ç®æ¬¡ã
- ãªããããå¿ èŠã§ãã
- ãããã€ããŒã¯ç§ãã¡ãèŠãŠããŸã
- ãµãŒãã¹ãããã€ããŒã«ãã£ãŠç£èŠãããŠããŸãã
- ã€ã³ã¿ãŒãããã®å¿åæ§
- Webãµã€ãã®ç»é²èŠå
- ãã©ãŠã¶èšå®
- PGPæå·åã䜿çšãã
- ã»ã«ããã¹ããµãŒãã¹ã®äœ¿çš
- ããŒãã¹
- åç §è³æ
ãªããããå¿ èŠã§ãã
ãããã€ããŒã¯ç§ãã¡ãèŠãŠããŸã
æå·åãããŠããªã圢åŒã§éä¿¡ããããã¹ãŠã®ãã®ãååããã³å€æŽã§ããŸãïŒã¯ã©ã·ãã¯MitM ïŒã ãŸããåœç€Ÿã®ãããã€ããŒã¯ãMACã¢ãã¬ã¹ãšã¯ã©ã€ã¢ã³ãå¥çŽã®æ£ç¢ºãã§ãªã¯ãšã¹ããç°¡åã«èå¥ã§ããŸãã
ãããã€ããŒããã®ãããªããšãæ±ã£ãŠããªãå Žåã§ãããã®ããŒã¿ã»ã³ã¿ãŒã«ã¯ç¢ºãã«ãäžå®éã®ãã©ãã£ãã¯ããã©ãŒãªã³ã°ãããç®ç«ããªããµãŒããŒããããŸãã ããã¯SORMãµãŒããŒã§ãã SORMã®ãµãã©ã€ã€ä»¥å€ã®èª°ã«ãäžæãªç¹ããããŸã
ãµãŒãã¹ææè ããã©ããŒããŠããŸãã
ä»äºãå人ã®ã¡ãŒã«ãèªãããã«gmailã䜿çšããå ŽåããŸãã¯chromeãã©ãŠã¶ã䜿çšããå ŽåãGoogle Corporationãã©ãã«è¡ã£ãŠäœãæžããŠãããã«é¢ããæ å ±ãåéããããšã¯éåžžã«äŸ¿å©ã§ãã
ãã·ã¢ã®ãµãŒãã¹ã§ãåãããšãèšããŸããYandexKriptãæãåºããŠãã ãããVKã¯äžè¬ã«ãŠãŒã¶ãŒæ å ±ã®æž©åºã§ãã
ãŸãããœãŒã·ã£ã«ãããã¯ãŒã¯ã«ãã°ã€ã³ããŠã³ã¡ã³ããæ®ãããšãã§ããäœçŸãã®ãµã€ããæãåºããŠãã ããã
ãã¡ãããããã¯ãæ£ããåºåãããã£ãšèŠããããã ãã«è¡ãããŠããŸããã誰ãå°æ¥äœãèµ·ãããç¥ã£ãŠããŸãã
ã€ã³ã¿ãŒãããã§åŸããã®ã¯æ°žé ã«ããã«ãšã©ãŸã
ã€ã³ã¿ãŒãããã®å¿åæ§
ã€ã³ã¿ãŒãããã§å¿åæ§ãç¶æããå¿ èŠãããçç±ãããã£ãã®ã§ããããã©ã®ããã«éæã§ããããèŠãŠã¿ãŸãããã
ã€ã³ã¿ãŒããããµãŒãã¹ã®å©çšèŠçŽ
åŠæ³æ§ãå¢ãã«ã€ããŠãŸãšããããæ å ±
- å®å/å§/ç幎ææ¥ã䜿çšããªãã§ãã ãã
- ã©ãã§ãåããã¹ã¯ãŒãã䜿çšããªãã§ãã ããïŒ1ã€ãç Žã-ãã¹ãŠãç ŽãïŒ
- å¯èœã§ããã°ãç°ãªãããã¯ããŒã ãç°ãªãçš®é¡ã®ã¢ã¯ãã£ããã£ãæã€è€æ°ã®ã¢ã«ãŠã³ãã䜿çšããŸã
- ãµã€ããã¡ãŒã«ã§å ¬éãã¹ã¯ãŒããéä¿¡ããå Žåãããã¯æªããµã€ãã§ãã 圌ãã¯ããªãã®ãã¹ã¯ãŒããæå·åããã«ä¿æããŸããã€ãŸãã圌ãã¯èªåã§ãããç¥ã£ãŠãããçãæ©äŒã売ã/äžããããšãã§ããŸãã
- å¯èœã§ããã°ãç»é²äžã«ã·ãŒã¯ã¬ããã¢ãŒãã䜿çšããéèŠãªãµã€ãïŒéè¡ã¯ã©ã€ã¢ã³ããµã€ããè¶ å€§åã®éèŠãªãã°ãã©ãã«ãŒãªã©ïŒã«ãã°ã€ã³ããŸã
- åçãã¢ããããŒãããå Žåã¯ããŸãã¡ã¿ããŒã¿ã®æå³ããªããã©ããã確èªããå¿ èŠããããŸã
- ãªãŒãã³ãã£ãã«ãä»ããŠç§å¯ããŒã¿ã転éããå¿ èŠãããå Žåã¯ãpgpã䜿çšããŠäºåæå·åãå®è¡ããããç°ãªããã£ãã«ã®äžéšã§æ å ±ãéä¿¡ã§ããŸãã Skypeçµç±ã§ãã°ã€ã³ã転éãããã¹ã¯ãŒããçŽæ¥äŒããwhatsappçµç±ã§ã¢ãã¬ã¹ãéä¿¡ã§ããŸãã
- HTTPSãããå Žåã«ã®ã¿ãã°ã€ã³ããŠç»é²ããŸãïŒ
- ip-shnikãç §ãããªãããã«ãVPNã䜿çšããŠãã°ã€ã³ããŠç»é²ããŸã
ãã©ãŠã¶èšå®
- ãã©ãŠã¶ã¯ãã¹ã¯ãŒããèŠããŠã¯ãããŸãã
- ãã©ãŠã¶ã¯ãå±¥æŽ/ Cookie /ãã¹ã¯ãŒãããã³ãã®ä»ã®æ å ±ãã€ã³ã¿ãŒãããäžã®äžæãªãµãŒããŒãšåæããªãã§ãã ãã
- ãã©ãŠã¶ã¯åèµ·åã®éã«ã¯ãããŒãä¿åããã¹ãã§ã¯ãããŸãã
- ã¯ããã«
Firefoxã®èšå®äŸ
ã¢ãã¬ã¹ããŒã®èšå®ã«ç§»åããŠããã©ã€ãã·ãŒã«åœ±é¿ãããªãã·ã§ã³ã®ãªã¹ãã匷åããŸã
- media.peerconnection.enabled = false-WebRTCãããã³ã«ã®ãµããŒããçŠæ¢ããŸããWebRTCãããã³ã«ã®çŸåšã®å®è£ ã§ã¯ãããŒã«ã«ãããã¯ãŒã¯äžã®IPã¢ãã¬ã¹ã®ãªã¹ããïŒJavaScriptã䜿çšããŠïŒåå¥ã«åä¿¡ã§ããããããŠãŒã¶ãŒã®äžææ§ãåäžããŸãã
- browser.safebrowsing.enabled = falseããã³browser.safebrowsing.malware.enabled = false-蚪åããWebãµã€ãã«é¢ããæ å ±ã®Googleãžã®éä¿¡ãç¡å¹ã«ããŸãããã®ããŒã¿ããŒã¹ã¯ãäžæ£ãªWebãµã€ãã«é¢ããèŠåã«äœ¿çšãããŸãã
- browser.search.suggest.enabled = false-ãŠãŒã¶ãŒããã®æ瀺çãªç¢ºèªãªãã«ãæ€çŽ¢ãŠã£ã³ããŠã«å ¥åãããããã¹ãã®æ€çŽ¢ãšã³ãžã³ãžã®éä¿¡ãç¡å¹ã«ããŸãã ãªã¯ãšã¹ããå ¥åãããšæ€çŽ¢ãšã³ãžã³ããã®åè£ã¯å€±ãããŸãããçªç¶ã¯ãšãªã®å ¥åãéå§ããŠæ°ãå€ãã£ãå Žåã¯ãEnterããŒãæŒããŸã§ç§»åããŸããã
- dom.enable_performance = false-ãã©ãŠã¶ãŒãããŒãžã®èªã¿èŸŒã¿ã®éå§æéãšçµäºæéã«é¢ããæ å ±ãéä¿¡ã§ããªãããã«ããŸãã ãã®ããŒã¿ã®åæã«ããããããã·ãµãŒããŒã䜿çšããäºå®ãå€æã§ããŸãã
- network.dns.disablePrefetch = true-WebããŒãžäžã®ãã¹ãŠã®ãªã³ã¯ã®DNSåã®äºåçãªè§£æ±ºãçŠæ¢ããŸãïŒãŠãŒã¶ãŒããªã³ã¯ãã¯ãªãã¯ãããŸã§ïŒã ããã«ãããå¿åãããã·ãµãŒããŒãä»ããŠäœæ¥ããŠãããšãã«DNSãã©ãã£ãã¯ãæŒæŽ©ããå¯èœæ§ããããŸãã
- network.proxy.socks_remote_dns = true-ãããã·ã䜿çšããå Žåããããã·ãä»ããŠDNSã¯ãšãªãéä¿¡ããŸãã ãã以å€ã®å Žåããããã¯çŽæ¥ç§»åããå®éã®IPã¢ãã¬ã¹ã®é瀺ã«ã€ãªããå¯èœæ§ããããŸãã
- dom.battery.enabled = false-ããããªãŒã®ç¶æ ã®ç£èŠãçŠæ¢ããŸãã
- dom.network.enabled = false-ãããã¯ãŒã¯ãžã®æ¥ç¶ãã©ã¡ãŒã¿ãŒã®æ±ºå®ãçŠæ¢ããŸãïŒãã®å Žåãæ¥ç¶ã®ã¿ã€ãã¯è»¢éãããŸãïŒLANãWifiã3Gãªã©ïŒã
- network.proxy.no_proxies_on =ïŒç©ºã®å€ïŒ-ãµã€ããããŒã«ã«ãã·ã³ã«ã¢ã¯ã»ã¹ã§ããªãããã«ããŸããããã«ãããéããŠããããŒãã®ãªã¹ããåæã§ããããã«ãªããŸãã
PGPæå·åã䜿çšãã
ãã¡ã€ã«ãå®å šã«è»¢éããå Žåã¯ãæå·åã䜿çšããããšã匷ããå§ãããŸãã ããšãã°ãgpg / pgp
æå·åãããã¬ã¿ãŒãŸãã¯ãã¡ã€ã«ãåãåã£ãŠãpgpããŒã§çœ²åãã人ã¯ãåœç©ã§ã¯ãªããéä¿¡è ãæå®ããåä¿¡è ã®ã¿ããããèªãããšãã§ããããšã100ïŒ ç¢ºä¿¡ã§ããŸãã ãããã£ãŠããããã³ã°äžã«ã¡ãŒã«ããã¯ã¹ã«å®å šã«ã¢ã¯ã»ã¹ããå Žåã§ããã¡ãŒã«ã®ã»ãã¥ãªãã£ãå€§å¹ ã«åäžããæ»æè ãããŒã¿ãååŸããããšã¯ããå°é£ã«ãªããŸãã
æå·å
ä»»æã®ãã¡ã€ã«ãåçŽã«æå·åã§ããŸãã ãããè¡ãã«ã¯ã次ã®ã³ãã³ããå ¥åããŸãã
gpg -c file
ã·ã¹ãã ã¯ãã¹ã¯ãŒãã2åèŠæ±ããŸãã ãã®çµæããœãŒã¹ãã¡ã€ã«ã®è¿ãã«æ¡åŒµå.gpgãæã€æ°ãããã¡ã€ã«ãååŸããŸãã ããšãã°ãfile.gpgã 埩å·åãéåžžã«ç°¡åã§ãã
gpg file
ãã¹ã¯ãŒããå ¥åããåŸããœãŒã¹ãã¡ã€ã«ãååŸããŸãã
é察称æå·åãšçœ²å
ããå°ãè€éãªæé ã ããã«ã¯2ã€ã®ããŒãå«ãŸããŸãã ç§ãã¡ã ãã«ç¥ãããä»ã®èª°ã«ãç¥ãããŠããªãç§ãã¡ã®å人çãªç§å¯ã®äžã€ã å人ã䟿å©ãªæ¹æ³ã§é åžããå¥ã®å ¬éã ãã®ãªãã·ã§ã³ãšæãé »ç¹ã«äœ¿çšãããã®ã¯ã æåã®ããŒãžã§ã³ã§ã¯ãæå·åããããã¡ã€ã«ã«å ããŠããã¹ã¯ãŒãããã®ãã¡ã€ã«ã«è»¢éããå¿ èŠãããããã¹ã¯ãŒããååãããªããšããä¿èšŒã¯ãããŸããã
ãã®ãããã¯ã¯RuNetã§åãäžããããŸãã-1 〠ã 2ã€
次ã«ãèšäºã®ç¬¬2éšã«é²ã¿ãŸããããã§ã¯ã人æ°ã®ããGoogleã¡ãŒã«ãRSSãªãŒããŒãªã©ãã©ã®ããã«ãã©ã®ããã«çœ®ãæããããšãã§ãããã説æããŸãã
ã»ã«ããã¹ããµãŒãã¹ã®äœ¿çš
Googleã®ã«ã¬ã³ããŒãšé£çµ¡å ã䜿çšããéä¿¡ãYandex-mailã«ä¿åããevernoteã«ã¡ã¢ãæžãããã¡ã€ã«ãdropboxã«å ¥ãããšãå¿åã§ã€ã³ã¿ãŒãããããèŠããªãããã«ããããšããè©Šã¿ã¯ãã¹ãŠç¡æå³ã§ãã
ã€ã³ã¿ãŒããããµãŒãã¹ãç§ãã¡ãã¹ãã€ããªãããã«ããã«ã¯ãã€ã³ã¿ãŒããããµãŒãã¹ã®äœ¿çšãåæ¢ããå¿ èŠããããŸãã
è¡ããŸããã
ã¢ããªã±ãŒã·ã§ã³ããã¹ãããã«ã¯ãå¿åã®æ¯æãïŒãããã³ã€ã³ãŸãã¯é¡äŒŒã®ãã®ïŒãåããvpsãšæå·åããããã©ã€ãïŒãããå¯èœã«ããKVMãXENãããã³ãã®ä»ã®ä»®æ³åïŒãå¿ èŠã§ãã
å€éšIPã¢ãã¬ã¹ãvpsããã³dnsåã§è³Œå ¥ã§ããŸãã
æãé »ç¹ã«äœ¿çšãããã®ã¯äœã§ããïŒ
éµäŸ¿
ã¡ãŒã«ãã³ãã«å šäœãèªåã§èšå®ããããšãã§ããŸãïŒäŸïŒpostfix + dovecot + antispamïŒããŸãã¯iredmailã¢ã»ã³ããªã䜿çšã§ããŸãã
圌女ã«ã€ããŠã®ããã©ãŒã¯ããã«æžããŠã㊠ã ããæ°é®®ã§ãã
Dropbox
éåžžã«å€ãã®ãªãŒãã³ãœãŒã¹ã¢ããªã±ãŒã·ã§ã³ãDropboxã®ä»£æ¿åãšèŠãªãããå¯èœæ§ããããŸããã€ã³ã¹ããŒã«äŸãžã®ãªã³ã¯ãèšèŒããå°ããªãªã¹ããæäŸããŸãã
- Seafileãã€ã³ã¹ããŒã«ã¯å ¬åŒãŠã§ããµã€ãã§è©³çŽ°ã«èª¬æãããŠããŸã
- OwnCloudã ã€ã³ã¹ããŒã«ããã³äœ¿çš
- ã¹ããŒã¯ã«ã·ã§ã¢
- ããã£ãª
evernote / google keepã眮ãæãã
æ®å¿µãªãããevernoteãµãŒãã¹ã®æ¬æ ŒçãªWebããŒã¹ã®ä»£æ¿ã¯èŠã€ãããŸããã§ããã
lavernaã ãããããŸãããããã¯ãŸã æ°é®®ããããœãããŠã§ã¢ã§ãã åäŸã®ãã°ããšã©ãŒããã£ã±ã
Asechke / Skype / Messengerã®äº€æ
ããã¯ãã¡ããããã¹ãŠã®äººã®ãæ°ã«å ¥ãã®ãžã£ããŒã§ãããç¬èªã®vpsã§èšå®ããã³å®è¡ãããŸãã
prosodyã®ã€ã³ã¹ããŒã«æé ïŒjabberãä»ããéä¿¡çšã®è»œéã§å°åã®ãµãŒããŒïŒã
RSSã䜿çšãã
ãã¥ãŒã¹ãèªãã«ã¯ãTiny Tiny rss rssãªãŒããŒã䜿çšããŸãããã®ãªãŒããŒã«ã¯æŽ»æ°ã®ããã³ãã¥ããã£ããããéåžžã«äŸ¿å©ãªã€ã³ã¿ãŒãã§ã€ã¹ããããŸãã
ã€ã³ã¹ããŒã«æé
VPNã䜿çšãã
habrã§vpnãæ§æããæ¹æ³ã«ã€ããŠ2åã§ã¯ãªã2å以äžæžãã
Link1
Link2
firefoxåæãµãŒããŒã䜿çšãã
ãã©ãŠã¶ã§ãã¹ã¯ãŒããšããã¯ããŒã¯ã®åæãæäœããã«ã¯ãfirefoxåæãµãŒããŒã䜿çšããŸãã
ã»ããã¢ããæé
rootCAãäœæãã
ãã¹ãŠã®ãµãŒãã¹ãå®å šãªæ¥ç¶ã§æ©èœãããã«ã¯ãSSL蚌ææžïŒã¯ã€ã«ãã«ãŒã蚌ææžãŸãã¯ããã€ãã®éåžžã®èšŒææžïŒãè³Œå ¥ããããç¬èªã®èšŒææ©é¢ãäœæããŠãã©ãŠã¶ãŒã«çµ±åãããµãŒãã¹ã®SSL蚌ææžã§çœ²åããå¿ èŠããããŸãã
ã»ããã¢ããæé
ããŒãã¹
ãã©ãã€ãã®èœã¡çããé«ããè¿œå èŠçŽ
ä¿¡é Œã§ããªãããã°ã©ã ã«lxcãµã³ãããã¯ã¹ã䜿çšãã
ãªããããå¿ èŠãªã®ã§ããïŒ ããšãã°ãã¹ã«ã€ããŸãã¯ããã€ãã®ã¹ã«ã€ããèµ·åããããå¥ã®firefoxãèµ·åããŠãæ¥æ¬ã®vpnãä»ããŠè¶ ç§å¯ã®æ¥æ¬æ ç»ãèŠèŽããããšããŸãã
å€ãã®çç±ãèããããŸãã
ãã®ãããå®è£ ã¯lxcã®äœæè ã®1人ã®èšäºã§èª¬æãããŠããŸã
éç¹æš©ã³ã³ãã
ãããŠ
ã³ã³ãããŒå ã®GUI
ã³ã³ãã¥ãŒã¿ãŒ/ã©ãããããã§å®å šãªOSãæ§ç¯ãã
- ããã¯ãLinuxãŸãã¯å¥ã®ãªãŒãã³ãœãŒã¹OSã䜿çšããããšãæå³ããŸãã
- ããã¯ãæå·åãã¹ã¯ãŒãã䜿çšããããšãæå³ããŸãïŒãŸãã¯ãæçŽã䜿çšããèªåèªèšŒïŒã
- ããã¯ããã£ã¹ã¯ããŒãã£ã·ã§ã³ãæå·åããããšãæå³ããŸãã
Androidãã©ã³ã®ã»ããã¢ãã
- æšæºãã¡ãŒã ãŠã§ã¢ãCyanogenmod / Replicant / Paranoid Androidã«çœ®ãæãã
- ãã¡ã€ã«ã·ã¹ãã æå·åã®äœ¿çš
- VPNãä»ããã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã®ã¿
- Google Playã®äœ¿çšæåŠãF-Droidãšã®äº€æ
- é·ã匷åãªãã¹ã¯ãŒãã䜿çšãã
- æºåž¯é»è©±ã远跡ããïŒgps tracker android self in searchïŒ
åç §è³æ
ãã©ãŠã¶ãããªãã«é¢ããæ å ±ãã©ã®ããã«æ£ç¢ºã«ããŒãžãããã¯ãLurkaã§ããªããã説æãããŠããŸãã
ã€ã³ã¿ãŒããããŠãŒã¶ãŒèå¥
å¿åã§ã€ã³ã¿ãŒãããã䜿çšããããšã«é¢ãããŠã£ãããã¯ã«é¢ããçŽ æŽãããèšäºããããŸãã
Confidential_protection_and_anonymity_of_Internet
æ®å¿µãªããããã®èšäºã«ã¯ãã以äžã®æ å ±ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¯å«ãŸããŠããŸããã
èå³æ·±ã解決çãžã®ãªã³ã¯ã§ã®ã£ãããåããããšããŸãã
habrahabr.ru/post/120620-DNSSEC ãããã¯äœã§ããªã
prism-break.org/ru-SORMããä¿è·ããããã®ç¬èªã®ãœãªã¥ãŒã·ã§ã³ã®ä»£æ¿æ¡ãæ€çŽ¢ãããããžã§ã¯ã
www.opennet.ru/base/sec/ubuntu_disk_crypt.txt.html-Linuxã®ãã£ã¹ã¯æå·å