
ãã¹ãŠã®äººã«è¯ãäžæ¥ãïŒ
ãã®ããŒãã®ç·šéã«åºã¥ããŠãè³æãžã®2ã€ã®ãªã³ã¯ãããã«æäŸããããšæããŸãã ãœãŒã¹ãçŽæ¥ç¥ãããããã¯ãèªãããšã¯ã§ããŸãããããã¯ç§ã®ç¡æ翻蚳ã§ãããå°éã®ã®ã£ã°ã§äž»èŠãªãã€ã³ããèªã¿çŽããŸãã
BlackHat USA 2011ïŒSSLãšæªæ¥ã®çæ£æ§Moxie Marlinspike ::ããã°-SSL and The Future of Authenticityå
¥é
æ°æ¥åãSSL / TLS蚌ææžã®ååŸ
ã«é¢ããèšäºããããŸããã ããããç§ã®ã³ã¡ã³ãã¯ãããã«å¯Ÿããã³ã¡ã³ãããã®äž»é¡åéã®è°è«ãã®ãã®ããããã¯ããããã®äžåšã«ãã£ãŠã§ã¯ãªããèšäºèªäœã«ãã£ãŠã§ã¯ãããŸããã§ããã ç§ã¯ãã®å Žã§è°è«ãéå§ãããåé¡ã解決ããããã®ãªãã·ã§ã³ãšäžç·ã«åé¡ã匷調ããã³ã¡ã³ãã§å
šäœãè°è«ããããšãã§ããå¥ã®ãããã¯ãæã€ããšãçã«ããªã£ãŠãããšå€æããŸããã
äžèšã®èšäºããã®ã³ã¡ã³ããããã€ãåŒçšããŸãããã
蚌ææžã¯èªç©ºååŒã®åªããäŸã§ãã ãããŠãããªãçŸå®çãªãéã®ããã«ãäœãä¿èšŒãããäœã«å¯ŸããŠãä¿è·ããªããã€ãã®ã»ãããååŸããŸã....ïŒcïŒangry_elf
ããã«å¯ŸããçãïŒ
MiMä¿è·ãªãã·ã§ã³ãæäŸããŸãïŒ ãã®åŸãããªãã¯ç©ºäžã§ååŒããããäœãããå¿
èŠããªãã»ã©è±ãã§äººæ°ããããŸãã ïŒcïŒokazymyrovã
ãŸããå€ãã®ã³ã¡ã³ãããããŸããããããã®ã³ã¡ã³ãããã次ã®ãããã¯ãåé¡ã質åã«ã€ããŠã¯ãŸã 人ã
ãæ°ã«ããŠããããšãæããã§ãã
- 蚌ææžååŒ-èªç©ºååŒïŒ äœã®ããã«ãéãæãã®ã§ããïŒ
- èªèšŒå±ïŒCAïŒã¯ãå²ãåœãŠããã責任ã«å¯Ÿå¿ããŠãããå®éã®ä¿è·ãæäŸãããšæ³å®ã§ããŸããããŸãã¯ããã«çåãåããããšãã§ããŸããïŒ
- é°æ¹¿ãªäžéè
ãã身ãå®ãããã«ããžã£ã³ãã®ã¢ãªã¹ãšããã«äœããã¹ããïŒ
ãããã¯ãè¡šé¢çã«ãããæ·±ããããå€ãã®è³ªåã«ãããŸããã èŠãŠã¿ãŸãããã
çè«ã®ããã
ã€ã³ã¿ãŒãããäžã®ããŒãéã§ã®ããŒã¿ã®å®å
šãªéä¿¡ã¯ãHTTPSãããã³ã«ïŒHTTPãããã³ã«æ¡åŒµïŒãä»ããŠè¡ãããéä¿¡ãããããŒã¿ã¯SSL / TLSæå·åãããã³ã«ïŒTLSã¯SSL 3.0ã«åºã¥ããŠéçºãããæšæºïŒã«ã«ãã»ã«åãããé察称ã¢ã«ãŽãªãºã ã®äœ¿çšã«åºã¥ããŠããŸãå
¬ééµæå·å-RSAã é察称æå·åã®äžè¬çãªåé¡ã¯ãå
¬éããŒã®ä¿¡é Œæ§ãæ€èšŒããããšãé£ããããšã§ãã ãããã£ãŠãå
¬ééµã¢ã«ãŽãªãºã ã«åºã¥ããã¹ãŠã®æå·åãããã³ã«ã§ã¯ãä¿¡é Œã®åé¡ãæ ¹æ¬çã«éèŠã§ãã ã€ãŸãããµãŒããŒããåä¿¡ããå
¬éããŒãããã¹ãŠã®HTTPSãã©ããããäžéè
ãããã¯ãŒã¯ã»ã°ã¡ã³ãã«ããããŒã§ã¯ãªããå®éã«ãµãŒããŒãå®å
šãªéä¿¡ãã£ãã«ã確ç«ããããã«äœ¿çšããããŒã§ããããšã確èªããæ¹æ³
sslsniffãžã®ãã©ãã£ãã¯ã ä¿¡é Œã®åé¡ããããŸãã
èªèšŒå±
æŽå²çã«ã圌ãã¯PKIïŒPublic Key InfrastructureïŒãªã©ã®èªèšŒæè¡ã䜿çšããŠä¿¡é Œã®åé¡ã解決ãå§ããŸããã ããã¯ãCAãä»ããŠå
¬éããŒããŠãŒã¶ãŒã®IDã«æ¥ç¶ããå
æ¬çãªæž¬å®ã·ã¹ãã ã§ãã PKIã¯ãå
¬éããŒæå·åã·ã¹ãã ãšããã€ãã®åºæ¬ååã®äœ¿çšã«åºã¥ããŠããŸãã
- ç§å¯éµã¯ãã®ææè
ã®ã¿ãç¥ã£ãŠããŸãã
- CAã¯å
¬ééµèšŒææžãäœæããããã«ãã£ãŠãã®éµãèªèšŒããŸãã
- 誰ããäºããä¿¡é ŒããŠããŸãããã誰ããCAãä¿¡é ŒããŠããŸãã
- CAã¯ã察å¿ããç§å¯ããŒãææããç¹å®ã®äººç©ã«å¯ŸããŠãå
¬éããŒã®æææš©ã確èªãŸãã¯åè«ããŸãã
å®éãPKIã¯CAãäž»èŠã³ã³ããŒãã³ããšããã·ã¹ãã ã§ããããŠãŒã¶ãŒã¯CAãä»ããŠçžäºã«å¯Ÿè©±ããŸãã
ããã¯æ¬¡ã®ããã«æ©èœããŸããããã¯ãã¢ãªã¹ãšä»ã®å人ã圌ãšå®å
šãªæ¥ç¶ã確ç«ã§ããããã«ããããšèããŠããŸãã 圌ã¯ãå
¬ééµãšä»ã®ããŒã¿ïŒååãäœæãªã©-蚌ææžã«å«ãŸãããã¹ãŠïŒãšãšãã«CAã«æ¥ãŠãäœããã®æ¹æ³ã§èº«å
ã確èªãïŒå€ãã®å Žåãåã«é»åã¡ãŒã«ã§ãããè¡ããŸãïŒããŒã CAã¯åœŒã«èšŒææžãçºè¡ããŸãã 次ã«ãBobã¯ãããå人ã«æž¡ããŸããå人ã¯ãå®å
šã«ä¿¡é ŒããŠããCAã®ããžã¿ã«çœ²åããã§ãã¯ããããšã§ãBobã«æ¬åœã«å±ããŠããããšã確èªã§ããŸãã
åé¡
åé¡ã¯äœã§ããïŒ åé¡ã¯ã圌ããããªããä¿¡é Œãã人ãããªãã®ããã«æ±ºããããšã§ãã ãªãœãŒã¹ã®ææè
ããããšãã°Comodoãã蚌ææžãåãåãããšã決å®ãããã®ç¬éã«-ããªããä¿¡é Œããªããã°ãªããªã人ãããªãã®ããã«æ±ºå®ããŸãã 誰ãã圌ã®ãªãœãŒã¹ã¯åœŒã®ããã§ããã蚌ææžãåãåãçžæã¯åœŒæ¬¡ç¬¬ã ãšèšããããããŸããã ã¯ãããã ãããŒã¿ã¯ïŒããšãã°ã¯ã¬ãžããã«ãŒãããŒã¿ïŒãã®ãªãœãŒã¹ã¯ããªãã®ãã®ã§ãïŒ ãããŠãããã圌女ã®æ¯èŠªã¯åé¡ã§ãïŒ èªèšŒã»ã³ã¿ãŒã®æ¢åã®ã·ã¹ãã ã®ä¿¡é Œæ§ã«èª°ãçåãåããã圌ããå®ç§ã«äœæ¥ãè¡ããªãããã¹ãŠãããŸãããã§ãããããããã§ã¯ãããŸããã UTã¯æ°éäŒæ¥ã§ãã圌ãã¯ãããªãèªèº«ã®å©å·±çãªå©çãè¿œæ±ããè³briãè
è¿«ãè
è¿«ãåããããšãã§ããããªãã«ç¥ãããŠããªãçããŠãã人ã
ãéããŸãã CAã¯éšå€è
ïŒå¥åããã«ãŒïŒã«ãã£ãŠäŸµå®³ãããå¯èœæ§ããããŸãã ä»å¹Žã®æ¥ïŒ
link ïŒã«çºçããComodo CAã®éšã
ãã話ãæãåºãããšãã§ããŸãããã®é
ããµã€ããŒç¯çœªè
ã«ãã£ãŠæž
ç®ãã ã
å
æ¥ DigiNotar CAïŒ
link1 ã
link2 ïŒã§äºä»¶ã
æž
ç®ãããŸãã ã DigiNotarã§ã圌ãã¯ã©ããããããåé¡ã解決ããŸãã-ãã©ãŠã¶ã®ã«ãŒã蚌ææžã®ãªã¹ãããå°çã«ããããã«ããããããã¯çµãããŸããïŒ
誀çºè¡ã®ç¯å²ãæ確ã§ãªããããç§ãã¡ã¯Firefoxã®æ°ããããŒãžã§ã³ããªãªãŒã¹ããŠããŸã...ãŸããªãåãæ¶ãDigiNotarã«ãŒããä¿¡é ŒããŸãïŒã ããããComodoã¯DigiNotarã§ã¯ãªãããã倧ããªéã§ãã ã³ã¢ãã¯ã©ããªããŸãããïŒ èª°ããäžå¹³ãèšã£ãŠãäžå¹³ãèšã£ãŠå¿ããŸããã Comodoããã©ãŠã¶ã®ã«ãŒã蚌ææžã®ãªã¹ãã«èŒã£ãŠããããã«ã蚌ææžã販売ããŠããã®ã§ãComodoã¯åããŸãŸã§ãã éãã«ç ãããã©ãŠã¶ã®èªèšŒå±ãªã¹ãã«ç»é²ãããŠãã人ãä¿¡é Œãç¶ããããšãã§ããŸãã ãããŠããããã¯å ±éã§åãäžããããã±ãŒã¹ã ãã§ããã誰ã«ã話ãããªãã£ãã±ãŒã¹ãèªåèªèº«ããç¥ããªãã£ãã±ãŒã¹ãçŸæç¹ã§æå¹ãªæ£åŒãªèšŒææžã¯ããã€ãããŸããïŒ ãããŠãå€éšããèªèšŒæ©é¢ãèªèšŒããäœæ¥ãå±éºã«ãããæªç¥ã®æ»æè
ã®èŠå ãé€å€ãããšããŠãããããã®ã»ã³ã¿ãŒèªäœã®èå°è£ã§äœãèµ·ãã£ãŠããã®ã§ããããïŒ ã¹ãã·ã£ã«ã®ä»£è¡šè
ã¯ã©ãã§ããã ãµãŒãã¹ïŒ ã§ãããåŠæ³ïŒ ãã®èšäºãšit-
Law Enforcement Devices UnderSSL SSLã®ãªã³ã¯ã
ã芧ãã ãã ã äžè¬çã«ãå°ããªåé¡ã¯ã誰ãèšã£ãŠãããããã¯ååšããŸãããç®ãèŠããªã人ã ããããããç®ã«ããŸããã
解決ç
ãåç¥ã®ããã«ã蚌ææžã€ã³ãã©ã¹ãã©ã¯ãã£ãç·šæããããã®ã¢ãã«ã«ã¯ãéäžåïŒPKIïŒãšåæ£åïŒããããä¿¡é Œãããã¯ãŒã¯-ä¿¡é Œã®Webã«åºã¥ããŠå®è£
ïŒã®2ã€ããããçŸåšPGP / GPGãããã¯ââãŒã¯ã§æãåºã䜿çšãããŠããŸãã éäžåã¢ãã«ã®ãã¹ãŠã®å©ç¹ã«ã€ããŠã¯äžèšã§èª¬æããŸããã åäžã®èªèšŒå
ãååšããªãåæ£ã·ã¹ãã ã«ã€ããŠèããŠã¿ãŸããããéã«ãåãŠãŒã¶ãŒã¯ãä»ã®å
¬ééµã®èªèšŒãä¿¡é Œãã人ãšä¿¡é Œããªã人ãç¬èªã«æ±ºå®ããããã«ãã£ãŠå人ã®ä¿¡é Œãããã¯ãŒã¯ãäœæããŸãã ãã®ã¢ãããŒãã¯ãæªæã®ãã圱é¿ã«å¯Ÿããã·ã¹ãã ã®æè»æ§ãšå®å®æ§ãæäŸããŸããåæ£ã·ã¹ãã ã®1ã€ã®ããŒãã«åœ±é¿ãäžããããšãã§ããŸãïŒãã®å Žåãä¿¡é Œãããã¯ãŒã¯ããé€å€ããŸãïŒã
äžå€®éäžåã¢ãã«ãä¿®æ£ã§ããŸããããã«åºã¥ããŠããªãœãŒã¹èªäœãç¹å®ã®CAã§èšŒææžãèŠæ±ããããšã§ä¿¡é Œãéå§ããããã«ããããã¹ãŠã®é¡§å®¢ããã®ç¹å®ã®CAãšå¯Ÿè©±ããŠä¿¡é Œæ§ãæ€èšŒããåæ£åã¢ãããŒããé©çšããããšã矩åä»ããŸããã¯ã©ã€ã¢ã³ããéå§ããçžäºäœçšã¯æ¬¡ã®ãšããã§ãã
- ã¯ã©ã€ã¢ã³ãã¯ãç¹å®ã®ãµã€ããšã®å®å
šãªéä¿¡ãã£ãã«ã確ç«ããããšèããŠããŸãã 圌ã¯ãã®ãµã€ãã«ã¢ã¯ã»ã¹ãã圌ããSSL蚌ææžãåãåããŸãã åé¡ã¯ãããã¯ãã®ãµã€ãã®èšŒææžãªã®ããäžéè
ãããæãã蚌ææžãªã®ãïŒ ç¢ºèªããå¿
èŠããããŸãã
- ã¯ã©ã€ã¢ã³ãã¯ãèªåãäœæãã蚌ææžãµãŒããŒã®ãªã¹ãã«ç®ãéããããããã«ããã®ãµã€ãã§ã©ã®èšŒææžã衚瀺ãããŸããïŒããšå°ããŸãã
- ãµãŒããŒãªã¯ãšã¹ãã«å¿çããŠãæå®ããããµã€ãã«ã¢ã¯ã»ã¹ãããããã蚌ææžãåä¿¡ããèŠæ±å
ã®ã¯ã©ã€ã¢ã³ãã«è»¢éããŠã眲åã確èªããŸãã
- ã¯ã©ã€ã¢ã³ãã¯ããµãŒããŒããçŽæ¥åãåã£ã蚌ææžãšèšŒææžãµãŒããŒããåãåã£ã蚌ææžãæ¯èŒããŸãã
- 蚌ææžãäžèŽããå Žå-ãã¹ãŠãæ£åžžã§ããã°ãç§ãã¡ã¯åããŸãã ãããã¯äžèŽããŸãããè¿ãã®ã©ãããäžéè
ã§ãããåââé¡ãçºçããå¯èœæ§ããããŸãã
å®è£
å
æåãã«ã©ã¹ãã¬ã¹ã§éå¬ããã
BlackHatäŒè°ã§ãã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãã®ç 究çã§ããç¥ãããŠãã
Moxie Marlinspike㯠ã
Convergence ïŒèªèšŒæ©é¢ã·ã¹ãã ã®ã¢ãžã£ã€ã«ãåæ£ãå®å
šãªä»£æ¿ïŒãšåŒã°ãããããžã§ã¯ããçºè¡šããŸããã ã ãããžã§ã¯ãã®äžç°ãšããŠãèªèšŒãµãŒããŒã¯Notaryãšåä»ããããŸããã
FireFoxãã©ã°ã€ã³ãããŒãã³ã°ããŠã€ã³ã¹ããŒã«ããŸã
-onvergence ïŒ

å
¬èšŒäººãªã¹ããäœæããŸãã ãããè¡ãã«ã¯ãæ¢åã®ãµãŒããŒã®ãªã¹ãã䜿çšã§ããŸã
-Notary list ãNotary-serversãäžããããšãã§ããŸã-Running
-a-Notary ãæåãš2çªç®ãè¡ãããšãã§ããŸãã


ã·ã¹ãã èšå®ã®æ©èœ-æ€èšŒãããå€ãªãã·ã§ã³ãå€æŽããããšã«ãããåŠæ³ã®ãããå€ã調æŽã§ããŸãã

以åã¯ãåŸæ¥ã®èªèšŒæ©é¢ã·ã¹ãã ã®äœ¿çšã¯æ¬¡ã®ãšããã§ããã

ãã©ã°ã€ã³ãã¢ã¯ãã£ãã«ããConvergenceã«ç§»åããŸãã

ããŠããªããšïŒ
- ãµã€ã管çè
ã¯ãµãŒããŒåŽã§äœãããå¿
èŠã¯ãããŸããã ã€ã³ã¿ãŒãããã®æ°ããèªèšŒã·ã¹ãã ãžã®ç§»è¡ãæé
ããå¿
èŠã¯ãããŸããã ãã¹ãŠããã§ã«æ©èœããŠããããããã¹ãŠã®äž»èŠãªãã©ãŠã¶ã«ãã©ã°ã€ã³ãå®è£
ããã ãã§ãã
- ã¯ã©ã€ã¢ã³ãã¯èªåã誰ã«çœ²åããããæ°ã«ããªããããèªå·±çœ²å蚌ææžã«é¢ããèŠåã¯ãããããŸãããã¯ã©ã€ã¢ã³ãã¯ãMan-In-The-Middleã§ã¯ãªããµãŒããŒã«ãã£ãŠæäŸããã蚌ææžã䜿çšããããšã確èªããããšãéèŠã§ãã
ãããã«
誰ãä¿¡é Œããå¿
èŠããããŸããïŒ
...ãããŠã©ããããã®æéïŒ
å®ããããäžé£ã®äººã
ã
ãŸãã¯ãåæãè©Šãæéã§ããïŒ