ããµãã¥ãŒã»ããå·¥ç§å€§åŠã è¬çŸ©ã³ãŒã¹6.858ã ãã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®ã»ãã¥ãªãã£ãã ãã³ã©ã€ã»ãŒã«ããŽã£ããããžã§ãŒã ãºã»ãã±ã³ãºã 2014幎
ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã»ãã¥ãªãã£ã¯ãå®å šãªã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®éçºãšå®è£ ã«é¢ããã³ãŒã¹ã§ãã è¬çŸ©ã§ã¯ãè åšã¢ãã«ãã»ãã¥ãªãã£ãå±éºã«ãããæ»æãããã³æè¿ã®ç§åŠçç 究ã«åºã¥ããã»ãã¥ãªãã£æè¡ãæ±ããŸãã ãããã¯ã«ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒOSïŒã»ãã¥ãªãã£ãæ©èœãæ å ±ãããŒç®¡çãèšèªã»ãã¥ãªãã£ããããã¯ãŒã¯ãããã³ã«ãããŒããŠã§ã¢ã»ãã¥ãªãã£ãããã³Webã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãå«ãŸããŸãã
è¬çŸ©1ïŒãã¯ããã«ïŒè åšã¢ãã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©2ïŒãããã«ãŒæ»æã®å¶åŸ¡ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©3ïŒããããã¡ãªãŒããŒãããŒïŒãšã¯ã¹ããã€ããšä¿è·ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©4ïŒãç¹æš©ã®å ±æã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©5ïŒãã»ãã¥ãªãã£ã·ã¹ãã ã¯ã©ãããæ¥ãã®ãïŒã ããŒã1 / ããŒã2
è¬çŸ©6ïŒãæ©äŒã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©7ïŒããã€ãã£ãã¯ã©ã€ã¢ã³ããµã³ãããã¯ã¹ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©8ïŒããããã¯ãŒã¯ã»ãã¥ãªãã£ã¢ãã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©9ïŒãWebã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©10ïŒãã·ã³ããªãã¯å®è¡ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©11ïŒãUr / Webããã°ã©ãã³ã°èšèªã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©12ïŒãããã¯ãŒã¯ã»ãã¥ãªãã£ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©13ïŒããããã¯ãŒã¯ãããã³ã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©14ïŒãSSLããã³HTTPSã ããŒã1 / ããŒã2 / ããŒã3
HTTPSã®æœè¡ã¯ã蚌ææžã䜿çšãããã©ããã決å®ããéã®è£éãå€ããããŠãŒã¶ãŒã«å¯Ÿããæžå¿µã«ãããã®ã ãšæããŸãã
å®éã«çºçããHTTPSã®äœ¿çšã匷å¶ããå¥ã®åé¡ã¯ãå®å šã§ãªãæ·»ä»ãã¡ã€ã«ãŸãã¯WebããŒãžäžã®æ··åã³ã³ãã³ãã§ãã ãã®åé¡ã®ãã€ã³ãã¯ãå®å šãªãµã€ããŸãã¯ä»»æã®Webãµã€ããããã®ã»ãã®ã³ã³ãã³ããWebããŒãžã«åã蟌ãããšãã§ãããšããããšã§ãã
ãããã£ãŠãfoo.com / index.htmlãªã©ã®äœããã®Webãµã€ããããå Žåã¯ãHTTPSãããã³ã«ã䜿çšããŠæäŸã§ããŸãããHTMLããŒãžå ã«ã¯ããã©ãŠã¶ãŒã匷å¶çã«ã©ããã«ç§»åããããã®äžéšã«ããããã®å€ãã®ã¿ã°ãå«ããããšãã§ããŸããã®ããŒãžã«ã¯ãããçš®ã®ãšã€ãªã¢ã³ã³ã³ãã³ãããããŸãã
ãã®ã·ããªãªã®ã¿ã°ã¯æ¬¡ã®ããã«ãªããŸãã
<script scr = «http://jquery.com/âŠâ>
jquery.comã®ãœãŒã¹ãæããŸãã ãããã£ãŠã人æ°ã®ããJavaScriptã©ã€ãã©ãªãŒã¯ããã©ãŠã¶ãŒå ã®å€ãã®ãã®ã®çžäºäœçšãä¿é²ããŸãã ããããå€ãã®Webéçºè ã¯ãåã«å¥ã®ãµã€ãã®URLã«ãªã³ã¯ããŠããŸãã ããã¯ç©äºãç°¡åã«ããŸãããäœããã£ããã«ãªãã®ã§ããããïŒ å®å šãªãµã€ãããããããããjQueryãããŠã³ããŒãããã ãã ãšããŸãã
åŠçïŒããã¯åœã®jQueryãããããŸããã
ææïŒã¯ããããã§ãã å®éã«ã¯ãåãåãããšãæåŸ ããŠããªãééã£ããã®ãååŸãã2ã€ã®æ¹æ³ããããŸãã 1ã€ã®å¯èœæ§ã¯ãjQueryèªäœãå±éºã«ãããããå¯èœæ§ãããããšã§ãã ããªãã¯ããªããèŠæ±ãããã®ã«äŒŒãäœããåŸãŸããã jQueryãå±éºã«ãããããŠããå Žåãããã¯éåžžã«æªãããšã§ãã å¥ã®å¯èœæ§ã¯ããã®èŠæ±ãæå·åãŸãã¯èªèšŒãªãã§ãããã¯ãŒã¯ãä»ããŠéä¿¡ãããããšã§ãã ãããã£ãŠãæ»æè ããããã¯ãŒã¯æ¥ç¶ãå¶åŸ¡ããŠããå Žåãæ»æè ã¯ãã®ãªã¯ãšã¹ããã€ã³ã¿ãŒã»ããããå¿çãšããŠå¥ã®JavaScriptã³ãŒããéä¿¡ããããšãã§ãããã®JavaScriptã³ãŒãã¯ããŒãžã®äžéšãšããŠæ©èœããŸãã ãããŠã圌ã¯ãã®HTTPSãã¡ã€ã³foo.comã§åããŠãããããä¿è·ãããcookie foo.comããã³ãã®ããŒãžã®ä»ã®ãã¹ãŠã«ã¢ã¯ã»ã¹ã§ããŸãã ããã¯æ¬åœã«æªãããšã®ããã«æããŸãã®ã§ã泚æããŠãã ããã ãŸããWebéçºè ã¯ããã®çš®ã®ééããããªãããã«æ³šæããå¿ èŠããããŸãã
ãããã£ãŠã1ã€ã®ãœãªã¥ãŒã·ã§ã³ã¯ãå®å šãªããŒãžã«åã蟌ãŸãããã¹ãŠã®ã³ã³ãã³ãã®ã»ãã¥ãªãã£ã確ä¿ããããšã§ãã ããã¯ãå€ãã®Webéçºè ãåŸãã¹ãåªããã¬ã€ãã©ã€ã³ã§ãã ãããã£ãŠããã®è¡ã§jquery.comã®ä»£ããã«jquery.comã䜿çšããå¿ èŠããããŸãã ãŸãã¯ãURLããªãªãžã³ããªã·ãŒããµããŒãããŠããå ŽåãHTTPSã®äžéšãçç¥ããŠããã®ã¹ã¯ãªããã®ãªãªãžã³ã//jquery.com/ã§ãããã€ãŸãscr = "//jquery.com / ..."ãšã ãèšãããšãã§ããããšãæå³ããŸã
ã€ãŸãããã®ã¿ã°ã¯ãHTTPSããŒãžã«ããå Žåã¯jquery.comã« ãHTTPSã§ã¯ãªãéåžžã®HTTP URLã«ããå Žåã¯jquery.comã«éä¿¡ããããšãæå³ããŸãã ããã¯ããã®ãããªåé¡ãåé¿ãã1ã€ã®æ¹æ³ã§ãã
ãã ãã人ã ã¯åžžã«ãã¹ãŠãæ¹åããããšããŠããããããã®åé¡ã解決ããå¥ã®æ¹æ³ã®1ã€ã¯ãããããã¿ã°ã«ããã·ã¥ãŸãã¯ã€ã³ãžã±ãŒã¿ãŒã®ãããªãã®ãå«ããããšã§ãã
<script scr = «http://jquery.com/âŠâ>
ããŠã³ããŒãããã³ã³ãã³ãã®çš®é¡ãããã£ãŠããå Žåã¯ãããããHTTPSãããã³ã«ã䜿çšããŠå®å šã«ããŠã³ããŒãããå¿ èŠã¯ãããŸããã å®éãç¹å®ã®ããã·ã¥ã«äžèŽããéãããã®ã³ã³ãã³ããã ããæäŸãããã¯æ°ã«ããŸããã
ãããã£ãŠããã®çš®ã®ã¿ã°ã®ããã·ã¥ãæ§æã§ããæ°ããä»æ§ããããŸãã ãã®ãããHTTPS URLã䜿çšããŠjquery.comã«ãªã³ã¯ãã代ããã«ãã¹ã¯ãªãããœãŒã¹ãjquery.comãŸãã¯HTTPã§ãããšã ãèšãããšãã§ããŸãããã¹ã¯ãªããã®æåŸã«äœããã®çš®é¡ã®ã¿ã°å±æ§ãè¿œå ããŸããããšãã°ãããã·ã¥ã¯ãµãŒããŒããååŸããããšèããŠããŸãã
åŠçïŒãã®ä»æ§ã®ååã¯äœã§ããïŒ
ææïŒè€éãªååãæã¡ãè¬çŸ©ããŒãã®ããŒãã«ãããŸããããµããªãœãŒã¹ã®æŽåæ§ãããµããªãœãŒã¹ã®æŽåæ§ãªã©ã§ãã å®è£ ã¯ããªããã£ããã§ãããè¿ãå°æ¥ãããŸããŸãªãã©ãŠã¶ã«é©çšãããããšãé¡ã£ãŠããŸãã ããã¯ããããã¯ãŒã¯ã¬ãã«ã§ã®ããŒã¿æå·åã«äŸåããã«ã³ã³ãã³ããèªèšŒããå¥ã®æ¹æ³ã«äŒŒãŠããŸãã
ãããã£ãŠãSSLãšTLSã䜿çšããŠç¹å®ã®ãµãŒããŒãžã®æ¥ç¶ãèªèšŒãããã®éåžžã«äžè¬çãªèšç»ããããŸãã ããã¯ããããã¯ãŒã¯æ¥ç¶ãä¿è·ãã代æ¿æ¹æ³ã§ãã æŽåæ§ãéèŠããå Žåãæå·åãããå®å šãªãããã¯ãŒã¯ãã£ãã«ã¯å¿ èŠãªãå ŽåããããŸãã å¿ èŠãªã®ã¯ãæçµçã«äœãååŸããããæ£ç¢ºã«æå®ããããšã ãã§ãã
åŠçïŒãã®SRCã³ãŒãã¯ã¯ã©ã€ã¢ã³ãããã®ãã®ã§ã¯ãããŸãããïŒ
ææïŒåœŒã¯ã¯ã©ã€ã¢ã³ãåŽã§åããŠããŸãããã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒãããã®ã³ãŒããåãåããŸãã
åŠçïŒ JavaScriptã³ãŒããããŒãžã«å ¥åããããšã¯ã§ããŸãããïŒ
ææïŒã§ãããšæããŸãã ãããã£ãŠãããã·ã¥ã®æå³ã¯ãä»ã®JavaScriptã³ãŒããå ¥åããããšããäŸµå ¥è ããããŒãžã®ã³ã³ãã³ããä¿è·ããããšã§ãã jQueryã§ã¯ãjQueryãœãŒã¹ã³ãŒããé衚瀺ã«ããããšããŠããªããããjQueryã¯ããç¥ãããŠãããããããã¯éåžžã«éèŠã§ãã ãããã£ãŠããããã¯ãŒã¯æ»æè ãæ¥ç¶ãååããŠjQueryã®æªæã®ããããŒãžã§ã³ãæ¿å ¥ã§ããªãããã«ããŠãCookieã®æŒæŽ©ã®åå ãšãªãããã«ããå¿ èŠããããŸãã 誰ãããããã®ãã®ã®ããã·ã¥ãèªåã§ç解ã§ããããšã¯äºå®ã§ãã ãããã£ãŠãããã¯ãã©ã€ãã·ãŒã§ã¯ãªãæŽåæ§ã®åé¡ã®è§£æ±ºçã§ãã
éçºè ã¯ãããŒãžãèšè¿°ããããHTMLããŒãžã®ã³ã³ãã³ããHTTPS URLã«å«ãããšãã«ãããã«æ³šæãæãå¿ èŠããããšæããŸãã ãã1ã€ã®æžå¿µã¯ãCookieã«é¢ãããã®ã§ãã ããã¯ãã»ãã¥ãªãã£ãã©ã°ä»ãã®Cookieãšããªãªãžã³ãªãªãžã³ã®Cookieã®éããé¢ä¿ãããšããã§ãã éçºè ãããã§å°ç¡ãã«ã§ããå¯äžã®ããšã¯ãããããã¯ãããŒã«ãã©ã°ãèšå®ããããšãå¿ããããšã§ããããã¯èµ·ãããŸãã ããããã圌ã¯HTTPS URLã®ã¿ã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã«ã€ããŠã®ã¿èãããã©ã°ãèšå®ããå¿ èŠã¯ãªããšèããŠããŸãã ããã¯åé¡ã§ããïŒ ãŠãŒã¶ãŒãéåžžã«æ éã§ãåžžã«HTTPS URLã«ã¢ã¯ã»ã¹ããå Žåãåé¡ã¯ãããŸããã ãã®å ŽåãCookieã«ã»ãã¥ãªãã£ãã©ã°ãæ®ãããšã¯çã«ããªã£ãŠãããšæããŸããïŒ
åŠçïŒæ»æè ãURLã«æ¥ç¶ããæªæã®ãããµã€ãã«ãªãã€ã¬ã¯ãããå¯èœæ§ã¯ãããŸããïŒ
ææïŒã¯ãã ãŠãŒã¶ãŒããã¬ãŒã³ããã¹ã圢åŒã®URLã«æ瀺çã«æåã§ã¢ã¯ã»ã¹ããªããŠããæ»æè ã¯å®å šã§ãªããµã€ããžã®ãªã³ã¯ãæäŸããããHTTPS以å€ã®URLã®ç»åãããŠã³ããŒãããããã«èŠæ±ãããã§ããŸãã ãããŠãå®å šã§ãªãCookieããããã¯ãŒã¯èŠæ±ãšãšãã«éä¿¡ãããŸãã ãããã£ãŠãããã¯åé¡ã§ããããŠãŒã¶ãŒãšã¢ããªã±ãŒã·ã§ã³ãéåžžã«æ éã§ãã£ãŠããæ¬åœã«ãã©ã°ãå¿ èŠã§ãã
åŠçïŒå®å šãªHTTP URLããããšæããŸãã
ææïŒã¯ããããã§ãã ããŒã80ããªãã¹ã³ããŠããªããµã€ãããããããŒã80ãä»ããŠæ¥ç¶ããæ¹æ³ããªããããå®å šã§ãªãCookieã䜿çšãããšåé¡ãçºçããå¯èœæ§ããããšä»®å®ããŸãã
åŠçïŒãã©ãŠã¶ãŒãCookieãå¥ã®ãã¡ã€ã³ã«éä¿¡ã§ããªãããã
ææïŒãŸã£ãããã®éãã§ãããã©ãŠã¶ãŒã¯å¥ã®ãã¡ã€ã³ã«Cookieãéä¿¡ããŸããããæ»æè ãèªåã®URLãããŠã³ããŒãããå±éºæ§ã¯ãŸã ãããŸãã ãããã£ãŠãamazon.comã¯SSLã®ã¿ã䜿çšããããŒã80ã§ããªãã¹ã³ããªããšä»®å®ããŸãããã®çµæãCookieã«ã»ãã¥ã¢ãã©ã°ãèšå®ããŸããã AmazonãããŒã80ã§ãªãã¹ã³ããŠããªããŠããããã«ãŒã¯ã©ããã£ãŠã¯ãããŒãçãããšãã§ããŸããïŒ
åŠçïŒãã©ãŠã¶ã¯ãããHTTPæ¥ç¶ã§ãããšãŸã èããããšãã§ããŸããïŒ
ææïŒãŸããããŒã443ã«æ¥ç¶ããŠSSLãŸãã¯TLSã䜿çšããå Žåãæ¥ç¶ã¯åžžã«æå·åããããããããã¯åé¡ã§ã¯ãããŸããã
åŠçïŒæ»æè ãæ¥ç¶ãååããå¯èœæ§ããããŸãã
ææïŒã¯ããæ»æè ã¯ããŒã80ãä»ããŠAmazonã«æ¥ç¶ããããšããŠãããã±ãããååãããµã€ãã«æ£åžžã«æ¥ç¶ãããµããããããšãã§ããŸãã ãããã£ãŠãæ»æè ããããã¯ãŒã¯ãå¶åŸ¡ããŠããå ŽåãAmazonå®ãŠã®ãã±ãããèªåã®ãã·ã³ã®ããŒã80ã«ãªãã€ã¬ã¯ãããããšãã§ããã¯ã©ã€ã¢ã³ãã¯ãã®éããèŠãããšã¯ã§ããŸããã AmazonãããŒã80ã§ãªãã¹ã³ããŠããããã«èŠããŸãããå®éã«ã¯ãCookieã¯ãã®ããã«ãŒã®WebãµãŒããŒã«éä¿¡ãããŸãã
åŠçïŒã¯ã©ã€ã¢ã³ããäžæãªããã
ææïŒããã§ããHTTPã«ã¯ãæ¥ç¶ããŠãããã¹ãã®ä¿¡é Œæ§ãæ€èšŒããæ¹æ³ããªãããã§ãã ããã¯ãŸãã«èµ·ãã£ãŠããããšã§ãã HTTPã«ã¯èªèšŒããããŸããã ãããã£ãŠããããã¯ãŒã¯ã®æµããããšæ³å®ããå Žåããã®HTTPæ¥ç¶ã®å®å ãããããªããããæåã«CookieãHTTPçµç±ã§éä¿¡ãããªãããã«ããå¿ èŠããããŸãã
åŠçïŒãã®ããã«ã¯ããããã¯ãŒã¯ãå¶åŸ¡ããå¿ èŠããããŸãã
ææïŒã¯ãããã¡ããã ãããã¯ãŒã¯ãå®å šã«å¶åŸ¡ã§ããå Žåãçžæã¯ãã±ãããååã§ããªãããšãããããŸãã ãã ãããããã¯ãŒã¯ãå®å šã«å¶åŸ¡ããŠããå Žåã§ãããã©ãã«ãçºçããå¯èœæ§ããããŸããTCPã®è¬çŸ©ã®è³æãèŠãŠãããŸããŸãªçš®é¡ã®ãããã¯ãŒã¯æ»æã調ã¹ãŸããã
察象è ïŒãããããã®å Žåããªãã€ã¬ã¯ãæ»æãé²ãããšã¯ã§ããŸãããïŒ
ææïŒããã«ãŒã¯ã amazon.comã§ã®ã¯ã©ã€ã¢ã³ãã®httpãªã¯ãšã¹ããååããå¯èœæ§ãé«ãããã®ãªã¯ãšã¹ãã«ã¯ãamazon.comã®ãã¹ãŠã®CookieããŸãã¯ãªã¯ãšã¹ããéä¿¡ããä»ã®ãã¡ã€ã³ã®Cookieãå«ãŸããŸãã ãããã£ãŠããããã®Cookieãå®å šãšããŠããŒã¯ããªãå Žåãæå·åãããæ¥ç¶ãšæå·åãããŠããªãæ¥ç¶ã®äž¡æ¹ã§éä¿¡ã§ããŸãã
åŠçïŒãã®ãªã¯ãšã¹ãã¯ã©ã®ããã«éå§ãããŸããïŒ
ææïŒãã¶ãããŠãŒã¶ãŒã«newyorktimes.comã«ã¢ã¯ã»ã¹ããŠãããããšãã§ããŸããnewyorktimes.comã§ã¯ã amazon.comããç»åãã¢ããããŒãããåºåã®æ¯æããããŸããã ãŸãããŠãŒã¶ãŒãããã®URLããç»åãããŠã³ããŒãããŠãã ããããšãã質åãé²ãããšã¯ã§ããŸããã ãã ãããã©ãŠã¶ããµã€ãã«æ¥ç¶ããããšãããšãæ¥ç¶ãæåããå ŽåãCookieãéä¿¡ãããŸãã
HTTPS Everywhereæ¡åŒµæ©èœããããŸããããã¯ã匷å¶HTTPSãŸãã¯åŒ·å¶HTTPSã«éåžžã«äŒŒãŠããããã®çš®ã®ãšã©ãŒãé²æ¢ããããšããŸãã 匷å¶HTTPSã¢ãŒãã§ãµã€ããéžæãããšããã©ãŠã¶ã¯äž»ã«ãã®ãã¹ããžã®HTTPæ¥ç¶ãé»æ¢ããŸãã
ãããã£ãŠãCookieãå®å šãšããŒã¯ããªãããŸãã¯åæ§ã®ééããããæ¹æ³ã¯ãããŸããã éçºè ãCookieã«ã»ãã¥ãªãã£ãã©ã°ãèšå®ããã®ãå¿ããå Žåããã®å Žåã®è§£æ±ºçã¯æçœã§ãã圌ã¯ééããä¿®æ£ããã ãã§ãã ãã ããããã«åŸ®åŠãªåé¡ããããŸããå®å šãªãŠã§ããµãŒããŒãã¯ã©ã€ã¢ã³ãã®Cookieãåä¿¡ãããšããã®Cookieãæå·åæ¥ç¶ãŸãã¯ãã¬ãŒã³ããã¹ãæ¥ç¶ã®ã©ã¡ãã§éä¿¡ããããã¯ããããŸããã å®éããµãŒããŒã¯Cookieã®ããŒå€ã2ã3ããåä¿¡ããªãããã§ãã
äžèšã®ã¢ã¯ã·ã§ã³ãã©ã³ããããªã¯ãšã¹ããå®å šãªãµãŒããŒã«éä¿¡ããå Žåããã©ãŠã¶ãŒã«ã¯å®å šãªCookieãšå®å šã§ãªãCookieã®äž¡æ¹ãå«ãŸããããšã«ãªããŸãã ãã ãããµãŒããŒåŽã§ã¯ãæ©å¯æ§ã¯ä¿èšŒãããŸããããŸãããµãŒããŒããŠãŒã¶ãŒCookieãåä¿¡ãããšãæå·åæ¥ç¶ãšããã¹ãæ¥ç¶ã®äž¡æ¹ã§éä¿¡ã§ããŸãã ããã¯ãã»ãã·ã§ã³åºå®ãªã©ã®æ»æã®å¯èœæ§ã«ã€ãªãããŸãã
ããã¯ãããšãã°ãæ»æè ãéä¿¡ããé»åã¡ãŒã«ãèŠããããšãæå³ããŸãã ãããè¡ãããã«ã圌ã¯èªåã®Cookieãèšå®ããŸããããã¯ãGmailã¢ã«ãŠã³ãã®Cookieã®ã³ããŒã§ãã ãŸããã¬ã¿ãŒãéä¿¡ãããšããã©ã«ããŒã§ã¯ãªããéä¿¡æžã¿ã¢ã€ãã ãã©ã«ããŒã«è¡šç€ºãããŸãã æ»æè ã®ã¢ã«ãŠã³ãã䜿çšããŠãããã®ããã«ãªããæ»æè ã¯ã¡ãŒã«ããã¯ã¹ããéä¿¡ãæœåºã§ããŸãã ãã®ãããããã«ãŒãã»ãã·ã§ã³Cookieããã©ãŠã¶ã«åŒ·å¶çã«å ¥ããå Žåã圌ã¯èªåã®ã¢ã«ãŠã³ãã䜿çšããããã«åŒ·å¶ããŸãã ããã¯ãHTTP CookieãšHTTPS Cookieã®äžå®å šãªåé¢ã«é¢ãã誀解ãåå ã§çºçããå¥ã®åé¡ã§ãã
åŠçïŒãã ããCookieãä»ã®èª°ãã®ãã©ãŠã¶ã«æ¿å ¥ããã«ã¯ãããã«è匱æ§ãå¿ èŠã§ãã
ææïŒããããCookieãèšå®ããããã«ãè匱æ§ã¯å¿ èŠãããŸããã ãã©ãŠã¶ãã ãŸããŠéåžžã®HTTPãã¹ãURLã«æ¥ç¶ããã ãã§ãã ãŸãããã©ãŠã¶ã«Force HTTPSãHTTPS Everywhereãªã©ã®æ¡åŒµæ©èœããªãå Žåãæ»æè ã¯ãŠãŒã¶ãŒã®ãã©ãŠã¶ã«ããŒãèšå®ã§ããŸãã ããã¯å®å šã§ãªãCookieã§ãããå®å šãªèŠæ±ã§ãã£ãŠãéãè¿ãããŸãã
åŠçïŒãã®ãã¡ã€ã³ãåããã¡ã€ã³ã§ãããšãã©ãŠã¶ã«æãããã«ã¯ã©ãããã°ããã§ããïŒ
ææïŒãã®ããã«ã¯ããããã¯ãŒã¯æ¥ç¶ãã€ã³ã¿ãŒã»ããããæ°ååã«è©±ããã¿ã€ãã®æ»æã®1ã€ãå®è¡ããå¿ èŠããããŸãã
ã§ã¯ã匷å¶HTTPSã¯å®éã«äœãããŸããïŒ åœŒã¯å€ãã®åé¡ã®ããã€ããé²ãããšããŠããŸãã Force HTTPSãããã³ã«ã«é¢ããç 究ã¯ã5幎ãŸãã¯6幎åã«å ¬éãããŸããã ãã以æ¥ãæšæºåãããå®éã«æ¡çšãããŠããŸãã ããã€ãã®ãã®ãšããã€ãã®ã¯ãããŒãä¿åãã倧ãã£ã±ãªãã©ã°ã€ã³ã®ããã«èŠããŸãã ä»æ¥ãã»ãšãã©ã®ãã©ãŠã¶éçºè ã¯ããããäœæããããšã¯è¯ãã¢ã€ãã¢ã ãšä¿¡ããŠããŸãã ãã©ãŠã¶ã«çŽæ¥çµ±åããããšããå§ãããŸãã HTTP Strict Transport SecurityïŒHSTSïŒãšåŒã°ãããã®ããããŸããããã¯ãHTTPSãããã³ã«ãä»ããå®å šãªæ¥ç¶ã匷å¶ããã¡ã«ããºã ã§ãã ããã¯ãç§åŠç 究ãWebã¢ããªã±ãŒã·ã§ã³ãšãã©ãŠã¶ã®ã»ãã¥ãªãã£ã«ã©ã®ããã«åœ±é¿ãããã®è¯ãäŸã§ãã
Force HTTPSãWebãµã€ãã«å¯ŸããŠè¡ãããšãèŠãŠã¿ãŸãããã 匷å¶HTTPSã䜿çšãããšãWebãµã€ãã¯ç¹å®ã®ãã¹ãåã«å¯ŸããŠãã®ããããèšå®ã§ããŸãããŸããHTTPSããã©ãŠã¶ãŒã®åäœã«åœ±é¿ãäžãã3ã€ã®ããšããããŸãã
1ã€ç®ã¯ã蚌ææžã®ãšã©ãŒã¯åžžã«èŽåœçã§ããããšã§ãã ãããã£ãŠããŠãŒã¶ãŒã¯ãééã£ããã¹ãåãæéåããªã©ã®ééã£ã蚌ææžãåãå ¥ããæ©äŒããããŸããã ããã¯ããã©ãŠã¶ãŒãå€æŽãã1ã€ã®ããšã§ãã
2ã€ç®ã¯ã匷å¶HTTPSã¯ãã¹ãŠã®HTTPèŠæ±ãHTTPSã«ãªãã€ã¬ã¯ãããããšã§ãã ããã¯ããªãè¯ãèãã§ãã ãµã€ããåžžã«åæ³çã«HTTPSã䜿çšããŠããããšãããã£ãŠããå Žåã¯ãéåžžã®HTTPãªã¯ãšã¹ããæåŠããå¿ èŠããããŸããããã¯ãäœããã®ãšã©ãŒã®å åãŸãã¯æ»æè ãæå·åããã«ãµã€ããžã®æ¥ç¶ãææ¡ããããšããŠãã蚌æ ã§ããå¯èœæ§ãããããã§ãã HTTPãªã¯ãšã¹ããå®è¡ãããåã«ãããå®éã«çºçããããšã確èªããå¿ èŠããããŸããããããªããšãHTTPãªã¯ãšã¹ãã¯ãã§ã«ãããã¯ãŒã¯ã«éä¿¡ãããŸãã
ãããŠãHTTPSããã©ãŠã¶ã«åŒ·å¶ããæåŸã®ããšã¯ã以åã«æ€èšããå®å šã§ãªãåã蟌ã¿ãã©ã³ãçŠæ¢ããããšã§ããããã¯ãHTTPSãµã€ãã«HTTP URLãåã蟌ããšãã§ãã
ãã®ããããããForce HTTPSæ¡åŒµæ©èœã®æ©èœã§ãã çŸåšäœ¿çšãããŠããçšèªã«åºã¥ããŠãHSTSãããã³ã«ã§ãåãããšãè¡ãããŸãã çŸåšãã»ãšãã©ã®ãã©ãŠã¶ã¯ããã©ã«ãã§å®å šã§ãªãåã蟌ã¿ãçŠæ¢ããŠããŸãã å€ãã®éçºè ãForce HTTPSã«ããåé¡ãæ±ããŠãããããããã¯è°è«ã®äœå°ããããŸããããFirefoxãChromeãIEã¯ããã©ã«ãã§å®å šã§ãªãã³ã³ããŒãã³ãããŸãã¯å°ãªããšãå®å šã§ãªãJavaScriptãšCSSãããŒãžã«ããŒãããããšãæåŠãããšæããŸãããã¯ééã£ãŠããŸãã
åŠçïŒè¡åã®å®è¡ã«é¢ããŠãŠãŒã¶ãŒã«è³ªåããŸãããïŒ
ææïŒåœŒãã¯éåžžããŠãŒã¶ãŒãåæãããšããäºå®ã«æ £ããŠããŸãã ããšãã°ãIEã¯ãããã¢ãããã€ã¢ãã°ã䜿çšããŠãè¿œå ã®ã³ã³ãã³ããŸãã¯ãã®ãããªãã®ãããŠã³ããŒããããã©ãããå°ããŸãã è©ŠããŠã¿ããšãããããã¹ãŠã®ã»ãã¥ãªãã£å¯Ÿçãåé¿ã§ãããšæããŸããããããè¡ãããšã¯ãå§ãããŸããã ãã®ãããææ°ã®ãã©ãŠã¶ã¯Force HTTPSããã³HSTSã䜿çšããŠããã€ãã®åé¡ã解決ããããšããŸãã
åŠçïŒãµã€ããHTTPSããµããŒãããŠããªãå Žåã¯ã©ããªããŸããïŒ
ææïŒã©ãããæå³ã§ããïŒ
åŠçïŒãã©ãŠã¶ãHTTPSçµç±ã§ãµã€ãã«æ¥ç¶ããªãããšã
ææïŒ HTTPSããµããŒãããªãããããã®Cookieãèšå®ããWebãµã€ããããå Žåã¯ã©ããªããŸããïŒ å®éããã©ãŠã¶ã§ãã®ãªãã·ã§ã³ã䜿çšãããšãHTTPSã䜿çšããªããããã»ãšãã©ã®ã€ã³ã¿ãŒããããšéä¿¡ã§ããªããªããŸãã ãããã£ãŠããã©ãŠã¶ã¯ããã®ãããªä¿è·ãæ¬åœã«å¿ èŠãšãããµã€ããšHTTPSãä»ããŠéä¿¡ã§ããå¿ èŠããããŸãã
åŠçïŒç§ã®èšæ¶ãæ£ãããã°ããµã€ããèš±å¯ãããŸã§ã¯ãããŒãèšå®ã§ããŸããã
ææïŒã¯ããããã§ãã ãããã®äººãã¡ã¯ããã®ãã©ã°ã€ã³ã䜿çšããŠä»ã®ãµã€ãã«åé¡ãåŒãèµ·ããDoSæ»æãå¿é ããŠããŸãã ããšãã°ãçããæããªãWebãµã€ãã«åŒ·å¶HTTPSããããèšå®ãããšããµããŒããããŠããªãHTTPSçµç±ã§èª°ãããããã«æ¥ç¶ããããšãããããçªç¶åäœãåæ¢ããŸãã ããã¯ããããåœãŠã«ããªããµã€ãã«åŒ·å¶HTTPSã䜿çšããããšã§DoSæ»æã䜿çšããå¯èœæ§ãå¿é ããã1ã€ã®äŸã§ãã
ãã1ã€ã®ããšã¯ããã®ãããã³ã«ããã¡ã€ã³å šäœã§ã®åŒ·å¶HTTPSã®äœ¿çšããµããŒãããŠããªãããšã§ãã ããšãã°ãç§ã¯ãŠãŒã¶ãŒmit.eduã§ããããã¹ãŠã®ãã©ãŠã¶ãŒã§HTTPS Cookieã匷å¶ããããã«èšå®ãããŠãããMITã§ã¯HTTPSæ¥ç¶ã®ã¿ãæ©èœããŸãã ããã¯å°ãå£æ» çã§ããããã«æãããã®ã§ãããããåæ§ã®ç¶æ³ãé¿ãããã§ãããã
äžæ¹ãHSTSãããã³ã«ã¯ããã«æ»ãããµããã¡ã€ã³å šäœã«åŒ·å¶HTTPSãèšå®ã§ãããšè¿°ã¹ãŸãããããã¯ãå ã®éä¿¡å ãããããªãå Žåããªã¯ãšã¹ããšãšãã«éä¿¡ãããå®å šã§ãªãCookieã«åœ¹ç«ã€ããšãå€æããããã§ãã ãããã®èšå®ã«ã¯æãäœãã¬ãã«ã®èšå®ãå€æ°ãããŸããããã®å Žåã®æ£ããéžæãäœãæå³ããã®ãã¯ãŸã æ確ã§ã¯ãããŸããã
èå³æ·±ã質åããããŸãããããã®æ¹åã¯åºæ¬çãªãã®ã§ããããããšãéçºè ãééããé¿ããã®ãå©ããããšã ããç®çãšããŠããã®ã§ãã å±éºãªã¢ã¯ã·ã§ã³ããšããã蚌ææžãæééãã«æŽæ°ããæ°ãã蚌ææžãäœæããéåžžã«è²¬ä»»ããéçºè ããããšããŸããForceHTTPSã䜿çšããå¿ èŠããããŸããïŒ
åŠçïŒãã¡ãããããã«ãŒãæ¢ãããã®ã¯äœããªãã®ã§ãããã«ãŒã¯ãŠãŒã¶ãŒã«HTTPçµç±ã§äœããããŠã³ããŒããããŠãããæ¥ç¶ãã€ã³ã¿ãŒã»ããããŸãã
ææïŒæ¬åœã§ãã ãããã圌ãéåžžã«å€åã§ããã¹ãŠã®Cookieãå®å šãšããŒã¯ãããŠãããšæããå Žåã誰ããããªãã®ãµã€ãã®HTTPããŒãžã§ã³ã«ã¢ã¯ã»ã¹ããŠããããã¯åé¡ã«ãªããŸããã
ãã ãããããããCookieã®äžæžããã€ã³ãžã§ã¯ã·ã§ã³æ»æããé²åŸ¡ããå¿ èŠããããŸãã ããã¯éªšã®æããäœæ¥ã§ãããããããããªãã¯ããã«ã€ããŠäœããããããšãã§ããŸãã
åŠçïŒã©ããªå Žåã§ããéçºè ã¯èšŒææžã®ä¿¡é Œæ§ã確èªã§ããªããšæããŸãããïŒ
ææïŒã¯ããããã¯ç§ãã¡ã®æåã®ååã«çŽæ¥é¢ä¿ããŠããŸãïŒã蚌ææžã«èª€ãããããšèŽåœçãªçµæã«ã€ãªãããŸãããæãéèŠãªç¹ã¯ãä»ã®ãã¹ãŠãã身ãå®ãããšãã§ãããšããããšã§ãããéçºè ã¯ããã®èšŒææ©é¢ã«ãã£ãŠçœ²åããããµãŒããŒã«ã®ã¿Cookieãéä¿¡ãããããšã確èªã§ããŸããããããŠããŠãŒã¶ãŒãããããããã§ååã§ãïŒããšèšãæ©äŒãããå Žåãéçºè ã¯ãäžéšã®ãŠãŒã¶ãŒãééã£ããµãŒããŒã«ãããããªãŒã¯ãããããèªåã®Cookieãã©ãã«è¡ãã®ããç¥ãæ¹æ³ããããŸããããããã£ãŠãããã¯éçºè ã«ãšã£ãŠãã®ãããã³ã«ã®äž»ãªå©ç¹ã ãšæããŸãã
åŠçïŒ , , HTTP HTTPS, , , .
: , UI, - , . URL-. amazon.com, , , . HTTPS amazon.com, HTTP URL . , URL-, , amazonn.com amazon.com. . , Force HTTPS.
â Force HTTPS ? ?
: , .
: . , , Force HTTPS HTTPS . , . , Force HTTPS, , , HTTP, HTTPS. , HTTPS. , , HTTPS.
: Force HTTPS?
: , , , . , , , , , , , Force HTTPS .
, amazon.com Force HTTPS, , , , amazon.com, .
. DNSSEC. DNSSEC, , , , HTTPS Force HTTPS, DNS-. , DNSSEC, , , .
Google , . , Chrome , Force HTTPS. Chrome, , CRL Force HTTPS, . , , , . , Google, , , .
, Google , , , , , Google . , Chrome , URL- Force HTTPS.
ã³ãŒã¹ã®å®å šçã¯ãã¡ãããå ¥æã§ããŸã ã
ãæ»åšããã ãããããšãããããŸãã ? ããèå³æ·±ãè³æãèŠããã§ããïŒ , 30% entry-level , : VPS (KVM) E5-2650 v4 (6 Cores) 10GB DDR4 240GB SSD 1Gbps $20 ? ïŒãªãã·ã§ã³ã¯RAID1ããã³RAID10ãæ倧24ã³ã¢ãæ倧40GB DDR4ã§å©çšå¯èœã§ãïŒã
VPSïŒKVMïŒE5-2650 v4ïŒ6ã³ã¢ïŒ10GB DDR4 240GB SSD 1GbpsãŸã§ 6ãæã®æéãæ¯æãå Žåã¯12æãŸã§ç¡æ㧠ã ããã§æ³šæã§ããŸã ã
Dell R730xdã¯2åå®ãã§ããïŒ ãªã©ã³ããšç±³åœã§249ãã«ããIntel Dodeca-Core Xeon E5-2650v4 128GB DDR4 6x480GB SSD 1Gbps 100 TVã2å°æã£ãŠããã ãã§ãïŒ ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ§ç¯æ¹æ³ã«ã€ããŠèªã ã¯ã©ã¹Rã¯ã1ç±³ãã«ã§9,000ãŠãŒãã®Dell R730xd E5-2650 v4ãµãŒããŒã䜿çšããŠããŸããïŒ