Chrome ga-amalite igbochi akụrụngwa HTTP na ibe HTTPS wee lelee ike okwuntughe

Google dọrọ aka ná ntị gbasara ịgbanwe ụzọ isi hazie ọdịnaya agwakọtara na ibe ndị mepere site na HTTPS. Na mbụ, ọ bụrụ na e nwere ihe ndị dị na ibe ndị meghere site na HTTPS nke ebukọrọ na-enweghị ezoro ezo (site na http://protocol), e gosipụtara ihe ngosi pụrụ iche. N'ọdịnihu, e kpebiri igbochi nbudata nke akụrụngwa ndị dị otú ahụ na ndabara. Yabụ, ibe emepere site na “https://” ga-ekwe nkwa ịnwe naanị akụrụngwa ebudatara site na ọwa nkwukọrịta echedoro.

Achọpụtara na ugbu a karịa 90% nke saịtị ndị ọrụ Chrome na-eji HTTPS meghere. Ọnụnọ nke ntinye etinyere na-enweghị ezoro ezo na-emepụta ihe egwu nchekwa site na mgbanwe nke ọdịnaya echedoro ma ọ bụrụ na enwere njikwa ọwa nkwukọrịta (dịka ọmụmaatụ, mgbe ị na-ejikọ site na Wi-Fi mepere emepe). Achọpụtara ihe ngosi ọdịnaya agwakọtara na-adịghị arụ ọrụ ma na-eduhie onye ọrụ, ebe ọ naghị enye nyocha doro anya nke nchekwa nke ibe.

Ugbu a, ụdị ọdịnaya agwakọta nke kachasị dị ize ndụ, dị ka scripts na iframes, ejirila ndabara egbochila ya, mana enwere ike ibudata onyonyo, faịlụ ọdịyo na vidiyo site na http://. Site n'iji ihe onyonyo, onye na-awakpo nwere ike dochie kuki ndị na-enyocha onye ọrụ, nwaa iji adịghị ike na ndị na-ese foto, ma ọ bụ mee ụgha site na dochie ozi enyere na onyonyo a.

A na-ekewa mmeghe nke mgbochi ahụ n'ọtụtụ ọkwa. Chrome 79, nke edobere maka Disemba 10, ga-egosipụta ntọala ọhụrụ nke ga-enye gị ohere gbanyụọ mgbochi maka saịtị ụfọdụ. A ga-etinye ntọala a na ọdịnaya agwakọtara nke akpọchielarị, dị ka scripts na iframes, a ga-akpọkwa ya site na menu nke dara ala mgbe ị pịrị akara mkpọchi, dochie akara ngosi echere na mbụ maka gbanyụọ mgbochi.

Chrome ga-amalite igbochi akụrụngwa HTTP na ibe HTTPS wee lelee ike okwuntughe

Chrome 80, nke a na-atụ anya na February 4, ga-eji atụmatụ mgbochi dị nro maka faịlụ ọdịyo na vidiyo, na-egosi ngbanwe akpaaka nke http: // njikọ na https://, nke ga-echekwa ọrụ ma ọ bụrụ na a na-enwetakwa nsogbu ahụ site na HTTPS. . Foto ga-aga n'ihu na-ebuwanye ibu na-enweghị mgbanwe, mana ọ bụrụ na ebudatara site na http: //, ibe https:// ga-egosipụta ihe njikọ na-enweghị nchebe maka ibe dum. Ka ịgbanwee na-akpaghị aka gaa na https ma ọ bụ gbochie onyonyo, ndị mmepe saịtị ga-enwe ike iji akụrụngwa nkwalite CSP-arịrịọ na-enweghị nchebe yana igbochi ọdịnaya-agwakọta niile. Chrome 81, nke ahaziri maka Machị 17, ga-edozi onwe ya http:// ka https:// maka ibugo onyonyo agwakọtara.

Chrome ga-amalite igbochi akụrụngwa HTTP na ibe HTTPS wee lelee ike okwuntughe

Ọzọkwa, Google mara ọkwa gbasara ntinye n'ime otu ntọhapụ na-esote nke ihe nchọgharị Chome nke akụrụngwa Checkup ọhụrụ, na mbụ na-emepe emepe n'ụdị mgbakwunye mpụga. Mwekota ga-eduga n'ọdịdị na njikwa okwuntughe Chrome mgbe niile nke ngwaọrụ maka nyochaa ntụkwasị obi nke okwuntughe nke onye ọrụ na-eji. Mgbe ị na-agbalị ịbanye na saịtị ọ bụla, a ga-enyocha nbanye na okwuntughe gị megide nchekwa data nke akaụntụ ndị mebiri emebi, yana ịdọ aka ná ntị gosipụtara ma ọ bụrụ na achọpụtara nsogbu. A na-eme nlele ahụ megide nchekwa data na-ekpuchi ihe karịrị ijeri 4 ijeri akaụntụ ndị pụtara na ọdụ data ndị ọrụ ewepụrụ. A ga-egosipụtakwa ịdọ aka ná ntị ma ọ bụrụ na ị nwaa iji okwuntughe ndị dị obere dị ka "abc123" (site na onu ogugu Google 23% nke ndị America na-eji okwuntughe ndị yiri ya), ma ọ bụ mgbe ha na-eji otu paswọọdụ na ọtụtụ saịtị.

Iji chekwaa nzuzo, mgbe ị na-enweta API mpụga, ọ bụ naanị bytes abụọ mbụ nke hash nke nbanye na paswọọdụ ka a na-ebufe (a na-eji hashing algọridim. Argon2). A na-eji igodo emepụtara n'akụkụ onye ọrụ ezoro hash zuru ezu. Hashes izizi dị na nchekwa data Google bụkwa nke ezoro ezo na ọ bụ naanị bytes abụọ mbụ nke hash ka fọdụrụ maka ndenye aha. A na-eme nkwenye ikpeazụ nke hashes nke dabara n'okpuru prefix-byte abụọ ebutere n'akụkụ onye ọrụ site na iji teknụzụ cryptographic "ìsì", nke ọ nweghị onye maara ọdịnaya nke data a na-enyocha. Iji kpuchido ọdịnaya nke nchekwa data nke akaụntụ ndị mebiri emebi, nke ejiri ike siri ike kpebisie ike na arịrịọ maka prefixes aka ike, a na-ezobe data a na-ebufe na njikọ igodo emepụtara na ndabere nke nchikota nbanye na paswọọdụ ekwenyesiri ike.

isi: opennet.ru

Tinye a comment