以åã¯ã蚌ææžã¯æåã§æŽæ°ããå¿
èŠããã£ããããæéåãã«ãªãããšããããããŸããã 人ã
ã¯åã«ãããããããšãå¿ããã ãã§ãã Let's Encrypt ã®ç»å Žãšèªåã¢ããããŒãæé ã«ããããã®åé¡ã¯è§£æ±ºãããã¯ãã§ãã ã§ãæè¿ã®
ãã®è©±ãèŠéããæ¹ã®ããã«ä»ãå ããŠãããŸããã4 幎 2019 æ XNUMX æ¥ã®æ·±å€ãã»ãŒãã¹ãŠã® Firefox æ¡åŒµæ©èœãçªç¶åäœããªããªã£ãŠããŸããŸããã
çµå±ã®ãšããã倧èŠæš¡ãªé害㯠Mozilla ãåå ã§çºçããŸããã
Mozilla ã¯ããã« Firefox 66.0.4 ãããããªãªãŒã¹ããŸãããããã«ããç¡å¹ãªèšŒææžã®åé¡ã解決ããããã¹ãŠã®æ¡åŒµæ©èœãéåžžã®ç¶æ
ã«æ»ããŸããã éçºè
ã¯ãããã€ã³ã¹ããŒã«ããããšãæšå¥šããŠããŸãã
ãããããã®è©±ã¯ã蚌ææžã®æå¹æéãä»æ¥ã§ãäŸç¶ãšããŠå·®ãè¿«ã£ãåé¡ã§ããããšãæ¹ããŠç€ºããŠããŸãã
ãã®ç¹ã§ããããã³ã«éçºè
ããã®ã¿ã¹ã¯ã«ã©ã®ããã«å¯ŸåŠããããšããããªãç¬åµçãªæ¹æ³ãèŠãã®ã¯èå³æ·±ãã§ãã
DNSCrypt
DNSCrypt 㯠DNS ãã©ãã£ãã¯æå·åãããã³ã«ã§ãã DNS éä¿¡ãååã MiTM ããä¿è·ããDNS ã¯ãšãª ã¬ãã«ã§ã®ãããã¯ããã€ãã¹ããããšãã§ããŸãã
ãã®ãããã³ã«ã¯ãã¯ã©ã€ã¢ã³ããšãµãŒããŒéã® DNS ãã©ãã£ãã¯ãæå·åæ§é ã§ã©ããããUDP ããã³ TCP ãã©ã³ã¹ããŒã ãããã³ã«äžã§åäœããŸãã ããã䜿çšããã«ã¯ãã¯ã©ã€ã¢ã³ããš DNS ãªãŸã«ããŒã®äž¡æ¹ã DNSCrypt ããµããŒãããŠããå¿
èŠããããŸãã ããšãã°ã2016 幎 152 æ以éãDNS ãµãŒããŒãš Yandex ãã©ãŠã¶ãŒã§æå¹ã«ãªã£ãŠããŸãã Google ã Cloudflare ãªã©ãä»ã®ããã€ãã®ãããã€ããŒããµããŒããçºè¡šããŠããŸãã æ®å¿µãªããããã®æ°ã¯ããã»ã©å€ããããŸãã (å
¬åŒ Web ãµã€ãã«ã¯ XNUMX ã®ãããªã㯠DNS ãµãŒããŒããªã¹ããããŠããŸã)ã ããããããã°ã©ã ã¯
DNSCryptã¯ã©ã®ããã«æ©èœããŸãã? ã€ãŸããã¯ã©ã€ã¢ã³ãã¯éžæãããããã€ããŒã®å
¬éããŒãååŸããããã䜿çšããŠèšŒææžãæ€èšŒããŸãã ã»ãã·ã§ã³ã®çæå
¬éããŒãšæå·ã¹ã€ãŒãèå¥åã¯ãã§ã«ååšããŸãã ã¯ã©ã€ã¢ã³ãã¯ãªã¯ãšã¹ãããšã«æ°ããããŒãçæããããšãæšå¥šããããµãŒããŒã¯ããŒãå€æŽããããšãæšå¥šãããŸãã 24æéããšã ããŒã亀æããå Žåã眲åã«ã¯ EdDSAããããã¯æå·åã«ã¯ XSalsa25519-Poly20 ãŸã㯠XChaCha1305-Poly20 ãšããŠãX1305 ã¢ã«ãŽãªãºã ã䜿çšãããŸãã
ãããã³ã«éçºè
ã®äžäººããã©ã³ã¯ã»ããã¹
ãŸããã»ãã¥ãªãã£ã®é¢ã§éåžžã«åœ¹ç«ã¡ãŸãããµãŒããŒã䟵害ãããããããŒãæŒæŽ©ãããããå Žåãæšæ¥ã®ãã©ãã£ãã¯ã埩å·åã§ããªããªããŸãã ããŒã¯ãã§ã«å€æŽãããŠããŸãã ããã¯ããããã€ããŒã«æå·åãã©ãã£ãã¯ãå«ããã¹ãŠã®ãã©ãã£ãã¯ã®ä¿åã矩åä»ããã€ããã€æ³ã®æœè¡ã«åé¡ãåŒãèµ·ããå¯èœæ§ããããŸãã ããã¯ãå¿ èŠã«å¿ããŠãµã€ãããããŒãèŠæ±ããããšã§åŸã§åŸ©å·åã§ããããšãæå³ããŸãã ããããã®å Žåããµã€ãã¯çæéã®ããŒã䜿çšããå€ãããŒãåé€ãããããåçŽã«ããŒãæäŸã§ããŸããã
ããããæãéèŠãªããšã¯ãçæããŒã«ãããµãŒããŒã¯åæ¥ããèªååãã»ããã¢ããããå¿ èŠãããããšã ãšãããã¹æ°ã¯æžããŠããŸãã ãµãŒããŒããããã¯ãŒã¯ã«æ¥ç¶ããŠããŠãããŒå€æŽã¹ã¯ãªãããèšå®ãããŠããªãããŸãã¯æ©èœããŠããªãå Žåãããã¯ããã«æ€åºãããŸãã
èªååã«ãã£ãŠéµãæ°å¹Žããšã«å€æŽããããšããã®éµã¯ä¿¡é Œã§ããªããªãã蚌ææžã®æå¹æéãå¿ããŠããŸãå¯èœæ§ããããŸãã æ¯æ¥ããŒãå€æŽãããšãããã¯å³åº§ã«æ€åºãããŸãã
åæã«ãèªååãæ£åžžã«æ§æãããŠããå Žåã¯ãæ¯å¹ŽãååæããšããŸã㯠24 æ¥ XNUMX åãªã©ãããŒãå€æŽããé »åºŠã¯é¢ä¿ãããŸããã ãã¹ãŠã XNUMX æé以äžæ©èœããã°ãæ°žä¹ ã«æ©èœãããšãã©ã³ã¯ ããã¹ã¯æžããŠããŸãã åæ°ã«ãããšããããã³ã«ã®ç¬¬ XNUMX ããŒãžã§ã³ã§ã®æ¯æ¥ã®ã㌠ããŒããŒã·ã§ã³ã®æšå¥šãšããããå®è£ ããæ¢è£œã® Docker ã€ã¡ãŒãžã«ãããæå¹æéãåãã蚌ææžãæã€ãµãŒããŒã®æ°ãå¹æçã«åæžãããåæã«ã»ãã¥ãªãã£ãåäžããŸããã
ãã ããäžéšã®ãããã€ããŒã¯ãæè¡çãªçç±ããã蚌ææžã®æå¹æéã 24 æé以äžã«èšå®ããããšã決å®ããŠããŸãã ãã®åé¡ã¯ãdnscrypt-proxy ã®æ°è¡ã®ã³ãŒãã§å€§éšåã解決ãããŸããããŠãŒã¶ãŒã¯ã蚌ææžã®æå¹æéãåãã 30 æ¥åã«æ å ±èŠåãåãåããæå¹æéã® 7 æ¥åã«ããéèŠåºŠã®é«ãå¥ã®ã¡ãã»ãŒãžãåãåãã蚌ææžã«æ®ããããå Žåã¯éèŠãªã¡ãã»ãŒãžãåãåããŸããæå¹æé㯠24 æé以å ã§ãã ããã¯ãæåããæå¹æéãé·ã蚌ææžã«ã®ã¿é©çšãããŸãã
ãããã®ã¡ãã»ãŒãžã«ããããŠãŒã¶ãŒã¯æé ãã«ãªãåã«ã蚌ææžã®æå¹æéãè¿«ã£ãŠããããšã DNS ãªãã¬ãŒã¿ãŒã«éç¥ããæ©äŒãåŸãããŸãã
ããããããã¹ãŠã® Firefox ãŠãŒã¶ãŒããã®ãããªã¡ãã»ãŒãžãåãåã£ãå Žåããããã誰ããéçºè ã«éç¥ãã蚌ææžã®æéåããèš±å¯ããªãã§ãããã ããããªã㯠DNS ãµãŒããŒã®ãªã¹ãã«ãã DNSCrypt ãµãŒããŒã§ãéå» XNUMX ïœ XNUMX 幎éã«èšŒææžã®æå¹æéãåãããã®ã¯ XNUMX ã€ãèŠããŠããŸããããš Frank Denis æ°ã¯æžããŠããŸãã ãããã«ãããèŠåãªãã«æ¡åŒµæ©èœãç¡å¹ã«ããããããæåã«ãŠãŒã¶ãŒã«èŠåããæ¹ãããã§ãããã
åºæïŒ habr.com