ãã¹ãŠã®äººã«è¯ãäžæ¥ãïŒ
ãã®ããŒãã®ç·šéã«åºã¥ããŠãè³æãžã®2ã€ã®ãªã³ã¯ãããã«æäŸããããšæããŸãã ãœãŒã¹ãçŽæ¥ç¥ãããããã¯ãèªãããšã¯ã§ããŸãããããã¯ç§ã®ç¡æ翻蚳ã§ãããå°éã®ã®ã£ã°ã§äž»èŠãªãã€ã³ããèªã¿çŽããŸãã
BlackHat USA 2011ïŒSSLãšæªæ¥ã®çæ£æ§
Moxie Marlinspike ::ããã°-SSL and The Future of Authenticity
å ¥é
æ°æ¥åãSSL / TLS蚌ææžã®ååŸã«é¢ããèšäºããããŸããã ããããç§ã®ã³ã¡ã³ãã¯ãããã«å¯Ÿããã³ã¡ã³ãããã®äž»é¡åéã®è°è«ãã®ãã®ããããã¯ããããã®äžåšã«ãã£ãŠã§ã¯ãªããèšäºèªäœã«ãã£ãŠã§ã¯ãããŸããã§ããã ç§ã¯ãã®å Žã§è°è«ãéå§ãããåé¡ã解決ããããã®ãªãã·ã§ã³ãšäžç·ã«åé¡ã匷調ããã³ã¡ã³ãã§å šäœãè°è«ããããšãã§ããå¥ã®ãããã¯ãæã€ããšãçã«ããªã£ãŠãããšå€æããŸããã
äžèšã®èšäºããã®ã³ã¡ã³ããããã€ãåŒçšããŸãããã
蚌ææžã¯èªç©ºååŒã®åªããäŸã§ãã ãããŠãããªãçŸå®çãªãéã®ããã«ãäœãä¿èšŒãããäœã«å¯ŸããŠãä¿è·ããªããã€ãã®ã»ãããååŸããŸã....ïŒcïŒangry_elfããã«å¯ŸããçãïŒ
MiMä¿è·ãªãã·ã§ã³ãæäŸããŸãïŒ ãã®åŸãããªãã¯ç©ºäžã§ååŒããããäœãããå¿ èŠããªãã»ã©è±ãã§äººæ°ããããŸãã ïŒcïŒokazymyrovããŸããå€ãã®ã³ã¡ã³ãããããŸããããããã®ã³ã¡ã³ãããã次ã®ãããã¯ãåé¡ã質åã«ã€ããŠã¯ãŸã 人ã ãæ°ã«ããŠããããšãæããã§ãã
- 蚌ææžååŒ-èªç©ºååŒïŒ äœã®ããã«ãéãæãã®ã§ããïŒ
- èªèšŒå±ïŒCAïŒã¯ãå²ãåœãŠããã責任ã«å¯Ÿå¿ããŠãããå®éã®ä¿è·ãæäŸãããšæ³å®ã§ããŸããããŸãã¯ããã«çåãåããããšãã§ããŸããïŒ
- é°æ¹¿ãªäžéè ãã身ãå®ãããã«ããžã£ã³ãã®ã¢ãªã¹ãšããã«äœããã¹ããïŒ
ãããã¯ãè¡šé¢çã«ãããæ·±ããããå€ãã®è³ªåã«ãããŸããã èŠãŠã¿ãŸãããã
çè«ã®ããã
ã€ã³ã¿ãŒãããäžã®ããŒãéã§ã®ããŒã¿ã®å®å šãªéä¿¡ã¯ãHTTPSãããã³ã«ïŒHTTPãããã³ã«æ¡åŒµïŒãä»ããŠè¡ãããéä¿¡ãããããŒã¿ã¯SSL / TLSæå·åãããã³ã«ïŒTLSã¯SSL 3.0ã«åºã¥ããŠéçºãããæšæºïŒã«ã«ãã»ã«åãããé察称ã¢ã«ãŽãªãºã ã®äœ¿çšã«åºã¥ããŠããŸãå ¬ééµæå·å-RSAã é察称æå·åã®äžè¬çãªåé¡ã¯ãå ¬éããŒã®ä¿¡é Œæ§ãæ€èšŒããããšãé£ããããšã§ãã ãããã£ãŠãå ¬ééµã¢ã«ãŽãªãºã ã«åºã¥ããã¹ãŠã®æå·åãããã³ã«ã§ã¯ãä¿¡é Œã®åé¡ãæ ¹æ¬çã«éèŠã§ãã ã€ãŸãããµãŒããŒããåä¿¡ããå ¬éããŒãããã¹ãŠã®HTTPSãã©ããããäžéè ãããã¯ãŒã¯ã»ã°ã¡ã³ãã«ããããŒã§ã¯ãªããå®éã«ãµãŒããŒãå®å šãªéä¿¡ãã£ãã«ã確ç«ããããã«äœ¿çšããããŒã§ããããšã確èªããæ¹æ³sslsniffãžã®ãã©ãã£ãã¯ã ä¿¡é Œã®åé¡ããããŸãã
èªèšŒå±
æŽå²çã«ã圌ãã¯PKIïŒPublic Key InfrastructureïŒãªã©ã®èªèšŒæè¡ã䜿çšããŠä¿¡é Œã®åé¡ã解決ãå§ããŸããã ããã¯ãCAãä»ããŠå ¬éããŒããŠãŒã¶ãŒã®IDã«æ¥ç¶ããå æ¬çãªæž¬å®ã·ã¹ãã ã§ãã PKIã¯ãå ¬éããŒæå·åã·ã¹ãã ãšããã€ãã®åºæ¬ååã®äœ¿çšã«åºã¥ããŠããŸãã
- ç§å¯éµã¯ãã®ææè ã®ã¿ãç¥ã£ãŠããŸãã
- CAã¯å ¬ééµèšŒææžãäœæããããã«ãã£ãŠãã®éµãèªèšŒããŸãã
- 誰ããäºããä¿¡é ŒããŠããŸãããã誰ããCAãä¿¡é ŒããŠããŸãã
- CAã¯ã察å¿ããç§å¯ããŒãææããç¹å®ã®äººç©ã«å¯ŸããŠãå ¬éããŒã®æææš©ã確èªãŸãã¯åè«ããŸãã
å®éãPKIã¯CAãäž»èŠã³ã³ããŒãã³ããšããã·ã¹ãã ã§ããããŠãŒã¶ãŒã¯CAãä»ããŠçžäºã«å¯Ÿè©±ããŸãã
ããã¯æ¬¡ã®ããã«æ©èœããŸããããã¯ãã¢ãªã¹ãšä»ã®å人ã圌ãšå®å šãªæ¥ç¶ã確ç«ã§ããããã«ããããšèããŠããŸãã 圌ã¯ãå ¬ééµãšä»ã®ããŒã¿ïŒååãäœæãªã©-蚌ææžã«å«ãŸãããã¹ãŠïŒãšãšãã«CAã«æ¥ãŠãäœããã®æ¹æ³ã§èº«å ã確èªãïŒå€ãã®å Žåãåã«é»åã¡ãŒã«ã§ãããè¡ããŸãïŒããŒã CAã¯åœŒã«èšŒææžãçºè¡ããŸãã 次ã«ãBobã¯ãããå人ã«æž¡ããŸããå人ã¯ãå®å šã«ä¿¡é ŒããŠããCAã®ããžã¿ã«çœ²åããã§ãã¯ããããšã§ãBobã«æ¬åœã«å±ããŠããããšã確èªã§ããŸãã
åé¡
åé¡ã¯äœã§ããïŒ åé¡ã¯ã圌ããããªããä¿¡é Œãã人ãããªãã®ããã«æ±ºããããšã§ãã ãªãœãŒã¹ã®ææè ããããšãã°Comodoãã蚌ææžãåãåãããšã決å®ãããã®ç¬éã«-ããªããä¿¡é Œããªããã°ãªããªã人ãããªãã®ããã«æ±ºå®ããŸãã 誰ãã圌ã®ãªãœãŒã¹ã¯åœŒã®ããã§ããã蚌ææžãåãåãçžæã¯åœŒæ¬¡ç¬¬ã ãšèšããããããŸããã ã¯ãããã ãããŒã¿ã¯ïŒããšãã°ã¯ã¬ãžããã«ãŒãããŒã¿ïŒãã®ãªãœãŒã¹ã¯ããªãã®ãã®ã§ãïŒ ãããŠãããã圌女ã®æ¯èŠªã¯åé¡ã§ãïŒ èªèšŒã»ã³ã¿ãŒã®æ¢åã®ã·ã¹ãã ã®ä¿¡é Œæ§ã«èª°ãçåãåããã圌ããå®ç§ã«äœæ¥ãè¡ããªãããã¹ãŠãããŸãããã§ãããããããã§ã¯ãããŸããã UTã¯æ°éäŒæ¥ã§ãã圌ãã¯ãããªãèªèº«ã®å©å·±çãªå©çãè¿œæ±ããè³briãè è¿«ãè è¿«ãåããããšãã§ããããªãã«ç¥ãããŠããªãçããŠãã人ã ãéããŸãã CAã¯éšå€è ïŒå¥åããã«ãŒïŒã«ãã£ãŠäŸµå®³ãããå¯èœæ§ããããŸãã ä»å¹Žã®æ¥ïŒ link ïŒã«çºçããComodo CAã®éšã ãã話ãæãåºãããšãã§ããŸãããã®é
解決ç
ãåç¥ã®ããã«ã蚌ææžã€ã³ãã©ã¹ãã©ã¯ãã£ãç·šæããããã®ã¢ãã«ã«ã¯ãéäžåïŒPKIïŒãšåæ£åïŒããããä¿¡é Œãããã¯ãŒã¯-ä¿¡é Œã®Webã«åºã¥ããŠå®è£ ïŒã®2ã€ããããçŸåšPGP / GPGãããã¯ââãŒã¯ã§æãåºã䜿çšãããŠããŸãã éäžåã¢ãã«ã®ãã¹ãŠã®å©ç¹ã«ã€ããŠã¯äžèšã§èª¬æããŸããã åäžã®èªèšŒå ãååšããªãåæ£ã·ã¹ãã ã«ã€ããŠèããŠã¿ãŸããããéã«ãåãŠãŒã¶ãŒã¯ãä»ã®å ¬ééµã®èªèšŒãä¿¡é Œãã人ãšä¿¡é Œããªã人ãç¬èªã«æ±ºå®ããããã«ãã£ãŠå人ã®ä¿¡é Œãããã¯ãŒã¯ãäœæããŸãã ãã®ã¢ãããŒãã¯ãæªæã®ãã圱é¿ã«å¯Ÿããã·ã¹ãã ã®æè»æ§ãšå®å®æ§ãæäŸããŸããåæ£ã·ã¹ãã ã®1ã€ã®ããŒãã«åœ±é¿ãäžããããšãã§ããŸãïŒãã®å Žåãä¿¡é Œãããã¯ãŒã¯ããé€å€ããŸãïŒã
äžå€®éäžåã¢ãã«ãä¿®æ£ã§ããŸããããã«åºã¥ããŠããªãœãŒã¹èªäœãç¹å®ã®CAã§èšŒææžãèŠæ±ããããšã§ä¿¡é Œãéå§ããããã«ããããã¹ãŠã®é¡§å®¢ããã®ç¹å®ã®CAãšå¯Ÿè©±ããŠä¿¡é Œæ§ãæ€èšŒããåæ£åã¢ãããŒããé©çšããããšã矩åä»ããŸããã¯ã©ã€ã¢ã³ããéå§ããçžäºäœçšã¯æ¬¡ã®ãšããã§ãã
- ã¯ã©ã€ã¢ã³ãã¯ãç¹å®ã®ãµã€ããšã®å®å šãªéä¿¡ãã£ãã«ã確ç«ããããšèããŠããŸãã 圌ã¯ãã®ãµã€ãã«ã¢ã¯ã»ã¹ãã圌ããSSL蚌ææžãåãåããŸãã åé¡ã¯ãããã¯ãã®ãµã€ãã®èšŒææžãªã®ããäžéè ãããæãã蚌ææžãªã®ãïŒ ç¢ºèªããå¿ èŠããããŸãã
- ã¯ã©ã€ã¢ã³ãã¯ãèªåãäœæãã蚌ææžãµãŒããŒã®ãªã¹ãã«ç®ãéããããããã«ããã®ãµã€ãã§ã©ã®èšŒææžã衚瀺ãããŸããïŒããšå°ããŸãã
- ãµãŒããŒãªã¯ãšã¹ãã«å¿çããŠãæå®ããããµã€ãã«ã¢ã¯ã»ã¹ãããããã蚌ææžãåä¿¡ããèŠæ±å ã®ã¯ã©ã€ã¢ã³ãã«è»¢éããŠã眲åã確èªããŸãã
- ã¯ã©ã€ã¢ã³ãã¯ããµãŒããŒããçŽæ¥åãåã£ã蚌ææžãšèšŒææžãµãŒããŒããåãåã£ã蚌ææžãæ¯èŒããŸãã
- 蚌ææžãäžèŽããå Žå-ãã¹ãŠãæ£åžžã§ããã°ãç§ãã¡ã¯åããŸãã ãããã¯äžèŽããŸãããè¿ãã®ã©ãããäžéè ã§ãããåââé¡ãçºçããå¯èœæ§ããããŸãã
å®è£
å æåãã«ã©ã¹ãã¬ã¹ã§éå¬ãããBlackHatäŒè°ã§ãã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãã®ç 究çã§ããç¥ãããŠããMoxie Marlinspike㯠ã Convergence ïŒèªèšŒæ©é¢ã·ã¹ãã ã®ã¢ãžã£ã€ã«ãåæ£ãå®å šãªä»£æ¿ïŒãšåŒã°ãããããžã§ã¯ããçºè¡šããŸããã ã ãããžã§ã¯ãã®äžç°ãšããŠãèªèšŒãµãŒããŒã¯Notaryãšåä»ããããŸããã
FireFoxãã©ã°ã€ã³ãããŒãã³ã°ããŠã€ã³ã¹ããŒã«ããŸã-onvergence ïŒ
å ¬èšŒäººãªã¹ããäœæããŸãã ãããè¡ãã«ã¯ãæ¢åã®ãµãŒããŒã®ãªã¹ãã䜿çšã§ããŸã-Notary list ãNotary-serversãäžããããšãã§ããŸã-Running -a-Notary ãæåãš2çªç®ãè¡ãããšãã§ããŸãã
ã·ã¹ãã èšå®ã®æ©èœ-æ€èšŒãããå€ãªãã·ã§ã³ãå€æŽããããšã«ãããåŠæ³ã®ãããå€ã調æŽã§ããŸãã
以åã¯ãåŸæ¥ã®èªèšŒæ©é¢ã·ã¹ãã ã®äœ¿çšã¯æ¬¡ã®ãšããã§ããã
ãã©ã°ã€ã³ãã¢ã¯ãã£ãã«ããConvergenceã«ç§»åããŸãã
ããŠããªããšïŒ
- ãµã€ã管çè ã¯ãµãŒããŒåŽã§äœãããå¿ èŠã¯ãããŸããã ã€ã³ã¿ãŒãããã®æ°ããèªèšŒã·ã¹ãã ãžã®ç§»è¡ãæé ããå¿ èŠã¯ãããŸããã ãã¹ãŠããã§ã«æ©èœããŠããããããã¹ãŠã®äž»èŠãªãã©ãŠã¶ã«ãã©ã°ã€ã³ãå®è£ ããã ãã§ãã
- ã¯ã©ã€ã¢ã³ãã¯èªåã誰ã«çœ²åããããæ°ã«ããªããããèªå·±çœ²å蚌ææžã«é¢ããèŠåã¯ãããããŸãããã¯ã©ã€ã¢ã³ãã¯ãMan-In-The-Middleã§ã¯ãªããµãŒããŒã«ãã£ãŠæäŸããã蚌ææžã䜿çšããããšã確èªããããšãéèŠã§ãã
ãããã«
誰ãä¿¡é Œããå¿ èŠããããŸããïŒ
...ãããŠã©ããããã®æéïŒ
å®ããããäžé£ã®äººã ã
ãŸãã¯ãåæãè©Šãæéã§ããïŒ