¾ã§ãã£ã¦ããããããã³ã°ã¯ã©ãè¦ç´ãã®ã ãããï¼DNSããããã³ã°ã¯æãç«ããªããªã£ã¦ãã±ãããè½ã¨ããªããé®æã§ããªããªããããã¨ã¦Torããã軽ããªã¼ãã¼ã¬ã¤ã»ãããã¯ã¼ã¯ãããã£ã¨å¹ççãã¤ã¢ã¯ã»ã¹ç¶²ã®å¹²æ¸ãåãã«ããCDNã¨ã®é£æºãããã³ã«ãåºã¦ããã°è¿åã§ãã¦ãã¾ãããããã¯å¼·æ¨©çã§å³æ ¼ãªè¨è«å¼¾å§ãè¡ãå½ã ã®å©ç¨è ã«å¯¾ãã¦ãæ¿åºã®é è¶ãã«èªç±ãªæ å ±ã®æµéãå®ç¾ããã®ã ãããã
ããããè»æ¡ç«¶äºã®å ã«ä½ãããã®ãèªã¿ã¥ããã¯ããããã©ããã¬ã¤ã¤ã¼åãããä¸çã®ä¸ã§ã足åããæ ããã¬ã¼ã¤ã¼ã«å¯¾ããçµ±å¶ãéãã¦ãä¸ä½å±¤ãã³ã³ããã¼ã«ãããã¨ã¯å¾ã ã«é£ãããªãã®ã§ã¯ãªãã ããããã³ã³ãã³ãã®ä¸èº«ãã³ã³ããã¼ã«ããã®ã§ããã°ãå ã ã¨ã¢ããªã±ã¼ã·ã§ã³å±¤ã§çµ±å¶ããããå¿ è¦ãçããããã«ã¦ã§ã¢ç£è¦ã«ãã¦ããã³ã³ãã³ãã®é®æããªã·ã¼ã«ãã¦ãã網ã§ã¯ãªã端æ«ã§å¶å¾¡ããå¿ è¦ãããã端æ«ã§ã以åã®ãã£ã«ã¿ãªã³ã°ã½ããã®ããã«OSã¨ãã©ã¦ã¶ã®éã«å ¥ãè¾¼ããã¨ã¯é£ãããªã£ã¦ããã©ã¦ã¶æ¡å¼µã¨ãã¦æ±ºããããæé ãä»ãã¦ãããã³ã³ãã³ãã®ä¸èº«ã«å¯¾ãã¦å¹²æ¸ã§ããªãããã«ãªãã¤ã¤ããã
ã»ãã¥ãªãã£ããã©ã¤ãã·ã¼ã®å¼·åã¨ããåç®ã«ã¯æãé£ããããã©ãçµæã¨ãã¦èµ·ãã£ã¦ããã®ã¯ããããã寡å åãé²ãã§ãããã©ã¦ã¶ã¨CDNã¨ãçµè¨ããISPãæ¿åºã¨ãã£ããä¸éè ãã®é è¶ãã«ããªã·ã¼ãèªç±ã«æ±ºããããã¢ã¼ããã¯ãã£ã®æ§ç¯ã ãããããGAFAãããå ã«MozillaãCloudflareã«ãã£ã¦é½ããã¤ã¤ãããã¨ã®æå³ãéãåãæ¢ããå¿ è¦ããããä¾ãã°GPKIã«ã¼ãèªè¨¼å±ã®ä»¶ã²ã¨ã¤ã¨ã£ã¦ããä»ã®ã¨ããMozillaããã¯GoogleãMicrosoftãAppleã®æ¹ãæè»ã§è©±ãåããæãç«ã£ã¦ãããÂ
870185 - Add Renewed Japanese Government Application CA Root certificate
ç¾å®çãªæ³å·è¡ãåã°ãã³ã¼ãã«ãã£ã¦è¦å®ãããä¸çã§ã¯ãã©ãã³ã³ã»ã³ãµã¹ï¼ã©ã³ãã³ã°ã³ã¼ãã§åãã°ãã¼ãã«ã»ã³ãã¥ããã£ã¨ã®å¯¾è©±ã¹ãã«ã身ã«ã¤ããªãéããé è¶ãã«ã¹ã«ã¼ããã¦ãã¾ããä¸æ¹ã§æ³çãªå½±é¿åãã©ãè¡ä½¿ããããå½é競äºã¨ãªã£ã¦ããããä¾ãã°GDPRãwhoisã«ä¸ããå½±é¿ãªããããããããã£ãæèã®ä¸ã§è¦ã¦ããå¿ è¦ãããããã ã Â
ICANN or ICAN'T? WHOIS search results in the era of GDPR - Lexology
ãããã«ãã¦ãç±³ä¸æ¬§ãããããå¾æãªçµ±å¶ãå¼·ãã¦è»æ¡ç«¶äºãã¨ã¹ã«ã¬ã¼ãããéããæ¥æ¬ã¯æ¯ãåãããå±éãç¶ãã ããããã®ä¸ã§ã«ã¼ã«ãã³ã¼ãã«å¯¾ããå½±é¿åã確ä¿ããè¦æ ¼ã®ä¸ã«æ¼ãè¾¼ããªããå®è³ªçã«æ ä¿ããããã¨ãå®ç¾ããããã®æ¹çã磨ãã¦ããå¿ è¦ãããããã®ããã®è²»ç¨ãå´åã誰ãè² æ ããã®ã ãããã