Security
OpenID Provider ã®ã»ãã¥ãªãã£å¯¾ç (2) - return_to 㨠realm ã®ãã§ãã¯ãæ ããªï¼
OpenID Provider ã®ã»ãã¥ãªãã£å¯¾ç (1) - ã¾ã㯠SSL ãå°å ¥ï¼è©±ã¯ããããã - Yet Another Hackadelicã®ç¶ç·¨ã§ãã ã¯ããã« RP ãèªè¨¼ã¢ãµã¼ã·ã§ã³ãªã¯ã¨ã¹ãã§ãã checkid_setup/checkid_immediate ãè¡ãéã«ã¯é常㯠return_to 㨠realm ãæå®ãã¾â¦
ãã£ã¨ä¸æºåçµãã£ãã®ã§æ¸ãã¦ã¿ããOpenID ã§ã®ãããã³ã«ã¡ãã»ã¼ã¸ã§ãèªè¨¼ã¢ãµã¼ã·ã§ã³è¦æ±*1åã³å¿ç*2ã§ã®ã¡ãã»ã¼ã¸ã¯é常ãRP-OP é㧠associate æã«äº¤æãã MAC ãã¼ãæã£ã¦ç½²åãè¡ãçºãæå¾ ããç¸æã¨éä¿¡ãã¦ããéãã¯æ¹ããã¯èµ·ããã«ãâ¦
çµè«ããè¨ãã¨ããªã¬ãªã¬è¨¼ææ¸ã使ã£ãå ´åã« LWP::UserAgent + Crypt::SSLeay ã¯æ示çãªã¨ã©ã¼ãåãåºãã®ã§ã¯ãªããã¬ã¹ãã³ã¹ããã Client-SSL-Warning ãä»ä¸ãã¦ã¢ã¯ã»ã¹çµæãè¿ãã¾ãã*1 ç°¡åã«ãã¹ãããå ´å $ lwp-request -e -d https://badâ¦
d:id:ZIGOROu:20080805:1217923189 ã®ç¶ããä¾ãã°å ã®ã¨ã³ããªã§æ¸ããã¹ã¯ãªããã§ãhttps://wassr.jp/ ã«ã¢ã¯ã»ã¹ããã¨è¦äºã«ãªã¬ãªã¬å¤å®ããã¡ãã訳ã§ãããããã¯åã«ä¸éCA証ææ¸ãæå ã«ã¤ã³ã¹ãã¼ã«ããã¦ããªãããèµ·ããã wassr ã®è¨¼ææ¸ã調â¦
å¾ã«ãå ã«ãã»ãã¥ãªãã£ãã¡ã¤ã³ãã¼ãã®éãã§ã話ããäºãç¡ããã㪠id:ZIGOROu ã§ããä»ã®ã¹ãã¼ã«ãå ¨å¡ã¹ã¼ãã§æ¥ãä¸ãä¸äººç§æã§æ¥ãã¨è¨ãç·å¼µæã®ç¡ã*1ã§ããããå®éã¯æ¿ããç·å¼µãã¦ã¾ããï½ 7/5 Developers DAY â äºä»¶ã¯ç¾å ´ã§èµ·ãã£ã¦ããâ¦â¦
ãããªæ¥ãæ¥ãã¨ã¯ã¾ã£ãã夢ã«ãæããªãã£ã訳ã§ããã7/5 Developers DAY â äºä»¶ã¯ç¾å ´ã§èµ·ãã£ã¦ããâ¦â¦ã»ãã¥ãªãã£ã©ã¤ããµã¤ã¯ã«ã¨ãã«ãã©ã¯ãã£ã¹ | Web Application Security Forum - WASForum ã«ã¦ OpenID ã®ã»ãã¥ãªãã£ã«ã¤ãã¦è¬æ¼ãã¾ãã æâ¦
Relying Party to Identity Provider redirect æªæãã RP ã discovery ãå½ã£ã¦ãã¦ã¼ã¶ã¼ã®å ¥åãã User-supplied Identifier ããå¤å¥ãã OP EndPoint URL ã«ã¯ãªãã¤ã¬ã¯ãããã«ãã£ãããªãã£ãã·ã³ã°ãµã¤ãã«è¡ãå¯è½æ§ãããããã£ã¦è©±ã 対ç â¦
Negotiating crypto keys associate ã®æã« DH éµäº¤æãè¡ãéã«æ½ãåé¡ç¹ã§ãã ä½ãåé¡ãªã®ã In the original description, the Diffie-Hellman exchange by itself does not provide authentication of the communicating parties and is thus vulneraâ¦
BlackHat USA (2007) 㧠Eugene Tsyrklevich ãã㨠Vlad Tsyrklevich ããããã¬ã¼ã³ããè³æããªã³ã©ã¤ã³ã§è¦ãã¾ãã OpenID: Single Sign-On for the Internet (PDF) ã§æ¢ã«æ¥æ¬èªã§ãç´¹ä»è¨äºãããã¾ãã èªåã§ãèªãã§ã¿ãã®ã§ãéä¸è§£èª¬ãã¦ã¿ããâ¦
ãããã man-in-the-middle attack ã£ã¦å¥´ã§ãã精巧ã«ãã¢ãä½ã£ã人ããã¾ããã ãã¢ãµã¤ã ç´¹ä»è¨äº äºãè¨ã£ã¦ããã¾ããããã¢ãµã¤ãã¯ãã£ãã·ã³ã°ã®ãã¢ãªã®ã§ç´ 人ã¯æ£ãããã¹ã¯ã¼ãã¯æ±ºãã¦ãããªãäºããããã¯ä½¿ããªãäºã*1試ãããã©ãidthefâ¦
第3åããã ãã¶æéãæãã£ã¦ãã¾ãã¾ããããOpenIDã®@ITã§ã®é£è¼ã®ç¬¬4åç®ãå ¬éããã¾ããã é å¼µã£ã¦æ¸ããã§ãããæ¯éè¦ã¦ä¸ããï¼OpenIDãã¨ãã¾ãã»ãã¥ãªãã£ä¸ã®è å¨ã¨ãã®å¯¾ç (1/3)ï¼OpenIDã®ä»æ§ã¨æè¡ï¼4ï¼ - ï¼ ITãã®è¨äºã§ããã大ãããâ¦
ãã£ã±ããµã¼ãã¹å´ã§å ç¢ãªãã¹ã¯ã¼ããã¦ã¼ã¶ã¼ã«å¼·å¶ããä»çµã¿ãç¡ãã¨åé¡ããããµã¼ãã¹ã¨è¨ãã®ã¯ããããããã£ã¦äºã§ãPerlã§åºæ¥ãéãç°¡åã«ããããä»çµã¿ãä½ããªãããªã¨ãå¹¾ã¤ãããã¯ã¢ãããã¦ã¿ã¾ããã Data::Passwordã¢ã¸ã¥ã¼ã«ã使ã â¦
Replay Attackã¨è¨ãã®ã¯ãå¹³ããè¨ãã°ãã¹ã¯ã¼ããæå·éµããããã¯èªè¨¼æ¸ã¿ã®ã»ãã·ã§ã³ãã¼ã¿çãåå©ç¨ãã¦ãã®ã¦ã¼ã¶ã¼ã«ãªããã¾ãæ»æã®äºãè¨ãã¾ãããã¹ã¯ã¼ããæ¼ããã£ã¦ã®ã¯è«å¤ã ã¨ãã¦ãOpenIDã®å ´åã¯id_resã¢ã¼ãã®ãªãã¤ã¬ã¯ãURLãçè´â¦
wiki.openid.netã®OpenID Wiki / OpenID_Phishing_Brainstormããã ãã£ãã·ã³ã°ã®æµã ã¦ã¼ã¶ã¼ã¯æªæã®ããRP(Consumer)ãµã¤ãã«è¡ãã¨OpenIDã£ã½ããã°ã¤ã³ãã©ã¼ã ããã ã¦ã¼ã¶ã¼ã¯ãã®ãã°ã¤ã³ãã©ã¼ã ã«èªåã®Identifier URLãå ¥å æªæã®ããRPã¯ã¦â¦
èªåç¨ã®ã¡ã¢ã§ãã ã¢ã«ã¦ã³ãã®èªååé OpenIDã®å ´åã¯IdentifierãURLãªã®ã§ãã¦ã¼ã¶ã¼åã®åéã¯ä¾ãã°Googleæ¤ç´¢ãªã©ã§è¡ããã http://www.google.co.jp/search?q=allintitle%3AIdentity+Page+for ä¾ãã°ããããæãã§ãããä»ã®OpenID Providerã®ã¦â¦
ã¯ããã« åèªèº«ãã»ãã¥ãªãã£ã«å¯¾ããæå·åã®ç¥èã足ããªãéããã®ã§ãããã§æãåã£ã¦ã¾ã¨ãã¦ã¿ããã¨æãã¾ãã HMAC-SHA1 Diffie-Hellmanéµå ±æ ã«ã¤ãã¦ä¸»ã«è¿°ã¹ã¾ãã ç¾ä»£ã®æå·åæè¡ã«ã¤ã㦠(via: wikipedia) ç¾ä»£ã®æå·ã£ã¦ã®ã¯æ¦ãï¼ãã¿â¦