ื”ืคืขืœื ื• ืืช TLS 1.3. ืœืžื” ืืชื” ืฆืจื™ืš ืœืขืฉื•ืช ืืช ืื•ืชื• ื”ื“ื‘ืจ

ื”ืคืขืœื ื• ืืช TLS 1.3. ืœืžื” ืืชื” ืฆืจื™ืš ืœืขืฉื•ืช ืืช ืื•ืชื• ื”ื“ื‘ืจ

ื‘ืชื—ื™ืœืช ื”ืฉื ื”, ื‘ื“ื•ื— ืขืœ ื‘ืขื™ื•ืช ืื™ื ื˜ืจื ื˜ ื•ื ื’ื™ืฉื•ืช ืœืฉื ื™ื 2018-2019 ื›ื‘ืจ ื›ืชื‘ื ื•ืฉื”ื”ืชืคืฉื˜ื•ืช ืฉืœ TLS 1.3 ื”ื™ื ื‘ืœืชื™ ื ืžื ืขืช. ืœืคื ื™ ื–ืžืŸ ืžื”, ืคืจืกื ื• ื‘ืขืฆืžื ื• ืืช ื’ืจืกื” 1.3 ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ Transport Layer Security, ื•ืœืื—ืจ ืื™ืกื•ืฃ ื•ื ื™ืชื•ื— ื ืชื•ื ื™ื, ืื ื—ื ื• ืกื•ืฃ ืกื•ืฃ ืžื•ื›ื ื™ื ืœื“ื‘ืจ ืขืœ ื”ืชื›ื•ื ื•ืช ืฉืœ ื”ืžืขื‘ืจ ื”ื–ื”.

ื™ื•"ืจ ืงื‘ื•ืฆืช ืขื‘ื•ื“ื” ืฉืœ IETF TLS ืœื›ืชื•ื‘:
"ื‘ืงื™ืฆื•ืจ, TLS 1.3 ืืžื•ืจ ืœืกืคืง ืืช ื”ื‘ืกื™ืก ืœืื™ื ื˜ืจื ื˜ ืžืื•ื‘ื˜ื— ื•ื™ืขื™ืœ ื™ื•ืชืจ ื‘ืžืฉืš 20 ื”ืฉื ื™ื ื”ื‘ืื•ืช."

ืคื™ืชื•ื— TLS 1.3 ืœืงื— 10 ืฉื ื™ื ืืจื•ื›ื•ืช. ืื ื—ื ื• ื‘-Qrator Labs, ื™ื—ื“ ืขื ืฉืืจ ื”ืชืขืฉื™ื™ื”, ืขืงื‘ื ื• ืžืงืจื•ื‘ ืื—ืจ ืชื”ืœื™ืš ื™ืฆื™ืจืช ื”ืคืจื•ื˜ื•ืงื•ืœ ืžื”ื˜ื™ื•ื˜ื” ื”ืจืืฉื•ื ื™ืช. ื‘ืžื”ืœืš ืชืงื•ืคื” ื–ื•, ื”ื™ื” ืฆื•ืจืš ืœื›ืชื•ื‘ 28 ื’ืจืกืื•ืช ืจืฆื•ืคื•ืช ืฉืœ ื”ื˜ื™ื•ื˜ื” ื›ื“ื™ ืœืจืื•ืช ื‘ืกื•ืคื• ืฉืœ ื“ื‘ืจ ืืช ื”ืื•ืจ ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ ืžืื•ื–ืŸ ื•ืงืœ ืœืคืจื™ืกื” ื‘-2019. ืชืžื™ื›ืช ื”ืฉื•ืง ื”ืคืขื™ืœื” ื‘-TLS 1.3 ื›ื‘ืจ ื ื™ื›ืจืช: ื”ื˜ืžืขืช ืคืจื•ื˜ื•ืงื•ืœ ืื‘ื˜ื—ื” ืžื•ื›ื— ื•ืืžื™ืŸ ืขื•ื ื” ืขืœ ื”ืฆืจื›ื™ื ืฉืœ ื”ื–ืžืŸ.

ืœืคื™ ืืจื™ืง ืจืกืงื•ืจืœื” (CTO ืฉืœ Firefox ื•ื”ืžื—ื‘ืจ ื”ื™ื—ื™ื“ ืฉืœ TLS 1.3) ื‘ืจืื™ื•ืŸ ืœ-The Register:

"ื–ื”ื• ืชื—ืœื™ืฃ ืžืœื ืœ-TLS 1.2, ืชื•ืš ืฉื™ืžื•ืฉ ื‘ืื•ืชื ืžืคืชื—ื•ืช ื•ืชืขื•ื“ื•ืช, ื›ืš ืฉื”ืœืงื•ื— ื•ื”ืฉืจืช ื™ื›ื•ืœื™ื ืœืชืงืฉืจ ืื•ื˜ื•ืžื˜ื™ืช ื‘ืืžืฆืขื•ืช TLS 1.3 ืื ืฉื ื™ื”ื ืชื•ืžื›ื™ื ื‘ื–ื”", ืืžืจ. "ื›ื‘ืจ ื™ืฉ ืชืžื™ื›ื” ื˜ื•ื‘ื” ื‘ืจืžืช ื”ืกืคืจื™ื™ื”, ื•ื›ืจื•ื ื•ืคื™ื™ืจืคื•ืงืก ืžืืคืฉืจื™ื TLS 1.3 ื›ื‘ืจื™ืจืช ืžื—ื“ืœ."


ื‘ืžืงื‘ื™ืœ, TLS ืžืกืชื™ื™ืžืช ื‘ืงื‘ื•ืฆืช ื”ืขื‘ื•ื“ื” ืฉืœ IETF ื”ื›ื ืช RFC, ื”ื›ืจื™ื– ืขืœ ื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ืฉืœ TLS (ืœืžืขื˜ TLS 1.2 ื‘ืœื‘ื“) ืžื™ื•ืฉื ื•ืช ื•ืื™ื ืŸ ืฉืžื™ืฉื•ืช. ื›ื›ืœ ื”ื ืจืื”, ื”-RFC ื”ืกื•ืคื™ ื™ืฉื•ื—ืจืจ ืœืคื ื™ ืกื•ืฃ ื”ืงื™ืฅ. ื–ื”ื• ืื•ืช ื ื•ืกืฃ ืœืชืขืฉื™ื™ืช ื”-IT: ืื™ืŸ ืœืขื›ื‘ ืืช ืขื“ื›ื•ืŸ ืคืจื•ื˜ื•ืงื•ืœื™ ื”ื”ืฆืคื ื”.

ืจืฉื™ืžื” ืฉืœ ื™ื™ืฉื•ืžื™ TLS 1.3 ื ื•ื›ื—ื™ื™ื ื–ืžื™ื ื” ื‘-Github ืœื›ืœ ืžื™ ืฉืžื—ืคืฉ ืืช ื”ืกืคืจื™ื™ื” ื”ืžืชืื™ืžื” ื‘ื™ื•ืชืจ: https://github.com/tlswg/tls13-spec/wiki/Implementations. ื‘ืจื•ืจ ืฉื”ืื™ืžื•ืฅ ื•ื”ืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœ ื”ืžืขื•ื“ื›ืŸ ื™ืชืงื“ืžื• - ื•ื›ื‘ืจ - ืžืชืงื“ืžื™ื ื‘ืžื”ื™ืจื•ืช. ื”ื”ื‘ื ื” ื›ื™ืฆื“ ื”ืคื›ื” ื”ื”ืฆืคื ื” ื”ื‘ืกื™ืกื™ืช ื‘ืขื•ืœื ื”ืžื•ื“ืจื ื™ ื”ืชืคืฉื˜ื” ื‘ืื•ืคืŸ ื ืจื—ื‘ ืœืžื“ื™.

ืžื” ื”ืฉืชื ื” ืžืื– TLS 1.2?

ืฉืœ ื”ืขืจื•ืช ืฉืœ ื—ื‘ืจืช ื”ืื™ื ื˜ืจื ื˜:
"ืื™ืš TLS 1.3 ื”ื•ืคืš ืืช ื”ืขื•ืœื ืœืžืงื•ื ื˜ื•ื‘ ื™ื•ืชืจ?

TLS 1.3 ื›ื•ืœืœ ื™ืชืจื•ื ื•ืช ื˜ื›ื ื™ื™ื ืžืกื•ื™ืžื™ื - ื›ืžื• ืชื”ืœื™ืš ืœื—ื™ืฆืช ื™ื“ ืคืฉื•ื˜ ืœื™ืฆื™ืจืช ื—ื™ื‘ื•ืจ ืžืื•ื‘ื˜ื— - ื•ื’ื ืžืืคืฉืจ ืœืœืงื•ื—ื•ืช ืœื—ื“ืฉ ืžื”ืจ ื™ื•ืชืจ ื”ืคืขืœื•ืช ืขื ืฉืจืชื™ื. ืืžืฆืขื™ื ืืœื” ื ื•ืขื“ื• ืœื”ืคื—ื™ืช ืืช ื–ืžืŸ ื”ืื—ื–ื•ืจ ืฉืœ ื”ื’ื“ืจืช ื”ื—ื™ื‘ื•ืจ ื•ื›ื™ืฉืœื•ื ื•ืช ื‘ื—ื™ื‘ื•ืจ ื‘ืงื™ืฉื•ืจื™ื ื—ืœืฉื™ื, ื”ืžืฉืžืฉื™ื ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื›ื”ืฆื“ืงื” ืœืกืคืง ืจืง ื—ื™ื‘ื•ืจื™ HTTP ืœื ืžื•ืฆืคื ื™ื.

ืœื ืคื—ื•ืช ื—ืฉื•ื‘, ื”ื•ื ืžืกื™ืจ ืชืžื™ื›ื” ื‘ืžืกืคืจ ืืœื’ื•ืจื™ืชืžื™ ื”ืฆืคื ื” ื•ื’ื™ื‘ื•ื‘ ืžื“ื•ืจ ืงื•ื“ื ื•ืœื ืžืื•ื‘ื˜ื—ื™ื ืฉืขื“ื™ื™ืŸ ืžื•ืชืจื™ื (ืื ื›ื™ ืœื ืžื•ืžืœืฅ) ืœืฉื™ืžื•ืฉ ืขื ื’ืจืกืื•ืช ืงื•ื“ืžื•ืช ืฉืœ TLS, ื›ื•ืœืœ SHA-1, MD5, DES, 3DES ื•-AES-CBC. ื”ื•ืกืคืช ืชืžื™ื›ื” ืขื‘ื•ืจ ื—ื‘ื™ืœื•ืช ืฆื•ืคืŸ ื—ื“ืฉื•ืช. ืฉื™ืคื•ืจื™ื ืื—ืจื™ื ื›ื•ืœืœื™ื ืืœืžื ื˜ื™ื ืžื•ืฆืคื ื™ื ื™ื•ืชืจ ืฉืœ ืœื—ื™ืฆืช ื”ื™ื“ (ืœื“ื•ื’ืžื”, ื—ื™ืœื•ืคื™ ืžื™ื“ืข ืชืขื•ื“ื•ืช ืžื•ืฆืคื ื™ื ื›ืขืช) ื›ื“ื™ ืœื”ืคื—ื™ืช ืืช ื›ืžื•ืช ื”ืจืžื–ื™ื ืœืฆื•ืชืช ืชืขื‘ื•ืจื” ืคื•ื˜ื ืฆื™ืืœื™ืช, ื›ืžื• ื’ื ืฉื™ืคื•ืจื™ื ื‘ืกื•ื“ื™ื•ืช ื”ืขื‘ืจื” ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžืฆื‘ื™ ื”ื—ืœืคืช ืžืคืชื—ื•ืช ืžืกื•ื™ืžื™ื, ื›ืš ืฉืชืงืฉื•ืจืช ื‘ื›ืœ ืขืช ื—ื™ื™ื‘ ืœื”ื™ืฉืืจ ืžืื•ื‘ื˜ื— ื’ื ืื ื”ืืœื’ื•ืจื™ืชืžื™ื ื”ืžืฉืžืฉื™ื ืœื”ืฆืคื ืชื• ื™ื™ืคื’ืขื• ื‘ืขืชื™ื“."

ืคื™ืชื•ื— ืคืจื•ื˜ื•ืงื•ืœื™ื ืžื•ื“ืจื ื™ื™ื ื•-DDoS

ื›ืคื™ ืฉืื•ืœื™ ื›ื‘ืจ ืงืจืืชื, ื‘ืžื”ืœืš ืคื™ืชื•ื— ื”ืคืจื•ื˜ื•ืงื•ืœ ื•ืืคื™ืœื• ืื—ืจื™, ื‘ืงื‘ื•ืฆืช ื”ืขื‘ื•ื“ื” ืฉืœ IETF TLS ื ื•ืฆืจื• ืกืชื™ืจื•ืช ื—ืžื•ืจื•ืช. ื›ืขืช ื‘ืจื•ืจ ืฉืืจื’ื•ื ื™ื ื‘ื•ื“ื“ื™ื (ื›ื•ืœืœ ืžื•ืกื“ื•ืช ืคื™ื ื ืกื™ื™ื) ื™ืฆื˜ืจื›ื• ืœืฉื ื•ืช ืืช ื”ื“ืจืš ืฉื‘ื” ื”ื ืžืื‘ื˜ื—ื™ื ืืช ื”ืจืฉืช ืฉืœื”ื ื›ื“ื™ ืœื”ืชืื™ื ืืช ื”ืคืจื•ื˜ื•ืงื•ืœ ื”ืžื•ื‘ื ื” ื›ืขืช ืกื•ื“ื™ื•ืช ืงื“ื™ืžื” ืžื•ืฉืœืžืช.

ื”ืกื™ื‘ื•ืช ืœื›ืš ืฉื”ื“ื‘ืจ ืขืฉื•ื™ ืœื”ื™ื“ืจืฉ ืžืคื•ืจื˜ื•ืช ื‘ืžืกืžืš, ื ื›ืชื‘ ืขืœ ื™ื“ื™ ืกื˜ื™ื‘ ืคื ื˜ืจ. ื”ืžืืžืจ ื‘ืŸ 20 ื”ืขืžื•ื“ื™ื ืžื–ื›ื™ืจ ืžืกืคืจ ื“ื•ื’ืžืื•ืช ืฉื‘ื”ืŸ ืืจื’ื•ืŸ ืขืฉื•ื™ ืœืจืฆื•ืช ืœืคืขื ื— ืชืขื‘ื•ืจื” ืžื—ื•ืฅ ืœืคืก (ืฉ-PFS ืื™ื ื• ืžืืคืฉืจ) ืœืžื˜ืจื•ืช ื ื™ื˜ื•ืจ, ืชืื™ืžื•ืช ืื• ืฉื›ื‘ืช ื™ื™ืฉื•ืžื™ื (L7) DDoS.

ื”ืคืขืœื ื• ืืช TLS 1.3. ืœืžื” ืืชื” ืฆืจื™ืš ืœืขืฉื•ืช ืืช ืื•ืชื• ื”ื“ื‘ืจ

ืืžื ื ืื ื—ื ื• ื‘ื”ื—ืœื˜ ืœื ืžื•ื›ื ื™ื ืœื”ืขืœื•ืช ื”ืฉืขืจื•ืช ืขืœ ื“ืจื™ืฉื•ืช ืจื’ื•ืœื˜ื•ืจื™ื•ืช, ืื‘ืœ ื”ืžื•ืฆืจ ื”ืงื ื™ื™ื ื™ ืฉืœื ื• ืœื”ืคื—ืชืช DDoS (ื›ื•ืœืœ ืคืชืจื•ืŸ ืœื ืžื—ื™ื™ื‘ ื’ื™ืœื•ื™ ืžื™ื“ืข ืจื’ื™ืฉ ื•/ืื• ืกื•ื“ื™) ื ื•ืฆืจ ื‘ืฉื ืช 2012 ืชื•ืš ื”ืชื—ืฉื‘ื•ืช ื‘-PFS, ื›ืš ืฉื”ืœืงื•ื—ื•ืช ื•ื”ืฉื•ืชืคื™ื ืฉืœื ื• ืœื ื”ื™ื• ืฆืจื™ื›ื™ื ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื›ืœืฉื”ื ื‘ืชืฉืชื™ืช ืฉืœื”ื ืœืื—ืจ ืขื“ื›ื•ืŸ ื’ืจืกืช ื”-TLS ื‘ืฆื“ ื”ืฉืจืช.

ื›ืžื• ื›ืŸ, ืžืื– ื”ื™ื™ืฉื•ื, ืœื ื–ื•ื”ื• ื‘ืขื™ื•ืช ื”ืงืฉื•ืจื•ืช ืœื”ืฆืคื ืช ืชื—ื‘ื•ืจื”. ื–ื” ืจืฉืžื™: TLS 1.3 ืžื•ื›ืŸ ืœื™ื™ืฆื•ืจ.

ืขื ื–ืืช, ืขื“ื™ื™ืŸ ืงื™ื™ืžืช ื‘ืขื™ื” ื”ืงืฉื•ืจื” ื‘ืคื™ืชื•ื— ืฉืœ ืคืจื•ื˜ื•ืงื•ืœื™ื ืžื”ื“ื•ืจ ื”ื‘ื. ื”ื‘ืขื™ื” ื”ื™ื ืฉื”ืชืงื“ืžื•ืช ื”ืคืจื•ื˜ื•ืงื•ืœ ื‘-IETF ื‘ื“ืจืš ื›ืœืœ ืชืœื•ื™ื” ืžืื•ื“ ื‘ืžื—ืงืจ ืืงื“ืžื™, ื•ืžืฆื‘ ื”ืžื—ืงืจ ื”ืืงื“ืžื™ ื‘ืชื—ื•ื ื”ืคื—ืชืช ื”ืชืงืคื•ืช ืžื ื™ืขืช ืฉื™ืจื•ืช ืžื‘ื•ื–ืจื•ืช ื”ื•ื ืขื’ื•ื.

ืื–, ื“ื•ื’ืžื” ื˜ื•ื‘ื” ืชื”ื™ื” ืกืขื™ืฃ 4.4 ื˜ื™ื•ื˜ืช IETF "QUIC Manageability", ื—ืœืง ืžื—ื‘ื™ืœืช ืคืจื•ื˜ื•ืงื•ืœ QUIC ื”ืงืจื•ื‘ื”, ืงื•ื‘ืขืช ื›ื™ "ืฉื™ื˜ื•ืช ืžื•ื“ืจื ื™ื•ืช ืœืื™ืชื•ืจ ื•ื”ืคื—ืชื” ืฉืœ [ื”ืชืงืคื•ืช DDoS] ื›ื•ืœืœื•ืช ื‘ื“ืจืš ื›ืœืœ ืžื“ื™ื“ื” ืคืกื™ื‘ื™ืช ื‘ืืžืฆืขื•ืช ื ืชื•ื ื™ ื–ืจื™ืžืช ืจืฉืช."

ื–ื” ื”ืื—ืจื•ืŸ, ืœืžืขืฉื”, ื ื“ื™ืจ ืžืื•ื“ ื‘ืกื‘ื™ื‘ื•ืช ืืจื’ื•ื ื™ื•ืช ืืžื™ืชื™ื•ืช (ื•ื™ืฉื™ืžื™ื ืจืง ื‘ื—ืœืงื• ืœืกืคืงื™ ืื™ื ื˜ืจื ื˜), ื•ื‘ื›ืœ ืžืงืจื” ืœื ืกื‘ื™ืจ ืฉื™ื”ื™ื” "ืžืงืจื” ื›ืœืœื™" ื‘ืขื•ืœื ื”ืืžื™ืชื™ - ืื‘ืœ ืžื•ืคื™ืข ื›ืœ ื”ื–ืžืŸ ื‘ืคืจืกื•ืžื™ื ืžื“ืขื™ื™ื, ื‘ื“ืจืš ื›ืœืœ ืœื ื ืชืžื›ื™ื ืขืœ ื™ื“ื™ ื‘ื“ื™ืงืช ื›ืœ ื”ืกืคืงื˜ืจื•ื ืฉืœ ื”ืชืงืคื•ืช DDoS ืคื•ื˜ื ืฆื™ืืœื™ื•ืช, ื›ื•ืœืœ ื”ืชืงืคื•ืช ื‘ืจืžืช ื”ืืคืœื™ืงืฆื™ื”. ื–ื” ื”ืื—ืจื•ืŸ, ืœืคื—ื•ืช ื‘ื’ืœืœ ื”ืคืจื™ืกื” ื”ืขื•ืœืžื™ืช ืฉืœ TLS, ื›ืžื•ื‘ืŸ ืฉืœื ื ื™ืชืŸ ืœื–ื”ื•ืช ืขืœ ื™ื“ื™ ืžื“ื™ื“ื” ืคืกื™ื‘ื™ืช ืฉืœ ืžื ื•ืช ืจืฉืช ื•ื–ืจื™ืžื•ืช.

ื‘ืื•ืคืŸ ื“ื•ืžื”, ืื ื—ื ื• ืขื“ื™ื™ืŸ ืœื ื™ื•ื“ืขื™ื ื›ื™ืฆื“ ืกืคืงื™ ื—ื•ืžืจื” ืœื”ืคื—ืชืช DDoS ื™ืกืชื’ืœื• ืœืžืฆื™ืื•ืช ืฉืœ TLS 1.3. ื‘ืฉืœ ื”ืžื•ืจื›ื‘ื•ืช ื”ื˜ื›ื ื™ืช ืฉืœ ื”ืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœ ืžื—ื•ืฅ ืœืคืก, ื”ืฉื“ืจื•ื’ ืขืฉื•ื™ ืœื”ื™ืžืฉืš ื–ืžืŸ ืžื”.

ื”ื’ื“ืจืช ื”ืžื˜ืจื•ืช ื”ื ื›ื•ื ื•ืช ืœื”ื ื—ื™ื™ืช ื”ืžื—ืงืจ ื”ื™ื ืืชื’ืจ ืžืจื›ื–ื™ ืขื‘ื•ืจ ืกืคืงื™ ืฉื™ืจื•ืชื™ ื”ืคื—ืชืช DDoS. ืชื—ื•ื ืื—ื“ ืฉื‘ื• ื ื™ืชืŸ ืœื”ืชื—ื™ืœ ืคื™ืชื•ื— ื”ื•ื ืงื‘ื•ืฆืช ืžื—ืงืจ SMART ื‘-IRTF, ืฉื ื—ื•ืงืจื™ื ื™ื›ื•ืœื™ื ืœืฉืชืฃ ืคืขื•ืœื” ืขื ื”ืชืขืฉื™ื™ื” ื›ื“ื™ ืœื—ื“ื“ ืืช ื”ื™ื“ืข ืฉืœื”ื ื‘ืชืขืฉื™ื™ื” ืžืืชื’ืจืช ื•ืœื—ืงื•ืจ ืืคื™ืงื™ื ื—ื“ืฉื™ื ืฉืœ ืžื—ืงืจ. ืื ื• ื’ื ืžื‘ืจื›ื™ื ืืช ื›ืœ ื”ื—ื•ืงืจื™ื ื‘ื‘ืจื›ื”, ืื ื™ื”ื™ื• ื›ืืœื” - ื ื™ืชืŸ ืœื™ืฆื•ืจ ืื™ืชื ื• ืงืฉืจ ืขื ืฉืืœื•ืช ืื• ื”ืฆืขื•ืช ื”ืงืฉื•ืจื•ืช ืœืžื—ืงืจ DDoS ืื• ืœืงื‘ื•ืฆืช ื”ืžื—ืงืจ SMART ื‘ื›ืชื•ื‘ืช [ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ]

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”