Ukuqhekezwa kweziseko zophuhliso ze-matrix.org

[:en]

Abaphuhlisi beqonga lemiyalezo yeMatrix basasazwa amagunya kwaziswa malunga nokuvalwa okungxamisekileyo kweeseva matrix.org и I-Riot.im (Umxumi ophambili weMatrix) ngenxa yokuqhekezwa kwezibonelelo zeprojekthi. Ukucima kokuqala kwenzeke phezolo, emva koko iiseva azizange zifumaneke ibuyiselwe, kwaye izicelo zakhiwa ngokutsha kwimithombo yolwazi. Kodwa kwimizuzu embalwa edlulileyo abancedisi babe usengozini okwesibini.

Abahlaseli iposwe ngokuyintloko iphepha leprojekthi ulwazi oluneenkcukacha malunga noqwalaselo lweseva kunye nedatha kubukho besiseko sedatha esinehashes eziphantse zibe zizigidi ezihlanu ezinesiqingatha zabasebenzisi beMatrix. Njengobungqina, igama eliyimfihlo lenkokeli yeprojekthi yeMatrix iyafumaneka esidlangalaleni. Ikhowudi yesayithi etshintshiweyo iposwe kwindawo yokugcina i-GitHub yabahlaseli (kungekhona kwindawo yokugcina i-matrix esemthethweni). Iinkcukacha malunga ne-hack yesibini ukuza kuthi ga ngoku engekhoyo.

Emva koqhaqho lokuqala liqela leMatrix, yapapashwa ingxelo, ebonisa ukuba i-hack yenziwe ngobuthathaka kwi-Jenkins engahlaziyo inkqubo yokudibanisa eqhubekayo. Emva kokufumana ukufikelela kumncedisi weJenkins, abahlaseli babamba izitshixo ze-SSH kwaye bakwazi ukufikelela kwezinye iiseva zeziseko. Kwaxelwa ukuba ikhowudi yomthombo kunye neephakheji azizange zichaphazeleke kuhlaselo. Uhlaselo aluzange luchaphazele iiseva zeModular.im. Kodwa abahlaseli bafumana ukufikelela kwi-DBMS ephambili, equlethe, phakathi kwezinye izinto, imiyalezo engabhalwanga, amathokheni okufikelela kunye ne-password hashes.

Bonke abasebenzisi bayalelwa ukuba batshintshe amagama abo ayimfihlo. Kodwa ngexesha lenkqubo yokutshintsha amagama ayimfihlo kumthengi ophambili weRiot, abasebenzisi ubuso ngokulahleka kweefayile ezineekopi ezigcinayo zezitshixo zokubuyisela imbalelwano efihliweyo kunye nokungakwazi ukufikelela kwimbali yemiyalezo edlulileyo.

Masikukhumbuze ukuba iqonga lokuququzelela unxibelelwano olunatyisiweyo Matrix iboniswa njengeprojekthi esebenzisa imigangatho evulekileyo kwaye inika ingqwalasela enkulu ekuqinisekiseni ukhuseleko kunye nobumfihlo babasebenzisi. I-Matrix ibonelela ngesiphelo ukuya-kwisiphelo soguqulelo oluntsonkothileyo olusekwe kwiprothokholi yayo, kuquka i-algorithm ye-Double Ratchet (ekwasetyenziswa njengenxalenye yoMqondiso woMqondiso), ixhasa uphendlo kunye nokujongwa okungenamkhawulo kwembali yembalelwano, ingasetyenziselwa ukudlulisa iifayile, ukuthumela izaziso, ukuvavanya. ubukho bomphuhlisi kwi-intanethi, eququzelela ii-teleconferences, ukwenza iifowuni zelizwi kunye nevidiyo. Ikwaxhasa iimpawu eziphambili ezifana nezaziso zokuchwetheza, ukuqinisekiswa kokufunda, izaziso zokutyhala kunye nokukhangela kwe-server-side, ungqamaniso lwembali yomxhasi kunye nesimo, iindlela ezahlukeneyo zokuchonga (i-imeyile, inombolo yefowuni, i-akhawunti ye-Facebook, njl.).

Ukongezwa: Papashwe ngomhla iqhubekile nenkcazelo yoqheliso lwesibini, ulwazi malunga nokuvuza kwezitshixo ze-PGP, kunye nesishwankathelo seengxaki zokhuseleko ezikhokelele kuqhekezo.

Umthomboopennet.ru

[: zu]

Abaphuhlisi beqonga lemiyalezo yeMatrix basasazwa amagunya kwaziswa malunga nokuvalwa okungxamisekileyo kweeseva matrix.org и I-Riot.im (Umxumi ophambili weMatrix) ngenxa yokuqhekezwa kwezibonelelo zeprojekthi. Ukucima kokuqala kwenzeke phezolo, emva koko iiseva azizange zifumaneke ibuyiselwe, kwaye izicelo zakhiwa ngokutsha kwimithombo yolwazi. Kodwa kwimizuzu embalwa edlulileyo abancedisi babe usengozini okwesibini.

Abahlaseli iposwe ngokuyintloko iphepha leprojekthi ulwazi oluneenkcukacha malunga noqwalaselo lweseva kunye nedatha kubukho besiseko sedatha esinehashes eziphantse zibe zizigidi ezihlanu ezinesiqingatha zabasebenzisi beMatrix. Njengobungqina, igama eliyimfihlo lenkokeli yeprojekthi yeMatrix iyafumaneka esidlangalaleni. Ikhowudi yesayithi etshintshiweyo iposwe kwindawo yokugcina i-GitHub yabahlaseli (kungekhona kwindawo yokugcina i-matrix esemthethweni). Iinkcukacha malunga ne-hack yesibini ukuza kuthi ga ngoku engekhoyo.

Emva koqhaqho lokuqala liqela leMatrix, yapapashwa ingxelo, ebonisa ukuba i-hack yenziwe ngobuthathaka kwi-Jenkins engahlaziyo inkqubo yokudibanisa eqhubekayo. Emva kokufumana ukufikelela kumncedisi weJenkins, abahlaseli babamba izitshixo ze-SSH kwaye bakwazi ukufikelela kwezinye iiseva zeziseko. Kwaxelwa ukuba ikhowudi yomthombo kunye neephakheji azizange zichaphazeleke kuhlaselo. Uhlaselo aluzange luchaphazele iiseva zeModular.im. Kodwa abahlaseli bafumana ukufikelela kwi-DBMS ephambili, equlethe, phakathi kwezinye izinto, imiyalezo engabhalwanga, amathokheni okufikelela kunye ne-password hashes.

Bonke abasebenzisi bayalelwa ukuba batshintshe amagama abo ayimfihlo. Kodwa ngexesha lenkqubo yokutshintsha amagama ayimfihlo kumthengi ophambili weRiot, abasebenzisi ubuso ngokulahleka kweefayile ezineekopi ezigcinayo zezitshixo zokubuyisela imbalelwano efihliweyo kunye nokungakwazi ukufikelela kwimbali yemiyalezo edlulileyo.

Masikukhumbuze ukuba iqonga lokuququzelela unxibelelwano olunatyisiweyo Matrix iboniswa njengeprojekthi esebenzisa imigangatho evulekileyo kwaye inika ingqwalasela enkulu ekuqinisekiseni ukhuseleko kunye nobumfihlo babasebenzisi. I-Matrix ibonelela ngesiphelo ukuya-kwisiphelo soguqulelo oluntsonkothileyo olusekwe kwiprothokholi yayo, kuquka i-algorithm ye-Double Ratchet (ekwasetyenziswa njengenxalenye yoMqondiso woMqondiso), ixhasa uphendlo kunye nokujongwa okungenamkhawulo kwembali yembalelwano, ingasetyenziselwa ukudlulisa iifayile, ukuthumela izaziso, ukuvavanya. ubukho bomphuhlisi kwi-intanethi, eququzelela ii-teleconferences, ukwenza iifowuni zelizwi kunye nevidiyo. Ikwaxhasa iimpawu eziphambili ezifana nezaziso zokuchwetheza, ukuqinisekiswa kokufunda, izaziso zokutyhala kunye nokukhangela kwe-server-side, ungqamaniso lwembali yomxhasi kunye nesimo, iindlela ezahlukeneyo zokuchonga (i-imeyile, inombolo yefowuni, i-akhawunti ye-Facebook, njl.).

Ukongezwa: Papashwe ngomhla iqhubekile nenkcazelo yoqheliso lwesibini, ulwazi malunga nokuvuza kwezitshixo ze-PGP, kunye nesishwankathelo seengxaki zokhuseleko ezikhokelele kuqhekezo.

umthombo: opennet.ru

[:]

Yongeza izimvo