é説çã«ïŒHTTPSã¯é·å¹Žã«ããã£ãŠäœ¿çšãããŠããŸããããé·å¹Žã«ããã£ãŠãã»ãã¥ãªãã£ãéèŠãªããŒã¿ãåŠçãããã¹ãŠã®ã€ã³ã¿ãŒããããªãœãŒã¹ã®ããã©ã«ãã®æšæºã«ã¯ãªããŸããã§ããã æšå¹Žãç§ãã¡ã¯äž»èŠãªãã·ã¢ã®ããŒã¿ã«ã®äžã§ãã¡ã€ã³ããŒãžã«HTTPSãçµã¿èŸŒãã æåã®äŒæ¥ã«ãªããŸããã
çŸåšãæå·åã¯Mail.RuããŒã¿ã«ã®ãŠãŒã¶ãŒã®æåã®ã¹ãããããæ©èœããããã©ã«ãã§åžžã«æå¹ã«ãªã£ãŠããŸãã ãã°ã€ã³ãã©ãŒã ãšã¡ãŒã«ãã¹ã¯ãŒããã¡ã€ã³ããŒãžã«ãããããããã¯åãªãå¿ é ã¢ã€ãã ã§ãã æ¿èªäžã®ãŠãŒã¶ãŒããŒã¿ã®è»¢éã¯é·å¹Žã«ããã£ãŠHTTPSçµç±ã§è¡ãããŠããŸãããã¡ã€ã³ããŒãžãHTTPçµç±ã§ããŒããããå ŽåãããŒã¿å ¥å段éã§SSLã¹ããªããæ»æäžã«ãããååããããšãã§ããŸããããã¯ãµã€ããŒç¯çœªè ã®éã§éåžžã«äººæ°ããããŸãã ããšãã°ãååšããªããµã€ãexample.comãåãäžããŠããã®æ¬è³ªãæãåºãããŠãã ããã
- ãŠãŒã¶ãŒããããªãã¯Wi-Fiãä»ããŠã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ãããã©ãŠã¶ãŒã«example.comãæžã蟌ããšããŸãã
- èŠæ±ã¯example.comãµãŒããŒã«éãããããã§ãµãŒããŒãå¿çã圢æããŸãã ç¹ã«ãæ¿èªãè¡ãããURLïŒhttps://auth.example.comïŒãžã®ãªã³ã¯ãå«ãŸããŠããŸãã
- æ»æè ã¯å¿çãååãããã®URLãä»ã®URLïŒhttps://some-fraudlent-server.comïŒã«å€æŽããŸãã HTTPSã䜿çšããªãå Žåãããã«ãŒã¯ãã©ãã£ãã¯ããèããã ãã§ãªãããµãŒããŒã«ä»£ãã£ãŠã¯ã©ã€ã¢ã³ãã«åœã®ããŒã¿ãéä¿¡ã§ããŸãã
- æ»æè ã¯ãåœã®ããŒãžã衚瀺ãããŠãŒã¶ãŒã®ãã©ãŠã¶ã«åœã®ããŒãžãéä¿¡ããŸãã éåžžã®ããŒãžãšãŸã£ããåãããã«èŠããŸãã
- çããæããªããŠãŒã¶ãŒããŠãŒã¶ãŒåãšãã¹ã¯ãŒããããã«å ¥åãããEnterããã¯ãªãã¯ããŸãã
- ãã©ãŠã¶ã¯ããŠãŒã¶ãŒãæ¿èªãã©ãŒã ã®ã¢ã¯ã·ã§ã³ã«è»¢éããŸãã æ»æè ã®ã¢ã¯ã·ã§ã³ããªãã£ãå Žåãæ»æè ã¯https://auth.example.comã«å€æããŸãããURLã®ãªãããŸãã®ããã«ããã©ãŠã¶ã¯ãããèªåã®ããŒãžhttpïŒ//some-fraudlent-server.comã«è»¢éããéä¿¡ããŸããŠãŒã¶ãŒã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãããããŸãã
ãŠãŒã¶ãŒãéåžžã«ç¬åµçã§ããããšãå€æããå Žåã§ãïŒããšãã°ãããã¯ããŒã¯ã«ããŒãžã®http-addressãä¿åããŸãã-httpïŒ//mail.ru/ãã®ãªã³ã¯ã䜿çšããŠã¡ã€ã³ããŒãžã«ç§»åããããšããŸãïŒãæ»æè ã¯éåžžã«æ°žç¶çã§ã-ãªã©ãã®å ŽåãStrict Transport Securityãã¯ãããžãŒã«ãããŠãŒã¶ãŒããŒã¿ãä¿è·ãããŸãã ããã¯ãHTTPSãä»ãã匷å¶ã»ãã¥ã¢æ¥ç¶ãã¢ã¯ãã£ãã«ããã¡ã«ããºã ã§ãã ææ°ã®ãã©ãŠã¶ã®ã»ãšãã©ã§ãµããŒããããŠããŸãã ãã®ãããã¡ã€ã³ããŒãžã«HTTPSãå®è£ ããããšãéåžžã«éèŠã§ããã
ãããã£ãŠãHTTPSãžã®ç§»è¡ã¯ããŸããã©ãã£ãã¯ããªãã¹ã³ããããšããä¿è·ããã次ã«ããŒãžã³ãŒããMiTMãå€æŽã§ãããšããäºå®ããä¿è·ããŸãã æ»æè ããŸãã¯ãŠãŒã¶ãŒã«ç¬èªã®ãããŒåºåã衚瀺ãããå ¬å ±ã®Wi-Fiãããã€ããŒãªã©ã§ãã ãã®ãããªãããŒã¯ãããã²ãŒã·ã§ã³èŠçŽ ãªã©ã®æçšãªã³ã³ãã³ãã®äžéšãšéãªãåãå ŽåããããŸã-ãã¡ãããããã¯åžžã«ãŠãŒã¶ãŒã«å¥œãããããã§ã¯ãããŸããã ãšããã§ãçè«çã«ã¯ããããã€ããŒã¯ãŠãŒã¶ãŒããŒã¿ãååããããšã§æªæã®ããã³ã³ãã³ããå°å ¥ããããšãã§ããŸãã
次ã«ãæã倧ããæã蚪åãããRunetããŒã¿ã«ã®1ã€ã®ã¡ã€ã³ããŒãžã«HTTPSãå®è£ ããæ¹æ³ãšãçŽé¢ããå°é£ã«ã€ããŠèª¬æããŸãã
ã³ã³ãã³ããHTTPSã«å€æãã
æåã®ã¹ãããã¯ãã¡ã€ã³ããŒãžã«è¡šç€ºããããã¹ãŠã®ã³ã³ãã³ããhttpsã«è»¢éããããšã§ããã ã»ãšãã©ã®æ å ±ã¯ãä»ã®Mail.RuãµãŒãã¹ïŒãã¥ãŒã¹ã倩æ°ãªã©ïŒããååŸããŸãã ãããã®ããã€ãã¯ãŸã HTTPSã«åãæ¿ããŠããŸããã ãã ããã³ã³ãã³ããã€ãŸãä»ã®ãµãŒãã¹ããæ®åœ±ãããåçã¯ç©ççã«ãµãŒããŒã«è»¢éããããããHTTPSãä»ããŠã³ã³ãã³ããåä¿¡ãããããããã®ãµãŒãã¹ã®è² è·ãå¢å ãããããŠãåé¡ã¯ãããŸããã§ããã
Mail.RuããŒã¿ã«ã§åäœããäžè¬çãªãããŒã·ã¹ãã ã«ã¯ãããŒãããŒããã®å€éšã³ã³ãã³ããå«ãŸããŠãããããããå°é£ã§ããã ãããã¯ãããŒãããŒã®ãããŒã衚瀺ããããšãã«çµ±èšæ å ±ãèšç®ããããã«äœ¿çšããããã¯ã»ã«ïŒ1x1ãã¯ã»ã«ã®éæãªåçïŒã§ãã ã¡ãŒã«ã«HTTPSãå®è£ ããå Žåã§ãã2ã€ã®ããšãè¡ããŸããã1ã€ç®ã¯ããŒãããŒãšHTTPSã«åãæ¿ããããšã§åæãã2ã€ç®ã¯ãå®å šã§ãªãã³ã³ãã³ããå«ããããŒã®è¡šç€ºããããŒã·ã¹ãã åŽã§æè¡çã«çŠæ¢ããããšã§ãã ã ã¡ã€ã³ããŒãžãHTTPSã«å€æããããã«ããããã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããŸããã
ã¢ãã£ãªãšã€ãã³ã³ãã³ãã®ãã1ã€ã®äŸã¯ããªãŒãã£ãšã³ã¹ã«ãŠã³ã¿ãŒã§ãã HTTPSã«åãæ¿ããå Žåã¯ãå®å šãªãããã³ã«ãšã®äºææ§ã«ã€ããŠããã®ãããªãã¹ãŠã®ã³ã³ãã³ãã確èªããããšããå§ãããŸãã
ã©ã€ããŠãŒã¶ãŒã®HTTPSãæå¹ã«ããåã«ãMail.Ru Groupã®åŸæ¥å¡ã匷å¶çã«è»¢éããŸããã ããã«ãããç®ç«ã£ãè² è·ãäžããããšã¯ã§ããŸããã§ããããããŒãžäžã®ãã¹ãŠã®ã³ã³ãã³ããå®å šãªãããã³ã«ã䜿çšããŠç¢ºå®ã«èªã¿èŸŒãŸããããã«ãªããŸããã
ã©ã€ãã§HTTPSãæå¹ã«ãã
ç§ãã¡ãæºåããŠããäž»ãªåé¡ïŒHTTPSã«åãæ¿ãããšããµãŒããŒã®è² è·ãå€§å¹ ã«å¢å ããŸãã ããã«ããµãŒããŒãžã®æ¥ç¶æéãšãã¹ã¯ãªãããšéçãã¡ã€ã«ãããŒãããæéãå¢ããããšã«ãããããŒãžå šäœã®ããŒãæéãå¢ãããŸãã ãããã£ãŠãç§ãã¡ã解決ããäž»ãªã¿ã¹ã¯ã¯ã第äžã«ãçŸåšã®éã®ããŒããŠã§ã¢ã§éå§ããããšããããšã§ããã第äºã«ãæå°ã®ããŒãžèªã¿èŸŒã¿é床ãååŸããããšã§ããã
ããã«ãã§ãã¯ãè¡ãããšã決å®ããäžéšã®ãŠãŒã¶ãŒã«å¯ŸããŠHTTPSãæå¹ã«ããŠãéã®è² è·ãã©ãã ãå¢å ãããã枬å®ããŸããã æ°æ¥éã«ããã£ãŠãHTTPSã®ã·ã§ã¢ãåŸã ã«å¢ããããã£ãŒãïŒãµãŒããŒäžã®CPUããããã¯ããšã®ããŒãžèªã¿èŸŒã¿æéãããã³ãªãŒãã£ãšã³ã¹ã€ã³ãžã±ãŒã¿ãŒïŒããããšã¡ã€ã³ã®ãããžã§ã¯ããžã®ç§»è¡ïŒïŒã«åŸããŸããã ããã§ãã¡ã€ã³ããŒãžã«ã€ããŠã¯ãè€æ°ã®è² è·ãç¶æããå¿ èŠããããšèããŠããããšã«æ³šæããŠãã ããã ãã ãããã¹ããéå§ãããšããã100ïŒ ã®ãŠãŒã¶ãŒã«å¯ŸããŠHTTPSãéå§ããå Žåããã®ããŒãžã³ã¯ååšããªãããšã瀺ãããŸããã ãããŠãæé©åã®æéã§ãã
ãŸããããŒãã¢ã©ã€ããæå¹ã«ããŸãããããã«ããããµãŒããŒãžã®åæ¥ç¶ã確ç«ããããã®æéãäžèŠã«ãªããŸããã ã¡ã€ã³ããŒãžMail.Ruã¯çŸåšã®ãŠãŒã¶ãŒã«é¢ããæ å ±ã1åããšã«ãµãŒããŒã«åãåãããããã確ç«ãããæ¥ç¶ã䜿çšããŠæŽæ°ããŸãã ããã«ãããããŒãã¢ã©ã€ãã¯ç¢ºç«ãããæ¥ç¶ã®æ°ãæžãããŸããã ãã®çµæãè² è·ãæžå°ãããµãŒããŒããã®å¿çã®å¹³ååŸ æ©æéãçŽ30ïŒ æžå°ããŸããã
第äºã«ããŠãŒã¶ãŒããŒã¿ã®æŽæ°èŠæ±ã®æ°ã3åã®1ã«åæžããŸããã ã¡ã€ã³ããŒãžã§ã¯ã1åéã«çŽ90äžä»¶ã®ãã®ãããªãªã¯ãšã¹ããè¡ãããŸãã ãã ãããŠãŒã¶ãŒãäžæ£ã§ãã£ãå ŽåããµãŒããŒãããã€è©ŠããŠãæ°ããããšã¯ããããŸããïŒããã¯ãæ°åããšã«å·èµåº«ã調ã¹ãŠãäœãæ°ãããã®ããããã©ããã確èªãããããªãã®ã§ãïŒã ãã®çµæããŠãŒã¶ãŒããŒã¿ã®æŽæ°ã¯ããã®ããŒã¿ãæŽæ°ã§ãããšæ³å®ããå Žåãã€ãŸããŠãŒã¶ãŒãæ¿èªãããããæ¿èªãå€æŽãããå Žåã«ã®ã¿é©çšããå§ããŸããã ãããã®å€æŽã«ããããµãŒããŒãè¿œå ããããšãªããè² è·ã蚱容å¯èœãªã¬ãã«ã«æžããããã¹ãŠã®ãŠãŒã¶ãŒã«å¯ŸããŠHTTPSãæå¹ã«ã§ããŸããã
HTTPSãããŸã£ãããæå¹ã«ãªã£ããšãããŠãŒã¶ãŒããããã«ééããå Žåãéæšæºã®ãã©ãŠã¶ãŒãŸãã¯OSã§ã®ããŒãžã®èªã¿èŸŒã¿ã«é¢ããåé¡ã瀺ãå¯èœæ§ãããããããªãŒãã£ãšã³ã¹ã€ã³ãžã±ãŒã¿ãŒã®å€åãç£èŠããŸããã
èå³æ·±ãç¹ããããŸãããHTTPSãæå¹ã«ããçŽåŸã«ãã¢ãã€ã«ããŒãžã§ã³ã®ã¡ã€ã³ããŒãžã®ã€ã³ãã¬ãã·ã§ã³æ°ãå¢å ããŠããããšãããããŸããã ãã¡ããããã®æé·ã¯æžå¿µãåŒãèµ·ãããŸããã HTTPSã䜿çšãããšããŠãŒã¶ãŒããã©ãŠã¶ã«æ»ã£ãŠã¯ãªãã¯ããŠããŒãžã«æ»ããšãããŒãžãå®å šã«ãªããŒããããããšãå€æããŸããã ãããŠããŠãŒã¶ãŒã¯ãã®æ¹æ³ã§ã¡ã€ã³ç»é¢ã«é »ç¹ã«æ»ããŸããã¡ã€ã³ç»é¢ã®ã¢ãã€ã«çããã®ãªã³ã¯ã¯ã倧ããªç»é¢ãšã¯ç°ãªããåããŠã£ã³ããŠã§éããŸãã HTTPã§ã¯ãã¢ãã€ã«ãã©ãŠã¶ã®ããŒãžã¯ãã£ãã·ã¥ãã衚瀺ãããããšããããããŸãïŒåäœã¯OSãšãã©ãŠã¶ã«ãã£ãŠç°ãªããŸãïŒã ãã®ãããã¡ã€ã³ã®ã«ãŠã³ãã€ã³ãã¬ãã·ã§ã³æ°ãå¢å ããŸããã ãã®ä»®èª¬ããã¹ãããããã«ãïŒäžéšã®ãã©ãŠã¶ãŒã®ïŒæ»ããã¿ã³ã䜿çšããŠããŒãžã®ãªããŒãã®ã°ã©ããäœæãã圌ã¯ããã確èªããŸããã
ããã§ãããŒã¿ã«ã®ã¡ã€ã³ããŒãžã®ç¿»èš³ã«æåããŸããã ããã«ãã³ã³ãã³ããããžã§ã¯ãã«HTTPSãå®è£ ããŸãããããšãã°ãã¡ãŒã«ãšæ¯èŒããŠããŸãå€ãã®ãŠãŒã¶ãŒããŒã¿ã¯ä¿åãããŸããããæ¿èªãã©ãŒã ããããŸãã ããã§ãMail.Ru NewsãAutoãCarsãHi-TechãWeatherãHealthãChildrenã§å®å šãªãããã³ã«ãæå¹ã«ãªãããã®ãªã¹ãã¯æ¡å€§ãç¶ããŸãïŒæ¬¡ã®æçš¿ã®ããããã§ãHTTPSãžã®ç§»è¡ãæ€çŽ¢ãšã³ãžã³ããã®ãã©ãã£ãã¯ã«ã©ã®ããã«åœ±é¿ãããã説æããŸãïŒ ïŒ
ãã®äŸãååãåºæ¿ããå€ããå°ãªãã倧èŠæš¡ãªãªãœãŒã¹ã®ãã¹ãŠã®ã¡ã€ã³ããŒãžãHTTPSã§åŸã ã«è¡šç€ºãããããšãé¡ã£ãŠããŸãã SSLstripæ»æãããŠãŒã¶ãŒããŒã¿ãä¿è·ããŸãïŒ