ืคื’ื™ืขื•ืช ื‘-TLS ื”ืžืืคืฉืจืช ืงื‘ื™ืขืช ืžืคืชื— ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ืฆืคื ื™ DH

ื’ื™ืœื” ืžื™ื“ืข ืขืœ ื”ื—ื“ืฉ ืคื’ื™ืขื•ืช (CVE-2020-1968) ื‘ืคืจื•ื˜ื•ืงื•ืœ TLS, ืขื ืฉื ืงื•ื“
ื“ื‘ื™ื‘ื•ืŸ ื•ืžืืคืฉืจ, ื‘ื ืกื™ื‘ื•ืช ื ื“ื™ืจื•ืช, ืœืงื‘ื•ืข ืžืคืชื— ืจืืฉื™ ืจืืฉื•ื ื™ (ืงื“ื-ืžืืกื˜ืจ), ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื›ื“ื™ ืœืคืขื ื— ื—ื™ื‘ื•ืจื™ TLS, ื›ื•ืœืœ HTTPS, ื‘ืขืช ื™ื™ืจื•ื˜ ืชืขื‘ื•ืจืช ืžืขื‘ืจ (MITM). ื™ืฆื•ื™ืŸ ื›ื™ ื”ืžืชืงืคื” ืงืฉื” ืžืื•ื“ ืœื™ื™ืฉื•ื ืžืขืฉื™ ื•ื”ื™ื ื‘ืขืœืช ืื•ืคื™ ืชื™ืื•ืจื˜ื™ ื™ื•ืชืจ. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื”, ื ื“ืจืฉืช ืชืฆื•ืจื” ืกืคืฆื™ืคื™ืช ืฉืœ ืฉืจืช ื”-TLS ื•ื™ื›ื•ืœืช ืœืžื“ื•ื“ ื‘ืฆื•ืจื” ืžื“ื•ื™ืงืช ืžืื•ื“ ืืช ื–ืžืŸ ื”ืขื™ื‘ื•ื“ ืฉืœ ื”ืฉืจืช.

ื”ื‘ืขื™ื” ืงื™ื™ืžืช ื™ืฉื™ืจื•ืช ื‘ืžืคืจื˜ TLS ื•ืžืฉืคื™ืขื” ืจืง ืขืœ ื—ื™ื‘ื•ืจื™ื ื‘ืืžืฆืขื•ืช ืฆืคื ื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ืคืจื•ื˜ื•ืงื•ืœ ื—ื™ืœื•ืคื™ ืžืคืชื—ื•ืช DH (Diffie-Hellman, TLS_DH_*"). ืขื ืฆืคื ื™ ECDH ื”ื‘ืขื™ื” ืœื ืžืชืจื—ืฉืช ื•ื”ื ื ืฉืืจื™ื ืžืื•ื‘ื˜ื—ื™ื. ืจืง ืคืจื•ื˜ื•ืงื•ืœื™ TLS ืขื“ ื’ืจืกื” 1.2 ืคื’ื™ืขื™ื; TLS 1.3 ืื™ื ื• ืžื•ืฉืคืข ืžื”ื‘ืขื™ื”. ื”ืคื’ื™ืขื•ืช ืžืชืจื—ืฉืช ื‘ื™ื™ืฉื•ืžื™ TLS ื”ืขื•ืฉื™ื ืฉื™ืžื•ืฉ ื—ื•ื–ืจ ื‘ืžืคืชื— ื”ืกื•ื“ื™ ืฉืœ DH ืขืœ ืคื ื™ ื—ื™ื‘ื•ืจื™ TLS ืฉื•ื ื™ื (ื”ืชื ื”ื’ื•ืช ื–ื• ืžืชืจื—ืฉืช ื‘ื›-4.4% ืžืฉืจืชื™ Alexa Top 1M).

ื‘-OpenSSL 1.0.2e ื•ื‘ื’ืจืกืื•ืช ืงื•ื“ืžื•ืช, ื ืขืฉื” ืฉื™ืžื•ืฉ ื—ื•ื–ืจ ื‘ืžืคืชื— ื”ืจืืฉื™ ืฉืœ DH ื‘ื›ืœ ื—ื™ื‘ื•ืจื™ ื”ืฉืจืช, ืืœื ืื ื›ืŸ ื”ืืคืฉืจื•ืช SSL_OP_SINGLE_DH_USE ืžื•ื’ื“ืจืช ื‘ืžืคื•ืจืฉ. ืžืื– OpenSSL 1.0.2f, ื ืขืฉื” ืฉื™ืžื•ืฉ ื—ื•ื–ืจ ื‘ืžืคืชื— ื”ืจืืฉื™ ืฉืœ DH ืจืง ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืฆืคื ื™ DH ืกื˜ื˜ื™ื™ื ("DH-*", ืœืžืฉืœ "DH-RSA-AES256-SHA"). ื”ืคื’ื™ืขื•ืช ืื™ื ื” ืžื•ืคื™ืขื” ื‘-OpenSSL 1.1.1, ืžื›ื™ื•ื•ืŸ ืฉื”ืขื ืฃ ื”ื–ื” ืื™ื ื• ืžืฉืชืžืฉ ื‘ืžืคืชื— ืจืืฉื™ ืฉืœ DH ื•ืื™ื ื• ืžืฉืชืžืฉ ื‘ืฆืคื ื™ DH ืกื˜ื˜ื™ื™ื.

ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืฉื™ื˜ืช ื”ื—ืœืคืช ืžืคืชื—ื•ืช DH, ืฉื ื™ ื”ืฆื“ื“ื™ื ืฉืœ ื”ื—ื™ื‘ื•ืจ ื™ื•ืฆืจื™ื ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื ืืงืจืื™ื™ื (ืœื”ืœืŸ ืžืคืชื— "a" ื•ืžืคืชื— "b"), ืขืœ ื‘ืกื™ืกื ืžื—ื•ืฉื‘ื™ื ื•ื ืฉืœื—ื™ื ืžืคืชื—ื•ืช ืฆื™ื‘ื•ืจื™ื™ื (ga mod p ื•-gb mod p). ืœืื—ืจ ืฉื›ืœ ืฆื“ ืžืงื‘ืœ ืืช ื”ืžืคืชื—ื•ืช ื”ืฆื™ื‘ื•ืจื™ื™ื, ืžื—ื•ืฉื‘ ืžืคืชื— ืจืืฉื™ ืžืฉื•ืชืฃ (gab mod p), ื”ืžืฉืžืฉ ืœื™ืฆื™ืจืช ืžืคืชื—ื•ืช ื”ืคืขืœื”. ืžืชืงืคืช ื”ื“ื‘ื™ื‘ื•ืŸ ืžืืคืฉืจืช ืœืš ืœืงื‘ื•ืข ืืช ื”ืžืคืชื— ื”ืจืืฉื™ ื‘ืืžืฆืขื•ืช ื ื™ืชื•ื— ืขืจื•ืฅ ืฆื“ื“ื™, ื‘ื”ืชื‘ืกืก ืขืœ ื”ืขื•ื‘ื“ื” ืฉืžืคืจื˜ื™ ื”-TLS ืขื“ ื’ืจืกื” 1.2 ืžื—ื™ื™ื‘ื™ื ืœื‘ื˜ืœ ืืช ื›ืœ ื”ื‘ื™ื™ื˜ื™ื ื”ืืคืกื™ื ื”ืžื•ื‘ื™ืœื™ื ืฉืœ ื”ืžืคืชื— ื”ืจืืฉื™ ืœืคื ื™ ื—ื™ืฉื•ื‘ื™ื ื”ืงืฉื•ืจื™ื ื‘ื•.

ื”ื›ืœืœืช ื”ืžืคืชื— ื”ืจืืฉื™ ื”ืงื˜ื•ืข ืžื•ืขื‘ืจืช ืœืคื•ื ืงืฆื™ื™ืช ื™ืฆื™ืจืช ืžืคืชื— ื”ื”ืคืขืœื”, ื”ืžื‘ื•ืกืกืช ืขืœ ืคื•ื ืงืฆื™ื•ืช ื’ื™ื‘ื•ื‘ ืขื ืขื™ื›ื•ื‘ื™ื ืฉื•ื ื™ื ื‘ืขืช ืขื™ื‘ื•ื“ ื ืชื•ื ื™ื ืฉื•ื ื™ื. ืžื“ื™ื“ื” ืžื“ื•ื™ืงืช ืฉืœ ืชื–ืžื•ืŸ ืคืขื•ืœื•ืช ื”ืžืคืชื— ืฉืžื‘ืฆืข ื”ืฉืจืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ืœืงื‘ื•ืข ืจืžื–ื™ื (ืื•ืจืงืœ) ื”ืžืืคืฉืจื™ื ืœืฉืคื•ื˜ ื”ืื ื”ืžืคืชื— ื”ืจืืฉื™ ืžืชื—ื™ืœ ืžืืคืก ืื• ืœื. ืœื“ื•ื’ืžื”, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื™ื™ืจื˜ ืืช ื”ืžืคืชื— ื”ืฆื™ื‘ื•ืจื™ (ga) ืฉื ืฉืœื— ืขืœ ื™ื“ื™ ื”ืœืงื•ื—, ืœืฉื“ืจ ืื•ืชื• ืžื—ื“ืฉ ืœืฉืจืช ื•ืœืงื‘ื•ืข
ื”ืื ื”ืžืคืชื— ื”ืจืืฉื™ ืฉื ื•ืฆืจ ืžืชื—ื™ืœ ืžืืคืก.

ื›ืฉืœืขืฆืžื”, ื”ื’ื“ืจืช ื‘ืช ืื—ื“ ืฉืœ ื”ืžืคืชื— ืื™ื ื” ื ื•ืชื ืช ื“ื‘ืจ, ืืš ืขืœ ื™ื“ื™ ื™ื™ืจื•ื˜ ืขืจืš ื”-"ga" ื”ืžืฉื•ื“ืจ ืขืœ ื™ื“ื™ ื”ืœืงื•ื— ื‘ืžื”ืœืš ืžืฉื ื•ืžืชืŸ ืขืœ ื”ื—ื™ื‘ื•ืจ, ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืงื‘ื•ืฆื” ืฉืœ ืขืจื›ื™ื ืื—ืจื™ื ื”ืงืฉื•ืจื™ื ืœ-"ga" ื•ืœืฉืœื•ื— ืื•ืชื ืืœ ื”ืฉืจืช ื‘ื”ืคืขืœื•ืช ื ืคืจื“ื•ืช ืฉืœ ืžืฉื ื•ืžืชืŸ ืขืœ ื—ื™ื‘ื•ืจ. ืขืœ ื™ื“ื™ ื™ืฆื™ืจื” ื•ืฉืœื™ื—ื” ืฉืœ ืขืจื›ื™ "gri*ga", ื”ืชื•ืงืฃ ื™ื›ื•ืœ, ื‘ืืžืฆืขื•ืช ื ื™ืชื•ื— ืฉื™ื ื•ื™ื™ื ื‘ืขื™ื›ื•ื‘ื™ื ื‘ืชื’ื•ื‘ืช ื”ืฉืจืช, ืœืงื‘ื•ืข ืืช ื”ืขืจื›ื™ื ื”ืžื•ื‘ื™ืœื™ื ืœืงื‘ืœืช ืžืคืชื—ื•ืช ืจืืฉื™ื™ื ื”ื—ืœ ืžืืคืก. ืœืื—ืจ ืฉืงื‘ืข ืขืจื›ื™ื ื›ืืœื”, ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืงื‘ื•ืฆื” ืฉืœ ืžืฉื•ื•ืื•ืช ืขื‘ื•ืจ ืคืชืจื•ื ื•ืช ื‘ืขื™ื•ืช ื‘ืžืกืคืจื™ื ื ืกืชืจื™ื ื•ื—ืฉื‘ ืืช ื”ืžืคืชื— ื”ืจืืฉื™ ื”ืžืงื•ืจื™.

ืคื’ื™ืขื•ืช ื‘-TLS ื”ืžืืคืฉืจืช ืงื‘ื™ืขืช ืžืคืชื— ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ืฆืคื ื™ DH

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉืœ OpenSSL ืฉื”ื•ืงืฆื” ืจืžืช ืกื›ื ื” ื ืžื•ื›ื”, ื•ื”ืชื™ืงื•ืŸ ืฆื•ืžืฆื ืœื”ืขื‘ืจืช ื”ืฆืคื ื™ื ื”ื‘ืขื™ื™ืชื™ื™ื "TLS_DH_*" ื‘ืžื”ื“ื•ืจื” 1.0.2w ืœืงื˜ื’ื•ืจื™ื™ืช ื”ืฆืคื ื™ื ืขื ืจืžืช ื”ื’ื ื” ืœื ืžืกืคืงืช ("ื—ืœืฉื™ื-ssl-ciphers"), ื”ืžื•ืฉื‘ืชืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. . ืžืคืชื—ื™ ืžื•ื–ื™ืœื” ืขืฉื• ืืช ืื•ืชื• ื”ื“ื‘ืจ, ื›ื‘ื•ื™ ื‘ืกืคืจื™ื™ืช NSS ื”ืžืฉืžืฉืช ื‘ืคื™ื™ืจืคื•ืงืก, ื—ื‘ื™ืœื•ืช ื”ืฆื•ืคืŸ DH ื•-DHE. ื”ื—ืœ ืž-Firefox 78, ืฆืคื ื™ื ื‘ืขื™ื™ืชื™ื™ื ืžื•ืฉื‘ืชื™ื. Chrome ื”ืคืกื™ืง ืืช ื”ืชืžื™ื›ื” ื‘-DH ื‘-2016. ื”ืกืคืจื™ื•ืช BearSSL, BoringSSL, Botan, Mbed TLS ื•-s2n ืื™ื ืŸ ืžื•ืฉืคืขื•ืช ืžื”ื‘ืขื™ื” ืžื›ื™ื•ื•ืŸ ืฉื”ืŸ ืื™ื ืŸ ืชื•ืžื›ื•ืช ื‘ืฆืคื ื™ DH ืื• ื‘ื’ืจืกืื•ืช ืกื˜ื˜ื™ื•ืช ืฉืœ ืฆืคื ื™ DH.

ื‘ืขื™ื•ืช ื ื•ืกืคื•ืช ืžืฆื•ื™ื ื•ืช ื‘ื ืคืจื“ (CVE-2020-5929) ื‘ืขืจื™ืžืช TLS ืฉืœ ื”ืชืงื ื™ F5 BIG-IP, ืžื” ืฉื”ื•ืคืš ืืช ื”ื”ืชืงืคื” ืœืžืฆื™ืื•ืชื™ืช ื™ื•ืชืจ. ื‘ืคืจื˜, ื–ื•ื”ื• ืกื˜ื™ื•ืช ื‘ื”ืชื ื”ื’ื•ืช ืฉืœ ืžื›ืฉื™ืจื™ื ื‘ื ื•ื›ื—ื•ืช ืืคืก ื‘ืชื™ื ื‘ืชื—ื™ืœืช ื”ืžืคืชื— ื”ืจืืฉื™, ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื ื‘ืžืงื•ื ืœืžื“ื•ื“ ืืช ื”ื”ืฉื”ื™ื” ื”ืžื“ื•ื™ืงืช ืฉืœ ื—ื™ืฉื•ื‘ื™ื.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”