ãšã³ãããŒãšã³ãæå·åïŒE2EïŒã䜿çšããã¡ãã»ã³ãžã£ãŒã§ã¯ããŠãŒã¶ãŒãããŒã管çããŸãã 圌ããããã倱ããšã圌ã¯åœŒã®ã¢ã«ãŠã³ãããªã»ããããããšãäœåãªããããŸãã
ã¢ã«ãŠã³ãã®ãªã»ããã¯å±éºã§ãã ããªãã¯å
¬ééµãæ¶å»ãããã¹ãŠã®äŒè©±ã§æå·ã®èŠç¥ãã¬äººã«ãªããŸãã IDã埩å
ããå¿
èŠããããŸããã»ãšãã©ãã¹ãŠã®å Žåãããã¯å人çãªäŒè°ãšåé£çµ¡å
ãšã®ãã»ãã¥ãªãã£çªå·ãã®æ¯èŒãæå³ããŸãã MiTMããã®å¯äžã®ä¿è·ã§ãããã®ãããªãã¹ããå®éã«ã©ã®ãããã®é »åºŠã§åããŸããïŒ
ã»ãã¥ãªãã£çªå·ãçå£ã«èããŠããå Žåã§ããäŒè°ã§å¹Žã«äžåºŠã ãå€ãã®ãã£ããããŒãããŒã衚瀺ããããããè¡ãè©°ãŸã£ãŠããŸãã
ããããããã¯ãã£ãã«èµ·ãããŸããããïŒ
ãªã»ããã¯ã©ã®ãããã®é »åºŠã§çºçããŸããïŒ åçïŒã»ãšãã©ã®E2Eãã£ããã¢ããªã±ãŒã·ã§ã³ã§ã¯åžžã«ã
ãããã®ã¡ãã»ã³ãžã£ãŒã§ã¯ãæå·åãèœãšãããµãŒããŒãä¿¡é Œãå§ããã ãã§ããïŒ1ïŒæ°ããé»è©±ã«åãæ¿ãããã³ã«ã ïŒ2ïŒäººãæ°ããé»è©±ã«åãæ¿ãããã³ã ïŒ3ïŒé»è©±ã®å·¥å Žåºè·æèšå®ã«ãªã»ããããããšãã ïŒ4ïŒå¯Ÿè©±è
ãå·¥å Žèšå®ãžã®ãªã»ãããå®è¡ãããšãã ïŒ5ïŒã¢ããªã±ãŒã·ã§ã³ãã¢ã³ã€ã³ã¹ããŒã«ããŠåã€ã³ã¹ããŒã«ãããšãããŸãã¯ïŒ6ïŒè©±ããŠãã人ããããã¢ã³ã€ã³ã¹ããŒã«ããŠåã€ã³ã¹ããŒã«ãããšãã å€æ°ã®é£çµ¡å
ãããå Žåãæ°æ¥ããšã«ãªã»ãããçºçããŸãã
ãªã»ããã¯éåžžã«å®æçã«è¡ãããããããããã®ã¢ããªã±ãŒã·ã§ã³ã¯ãããåé¡ã§ã¯ãªããµããããŸãã
ã»ãã¥ãªãã£ã®ã¢ããã°ã¬ãŒããããããã§ãïŒ ïŒããããããã§ã¯ãããŸããïŒæ¬åœã«è±è
ã§ããïŒ
æå·åã§ã¯ãçšèªTOFUïŒãæåã®äœ¿çšã«å¯Ÿããä¿¡é ŒãïŒã¯ã2人ã®åœäºè
ãåããŠè©±ããšãã®å¶ç¶ã®ã²ãŒã ãè¡šããŸãã 調åè
ã¯çŽæ¥äŒãã®ã§ã¯ãªããããããã®åŽã«è²¬ä»»ãè² ããŸã...ãããŠãåœäºè
ãèªããæ瀺ããåŸãååŽã¯ããŒã泚ææ·±ãç£èŠããŠãäœãå€æŽãããŠããªãããšã確èªããŸãã ããŒãå€æŽãããå Žåãäž¡åŽãã¢ã©ãŒã ãçºããŸãã
ãã®ãããªç¶æ³ã§ãªã¢ãŒããã¹ãã®ããŒãSSHã§å€æŽãããå Žåããæ£åžžã«åäœãããããšã¯ãããŸããããå®å
šã«å¥œæŠçã«ãªããŸãã
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the RSA key sent by the remote host is
00:11:22:33:44:55:66:77:88:99:aa:bb:cc:dd:ee:ff
Please contact your system administrator.
Add correct host key in /Users/rmueller/.ssh/known_hosts to get rid of this message.
Offending RSA key in /Users/rmueller/.ssh/known_hosts:12
RSA host key for 8.8.8.8 has changed and you have requested strict checking.
Host key verification failed.
ãããæ£ããåäœã§ãã ãããŠãèŠããŠãããŠ
ãã ãããå°ããªèŠåãåºããŠããã«äœæ¥ãé²ããããšãã§ããã°ãããã¯è±è
ã§ã¯ãããŸããã ã©ããã®ãã巚倧ãªé è骚ãèŠããã¯ãã§ãã
ãã¡ããããããã®ã€ã³ã¹ã¿ã³ãã¡ãã»ã³ãžã£ãŒã¯ããŠãŒã¶ãŒã«èŠåãããããããã¹ãŠãæ£åžžã§ãããšäž»åŒµããŸãã å¿
èŠã«å¿ããŠãã»ãã¥ãªãã£çªå·ã確èª
ã§ããŸãã ãããç§ãã¡ãåæããªãçç±ã§ãïŒ
- æ€èšŒã¯é »ç¹ã«è¡ããããããå®è¡ãããŸããã
- ãã§ãã¯ãåžããŸãã
- ã»ãã¥ãªãã£ãå¿é
ããŠããå人ã®å€§ãŸããªèª¿æ»ã§ããã誰ããã®ãã¹ããå¿é
ããŠããªãããšã瀺ãããŸããã
- ãããã£ãŠãããã¯ãµãŒããŒã«å¯Ÿããä¿¡é ŒãšSMSãžã®ä¿¡é Œã«ãããŸããïŒãŸãïŒïŒ äœåºŠãäœåºŠã ã
- æåŸã«ããããã®ã¢ããªã±ãŒã·ã§ã³ã¯ãã®æ¹æ³ã§åäœããªãã¯ãã§ãã ç¹ã«ããã€ã¹ãå€æŽãããšãã éåžžã®éåžžã®ã±ãŒã¹ã¯ã¹ã ãŒãºãã€å®å
šã«åŠçã§ããŸããããŸãã«ç¶æ³ãæªåããã»ã©ãèŠãç®ãæªããªããŸãã ããã«ãããŒããŒã¹ãœãªã¥ãŒã·ã§ã³ã玹ä»ããŸãã
è±è
ãšåŒã¶ã®ãããã
éåžžã«å¹æçãªæ»æããããŸãã ã€ããã¢ãªã¹ãšããã®æ¢åã®äŒè©±ã«äŸµå
¥ãããããã®éã«ç«ã¡ãããšä»®å®ããŸãã ã¢ãªã¹ãšããã¯é·å¹Žé£çµ¡ãåãåã£ãŠãããé·ãéè±è
ã亡ãããŠããŸãã
Eveã¯ãAliceã«Bobãæ°ããé»è©±ãè²·ã£ããšæãããã ãã§ãã
ããïŒã€ãïŒïŒã¡ãã£ãšãã¡ãã£ãšïŒ
ã¢ãªã¹ïŒãšãããïŒ æ°ããã»ãã¥ãªãã£çªå·ãããããã§ãã
BobïŒEveïŒïŒã¯ããç§ã¯iPhone XSã賌å
¥ããŸãããããã¯è¯ãé»è©±ã§ããšãŠãæºè¶³ããŠããŸãã RWC 2020ã§ã»ãã¥ãªãã£çªå·ã亀æããŸããããçŸåšã®ãã£ãã©ã€ã³ã®äœæã¯ãããŸããïŒ ãµã³ãã©ã³ã·ã¹ã³ã«ããéã«åœŒå¥³ãé©ããããã§ãã
ã¢ãªã¹ïŒç§ã¯æ¯èŒã§ããªããAndroid 4ã©ã€ãïŒ ã¯ããCozy Street 555ã
ãããã£ãŠãã»ãšãã©ã®æå·åãããã¡ãã»ã³ãžã£ãŒã¯ãTOFUã³ã³ãã©ã€ã¢ã³ã¹ãç²åŸããå¯èœæ§ã¯äœãã§ãã ããã¯TADAã«äŒŒãŠããŸã-ããã€ã¹ãè¿œå ããåŸã®ä¿¡é Œã ããã¯ãæ¢åã®äŒè©±ã«æªæã®ããå®è£
ã®æ©äŒãäœæãããããæ¶ç©ºã®åé¡ã§ã¯ãªããå®éã®åé¡ã§ãã æ¬åœã®è±è
ã§ã¯ã誰ããããªãã®äŒè©±ã«èå³ãæã€æãŸã§ã«ã圌ãã¯ããã«æµžéããããšãã§ããŸããã TADAã䜿çšãããšããããå¯èœã«ãªããŸãã
ã°ã«ãŒããã£ããã§ã¯ãç¶æ³ã¯ããã«æªåããŸãã ãã£ããã®åå è
ãå€ãã»ã©ãã¢ã«ãŠã³ããé »ç¹ã«åã€ã³ã¹ããŒã«ãããŸãã ããã20人ã®äŒç€Ÿã§ã¯ãããã¯çŽ2é±éã«1åçºçãããšèŠç©ãã£ãŠããŸãã ãããŠãäŒç€Ÿã®ãã¹ãŠã®äººããã®äººã«äŒããªããã°ãªããŸããã å人çã«ã ããããªããšã1人ã®ã»ãããŸãã¯ããã«ãŒã«ãã£ãŠãã£ããå
šäœãå±éºã«ãããããŸãã
解決ç
ç§å¯éµãµãŒããŒãžã®ä¿¡é Œãæ瀺ããªãè¯ã解決çã¯ãããŸããïŒ ç§ãã¡ã¯ãè€æ°ã®ããã€ã¹ã«å¯Ÿããçã®ãµããŒãããããšèããŠããŸãã ããã¯ãããªãã®åæ§ãè¡šãäžé£ã®ããã€ã¹ã管çããããšãæå³ããŸãã æ°ããããã€ã¹ïŒé»è©±ãã©ãããããããã¹ã¯ãããã³ã³ãã¥ãŒã¿ãŒãiPadãªã©ïŒãåãåããšãç¬èªã®ããŒãã¢ãçæããã以åã®ããã€ã¹ãããã«çœ²åããŸãã ããã€ã¹ãçŽå€±ããå Žåãæ®ãã®ããã€ã¹ã®1ã€ãããåé€ãããŸãã æè¡çã«ã¯ããã®ãããªåé€ã¯ãªã³ãŒã«ã§ããããã®å Žåãäœããã®çš®é¡ã®ããŒã®å転ãèªåçã«çºçããŸãã
ãã®çµæã
察è«è
ãååãæ°ããããã€ã¹ãåãåã£ããšãã«ãµãŒããŒãä¿¡é ŒããããçŽæ¥äŒã£ããããå¿
èŠã¯ãããŸãã ã åæ§ã«ãããã€ã¹ãæåŸã§ãªãã£ãå Žåãããã€ã¹ãåãå€ããšãã«ãµãŒããŒãä¿¡é ŒããããçŽæ¥äŒã£ããããå¿
èŠã¯ãããŸããã èŠåã衚瀺ããå¿
èŠãããã®ã¯ã誰ãããã¹ãŠã®èšå®ã«å®éã«ã¢ã¯ã»ã¹ã§ããªããªã£ããšãã ãã§ãã ãã®å Žåã次ã®ãããªé倧ãªèŠåã衚瀺ãããŸãã
ç¹ã«Specialããã®çµæããªã»ããããã³åã€ã³ã¹ããŒã«ãããã¢ã«ãŠã³ãã¯ã¯ããã«å°ãªããªããŸãã æŽå²çã«ãããŒããŒã¹ã§ã¯ãããã€ã¹ã®ã¢ããªã³ãšã¬ãã¥ãŒã®åèšæ°ã¯ã¢ã«ãŠã³ãã®è§£çŽæ°ã®
10åã§ãïŒããã«ã€ããŠèšèã«ããå¿
èŠã¯ãããŸãããããã¯ããŒã¯ã«ããªãŒã§å
¬éãããŠããŸãïŒã ä»ã®ã€ã³ã¹ã¿ã³ãã¡ãã»ã³ãžã£ãŒãšã¯ç°ãªããæè¿ããŒãåã€ã³ã¹ããŒã«ãã人ãšè©±ããŠãããšãã«ãæ¬åœã«æãããèŠåã衚瀺ã§ããŸãã
ããã€ã¹ç®¡çã¯è€éãªãšã³ãžãã¢ãªã³ã°æäœã§ãããäœåºŠãä¿®æ£ãããŠããŸãã æ¢åã®ããã€ã¹ã¯ãæ°ããããã€ã¹ã®å
¬ééµã«çœ²åããæ°ããããã€ã¹ã®å
¬ééµã®ãã¹ãŠã®éèŠãªç§å¯ããŒã¿ãæå·åããŸãã ãŠãŒã¶ãŒã®æ³šæç¯å²ã«ã€ããŠè©±ããŠããããããã®æäœã¯è¿
éã«ïŒ1ç§ä»¥å
ã«ïŒå®è¡ããå¿
èŠããããŸãã ãã®çµæãããŒããŒã¹ã¯ããŒéå±€ã䜿çšãããããå€ãããã€ã¹ãã32ãã€ãã®ç§å¯ããŒã¿ã転éããå Žåãæ°ããããã€ã¹ã¯ãã¹ãŠã®é·ææå·ããŒã¿ââãèŠãããšãã§ããŸãïŒè©³çŽ°ã«ã€ããŠã¯ã以äžã®FAQãåç
§ããŠãã ããïŒã ããã¯å°ãé©ããããããŸãããã
ããããŸãã«æå·åã®ãã€ã³ãã§ã ã ç§å¯ç®¡çã®åé¡ã解決ããã®ã§ã¯ãªããã·ã¹ãã ã®ã¹ã±ãŒã©ããªãã£ãé«ããã ãã§ãã
ã»ãã¥ãªãã£ã®å
šäœå
ããã§ãããŒããŒã¹ã¢ããªã±ãŒã·ã§ã³ã®4ã€ã®åºæ¬çãªã»ãã¥ãªãã£ããããã£ãå®åŒåã§ããŸãã
- é·æã«ãããç§å¯éµã¯ãããããäœæãããããã€ã¹ããé¢ããããšã¯ãããŸãã
- ãã«ãããã€ã¹ã®å®å
šãµããŒãã«ãããã¢ã«ãŠã³ãã®ãããããæå°éã«æããŸã
- ããŒã®åãæ¶ããæªæãæã£ãŠé
延ãŸãã¯ããŒã«ããã¯ããããšã¯ã§ããŸãã
- ã¯ããªãæéã¡ãã»ãŒãžã䜿çšããçŽæ¥ç§å¯
æåã®2ã€ã¯ç解ã§ããããã§ãã 3çªç®ã¯ãããã€ã¹ã®ãªã³ãŒã«ãäºæ³ãããæ£åžžãšèŠãªãããèšèšã§éèŠã«ãªããŸãã ã·ã¹ãã ã«ã¯ãæªæã®ãããµãŒããŒãããã€ã¹ã®ã¬ãã¥ãŒãé
ãããããšãã§ããªãããšããã§ãã¯ããå¿
èŠããããŸãã
4çªç®ã®ã»ãã¥ãªãã£
æ©èœã®è©³çŽ°ã«ã€ããŠã¯ã
çåœã¡ãã»ãŒãžã³ã°ã«é¢ããèšäºãåç
§ããŠ
ãã ãã ã
å€ãã®æ°ããæå·åããã¹ãŠãæ£ããå®è£
ãããŠããŸããïŒ
Keybaseã¯ããããŸã§ã«Keybaseã«ãã£ãŠå®è£
ãããããšã¯ãªããç§åŠèšäºã«ãèšèŒãããŠããŸããã æå·å
ãããã³ã«ãèªåã§çºæããå¿
èŠããããŸããã 幞ããªããšã«ãããããç¶æ³ã«å¯Ÿå¿ãããåžè²©ã®æšæºåãããåºã䜿çšãããŠãã
æå·åã¢ã«ãŽãªãºã ããããããããŸãã ãã¹ãŠã®ã¯ã©ã€ã¢ã³ãã³ãŒãã¯
å
¬éãããŠããŸãã çè«çã«ã¯ã誰ã§ãèšèšãŸãã¯å®è£
ãšã©ãŒãèŠã€ããããšãã§ããŸãã ããã
ãå
éšæ§é ã
å®èšŒããå®å
šãªåæã®ããã«æé«ã®ã»ãã¥ãªãã£ç£æ»äŒç€Ÿãéãããã£ãã®ã§ãã
æ¬æ¥ãNCCã°ã«ãŒã
ã¬ããŒããçºè¡šãããã®çµæã«éåžžã«åæ°ã¥ããããŸããã ããŒããŒã¹ã¯ç£æ»ã«10äžãã«ä»¥äžãè²»ãããNCCã°ã«ãŒãã¯ãããã¬ãã«ã®ã»ãã¥ãªãã£ããã³æå·åã®å°é家ãéããŸããã 圌ãã¯ç§ãã¡ã®å®è£
ã§2ã€ã®éèŠãªãšã©ãŒãçºèŠããããã«ä¿®æ£ããŸããã ãããã®ãã°ã¯ããµãŒããŒãæªæãæã£ãŠåäœããå Žåã«ã®ã¿çºçããå¯èœæ§ããããŸãã 圌ãããã®ããã«æ¯ãèããªãããšã¯ä¿èšŒã§ããŸãããããªãã¯ç§ãã¡ãä¿¡ããçç±ã¯ãããŸããã
ããããã€ã³ãã§ãïŒNCCããŒã ã¯çŽ æŽãããä»äºããããšä¿¡ããŠããŸãã 圌ããç§ãã¡ã®ã¢ãŒããã¯ãã£ãšå®è£
ãå®å
šã«ç解ããã®ã«è²»ãããæéãå°éããŠãã ããã 圌ãã¯æè¿ãã³ãŒãããŒã¹ã®ãã®éšåãç¹°ãè¿ãèŠãŠããŸãããéçºè
ã®æ³šæãåŒã埮åŠãªãšã©ãŒãèŠã€ããŸããã
ãã¡ãã®ã¬ããŒãã
ã芧ã«ãªããããããã質åã
ã芧ã«ãªãããšããå§ãããŸãã
ãããã質å
XYZ補åãã©ã®ããã«æ»æããŸããïŒ
èšäºããç¹å®ã®è£œåãžã®åç
§ãæ¢ã«åé€ããŸããã
ä»ã«äœïŒ
Keybaseã¯é»è©±çªå·ãå¿
èŠãšããã誰ããç¥ã£ãŠããã°TwitterãHackerNewsãRedditãGithubã®èå¥åãæå·ã§æ€èšŒã§ããããšãèªãã«æã£ãŠããŸãã
ãããŠ...ãŸããªã...ãã¹ããã³ã®ãµããŒãããããŸãã
é»è©±ãªãã€ã¬ã¯ãæ»æã¯ã©ãã§ããïŒ
å€ãã®ã¢ããªã±ãŒã·ã§ã³ã¯ãªãã€ã¬ã¯ããããæ»æãåãããããªã£ãŠããŸãã ã€ãã¯ã·ã§ããã³ã°ã»ã³ã¿ãŒã®ããªã¹ã¯ã«è¶³ãèžã¿å
¥ããã¢ãã€ã«ãªãã¬ãŒã¿ãŒã®ããã«ãããã®é»è©±çªå·ãããã€ã¹ã«è»¢éããããã«èª¬åŸããŸãã ãŸãã¯ãé»è©±ã§ä»£è¡šè
ã説åŸããŸãã ããã§ãEveã¯ã¡ãã»ã³ãžã£ãŒãµãŒããŒã§èªèšŒã§ããèªåãBobã§ãããšäž»åŒµããŸãã çµæã¯ãã¢ãªã¹ããããã€ãã®äŸã®ã»ããé«ãããã«èŠããŸãããã€ãã¯ãµãŒããŒã«äŸµå
¥ããå¿
èŠã¯ãããŸããã äžéšã®ã¢ããªã±ãŒã·ã§ã³ã¯ããã®æ»æããä¿è·ããããã«ãç»é²ãããã¯ããæäŸããŸãããããã©ã«ãã§ã¯è¿·æã§ãã
Keybaseãããã€ãã®ç§å¯éµããµãŒããŒã«éä¿¡ãããšèããŸãããïŒ
åæïŒ2014幎ãã2015幎åæïŒã§ã¯ãKeybaseã¯PGP Webã¢ããªã±ãŒã·ã§ã³ãšããŠæ©èœãããŠãŒã¶ãŒã¯èªåã®PGPéµããã¹ãã¬ãŒãºã§æå·åããããµãŒããŒã«ä¿åããæ©èœãéžæã§ããŸããïŒKeybaseã¯ç¥ããŸããã§ããïŒã
2015幎
9æã« ãæ°ããããŒããŒã¹ã¢ãã«ãå°å
¥ããŸããã PGPããŒã¯ãããŒããŒã¹ãã£ãããŸãã¯ãã¡ã€ã«ã·ã¹ãã ã§ã¯æ±ºããŠäœ¿çšãããŸããïŒäœ¿çšãããŸããïŒã
å€ãé»è©±ã¯æ°ããé»è©±ã§ããã«è¡šç€ºãããŸããïŒ
ä»ã®äžéšã®ã¢ããªã±ãŒã·ã§ã³ã§ã¯ããµãŒããŒãä»ããŠå€ãã¡ãã»ãŒãžãåæããããšã¯çŽæ¥ã®ç§å¯ã«åãããããæ°ããããã€ã¹ã§ã¯å€ãã¡ãã»ãŒãžã衚瀺ãããŸããã ããŒããŒã¹ã¢ããªã䜿çšãããšãç¹å®ã®ã¡ãã»ãŒãžããŸãã¯äŒè©±å
šäœããäžæçãªããã®ãšããŠæå®ã§ããŸãã ãããã¯äžå®ã®æéåŸã«ç Žæ£ããã2åæå·åãããŸãã1åã¯é·å¯¿åœã®ãã£ããæå·åããŒã䜿çšãããã1åã¯é »ç¹ã«å€æŽãããäžæããŒã䜿çšããŸãã ãããã£ãŠãäžæã¡ãã»ãŒãžã¯çŽæ¥ã®ç§å¯ãæäŸããé»è©±éã§åæããããšã¯ã§ããŸããã
éäžæçã¡ãã»ãŒãžã¯ããŠãŒã¶ãŒãæ瀺çã«åé€ããE2Eãæå·åã®ã¿ã§æ°ããSlackã¹ã¿ã€ã«ã®ããã€ã¹ãšåæãããŸã§æ®ããŸãïŒ ãããã£ãŠã誰ããããŒã ã«è¿œå ããããèªåã§æ°ããããã€ã¹ãè¿œå ãããšãã¡ãã»ãŒãžã®ãããã¯ã¯è§£é€ãããŸãã
次ã®æ®µèœã§åæã«ã€ããŠè©³ãã説æããŸãã
PUKã«ã€ããŠæããŠãã ããïŒ
2幎åã
ãŠãŒã¶ãŒåãããŒïŒPUKïŒãå°å
¥ããŸããã PUKã®ãããªãã¯ååã¯ããŠãŒã¶ãŒã®ãããªãã¯
sigchainã§ã¢ããã¿ã€ãºãããŸãã ç§å¯ã®ååã¯ãåããã€ã¹ã®å
¬ééµçšã«æå·åãããŸãã ã¢ãªã¹ãæ°ããããã€ã¹ãæºåããŠãããšãã圌女ã®å€ãããã€ã¹ã¯ãPUKã®ç§å¯ã®ååãšæ°ããããã€ã¹ã®å
¬ééµãç¥ã£ãŠããŸãã æ°ããããã€ã¹ã®å
¬éããŒçšã«PUKã®ç§å¯ã®ååãæå·åããæ°ããããã€ã¹ã¯ãã®æå·æããµãŒããŒããããŠã³ããŒãããŸãã æ°ããããã€ã¹ã¯PUKã埩å·åãããã¹ãŠã®é·åœã®ãã£ããã¡ãã»ãŒãžã«ããã«ã¢ã¯ã»ã¹ã§ããŸãã
ã¢ãªã¹ã¯ããã€ã¹ããªã³ãŒã«ãããã³ã«PUKãå€æŽããŸããããã«ãããæè¿ãªã³ãŒã«ãããããã€ã¹ãé€ããã¹ãŠã®ããã€ã¹ãæ°ããPUKãåãåããŸãã
ãã®åæã¹ããŒã ã¯ãåæã®ããŒããŒã¹PGPã·ã¹ãã ãšã¯æ ¹æ¬çã«ç°ãªããŸãã ããã§ãé¢ä¿ãããã¹ãŠã®ããŒã«ã¯32ãã€ãã®çã®ãšã³ããããŒãããããµãŒããŒãããã³ã°ã®å Žåã«ãã«ãŒããã©ãŒã¹ã§å£ããããšã¯ãããŸããã Trueã
Curve25519ãŸãã¯
Goã®
PRNGãç ŽæããŠããå Žåããã¹ãŠãç ŽæããŸãã ãã ããPUKåæã§ã¯ãä»ã®éèŠãªæå·åã®ä»®å®ã¯è¡ãããŸããã
倧ããªã°ã«ãŒããã£ããã¯ã©ãã§ããïŒ
tL; drã°ã«ãŒãã«ã¯ãããŒã«ã®å€æŽãã¡ã³ããŒã®è¿œå ããã³åé€ã®ããã®ç¬èªã®ç£æ»æžã¿çœ²åãã§ãŒã³ããããŸãã
ã»ãã¥ãªãã£ç 究è
㯠ãã°ã«ãŒããã£ããã«å¯Ÿããä»®æ³ãŠãŒã¶ãŒæ»æã«ã€ããŠ
æžããŠããŸãã ãŠãŒã¶ãŒã®ã¯ã©ã€ã¢ã³ããã°ã«ãŒãã¡ã³ããŒã·ãããæå·ã§æ€èšŒã§ããªãå Žåãæªæã®ãããµãŒããŒãã°ã«ãŒããã£ããã«ã¹ãã€ãŠã§ã¢ãšã¢ã«ãåã蟌ãããšãã§ããŸãã ããŒããŒã¹ã«ã¯ãããã§
ã°ã«ãŒãã®ç¹å¥ãªæ©èœãšãã圢ã§éåžžã«ä¿¡é Œæ§ã®é«ãã·ã¹ãã ããããŸãããããã«ã€ããŠã¯ä»åŸèª¬æããŸãã
NCC-KB2018-001ã«ã€ããŠè©±ããŠããããŸããïŒ
ãã®ãã°ã¯NCCç£æ»ã®æãéèŠãªçºèŠã§ãããšèããŠããŸãã ããŒããŒã¹ã¯äžå€ã®ããŒã¿æ§é ãç©æ¥µçã«äœ¿çšããŠããµãŒããŒã®ãããŸããããä¿è·ããŸãã ãã°ã®å Žåãæ£çŽãªãµãŒããŒãåé¿ãéå§ããå¯èœæ§ããããŸããã以åAã«èšã£ããããã°ãçºçãããããBãæå³ãããã ããããã¯ã©ã€ã¢ã³ãã«ã¯ããµãŒããŒã«ãã®ãããªæè»æ§ãèš±å¯ããªããšããå
±éã®ããªã·ãŒããããŸãããã°ã®å Žåã«ã¯ã
ããŒãã³ãŒãã£ã³ã°ãããäŸå€ããããŸãã
æè¿ã
Sigchain V2ãå°å
¥ã
ãŸãã ããã®ã·ã¹ãã ã¯ãæåã®ããŒãžã§ã³ã§ã¯æ£ããäºæž¬ã§ããªãã£ãã¹ã±ãŒã©ããªãã£ã®åé¡ã解決ããŸãã çŸåšãã¯ã©ã€ã¢ã³ãã¯ãåäžéãªã³ã¯ã®çœ²åã§ã¯ãªãã眲åãã§ãŒã³ã®æ«å°Ÿãã1ã€ã®çœ²åã®ã¿ãåä¿¡ãããµãŒããŒããååŸããæå·åããŒã¿ã䜿çšããæ¹ãçµæžçã§ãã ãããã£ãŠã顧客ã¯ç¹å®ã®çœ²åããã·ã¥ãæ€çŽ¢ãããµã€ã¯ã«ã«è¡ãæ©äŒã倱ããŸãããã以åã¯ãããã®ããã·ã¥ã䜿çšããŠããã®ããŒãã³ãŒãã£ã³ã°ãããäŸå€ã®ãªã¹ãã§äžè¯ãã§ãŒã³ãªã³ã¯ãæ€çŽ¢ããŸããã Sigchain V2ã®ãªãªãŒã¹ã®æºåãããŠããŸããããæœè±¡åã®ããã€ãã®å±€ã«åãããŠãããã®è©³çŽ°ãå¿ããŠãããããã·ã¹ãã ã¯ãµãŒããŒå¿çãããã£ãŒã«ããåçŽã«ä¿¡é ŒããŠããŸããã
NCCããã®ãšã©ãŒãçºèŠ
ãããšã
ä¿®æ£ã¯éåžžã«ç°¡åã§ããããã§ãŒã³ãªã³ã¯çœ²åããã·ã¥ã§ã¯ãªãããã§ãŒã³ãªã³ã¯ããã·ã¥ã䜿çšããŠããŒãã³ãŒãã£ã³ã°ãããäŸå€ãæ¢ããŸãã ã¯ã©ã€ã¢ã³ãã¯åžžã«ãããã®ããã·ã¥ãçŽæ¥èšç®ã§ããŸãã
ãã®ãšã©ãŒã¯ãSigchain V1ãšSigchain V2ãåæã«ãµããŒãããããã«å¿
èŠãªè¿œå ã®è€éãã«èµ·å ããããšããããŸãã ææ°ã®ã¯ã©ã€ã¢ã³ãã¯Sigchain V2ãªã³ã¯ãèšè¿°ããŸããããã¹ãŠã®ã¯ã©ã€ã¢ã³ãã¯ç¡æéã«ã¬ã¬ã·ãŒv1ãªã³ã¯ããµããŒãããå¿
èŠããããŸãã 顧客ã¯åããã€ã¹ã®ç§å¯éµã§ãªã³ã¯ã«çœ²åããããšãæãåºããŠãã ããã ãããã®ã¯ã©ã€ã¢ã³ãã¯åã«ãªãã©ã€ã³ã§ããå¯èœæ§ãããããããã¹ãŠã®é¡§å®¢ã劥åœãªæéå
ã«å±¥æŽããŒã¿ãäžæžããããã調æŽããããšã¯ã§ããŸããã
NCC-KB2018-004ã«ã€ããŠè©±ããŠããããŸããïŒ
001ïŒäžèšåç
§ïŒã®ããã«ãæ代é
ãã®ãœãªã¥ãŒã·ã§ã³ã®åæãµããŒããšæé©åã®ç¹å®ã®çµã¿åããã«å€±æããŸãããããã¯ãã·ã¹ãã ã®æäœçµéšãç©ãã«ã€ããŠéèŠã«æãããŸããã
Sigchain V2ã§ã¯ããŠãŒã¶ãŒã®æ€çŽ¢ã«å¿
èŠãªåž¯åå¹
ãåæžããããã«ããã§ãŒã³ã®ãµã€ãºããã€ãåäœã§åæžããŸãã ãã®ç¯çŽã¯ãæºåž¯é»è©±ã§ã¯ç¹ã«éèŠã§ãã ãããã£ãŠããã§ãŒã³ãªã³ã¯ã
JSONã§ã¯ãªã
MessagePackã§ãšã³ã³ãŒãã
ãŸã ã 次ã«ã顧客ã¯ãããã®ãã§ãŒã³ã®çœ²åã«çœ²åããŠæ€èšŒããŸãã NCCã®ç 究è
ã¯ãJSONãšMessagePackã®ããã«èŠããã眲åããäœæããããã®å·§åŠãªæ¹æ³ãçºèŠãã競åãåŒãèµ·ãããŠããŸãã JSONããŒãµãŒãæšæºã®GoããŒãµãŒããããå¹ççãªããŒãµãŒã«åãæ¿ãããšãã«ãæé©åäžã«ãã³ãŒãã®ãã®ãããŸãããæå³ããã«å°å
¥ããŸããã ãã®é«éããŒãµãŒã¯ããã®ããªã°ãããæ»ææ©èœãå«ãå®éã®JSONãèŠã€ããåã«ã倧éã®ãŽããéãã«ã¹ãããããŸããã ãã®ãšã©ãŒã¯ã
è¿œå ã®å
¥åæ€èšŒã«ãã£ãŠä¿®æ£ãã
ãŸã ã
Sigchain V2ã§ã¯ã眲åè
ãããã±ãŒãžã®åã«ã³ã³ããã¹ãã©ã€ã³ãã¬ãã£ãã¯ã¹ãšãã€ã
\0
眲åãä»ããããšã§ãæ€èšŒè
ã眲åè
ã®æå³ã«æ··ä¹±ããªãããã«ãããšãã
Adam Langleyã®ææ¡ãåãå
¥ããŸããã ãã®ã³ã³ããã¹ããã¬ãã£ãã¯ã¹ã¢ã€ãã¢ã®æ€èšŒåŽã«ã¯ãä»ã®ããªã°ãããæ»æã«ã€ãªããå¯èœæ§ã®ãããšã©ãŒããããŸããã
ãã¯ã€ããªã¹ãã§ãã®æ¬ é¥ããã°ããä¿®æ£
ããŸãã ã
äž¡æ¹ã®ãã°ãä¿®æ£ãããšããµãŒããŒã¯ããªã°ãããæ»æã®æªæã®ããè² è·ãæåŠããããããããã®è匱æ§ã®æªçšã¯ã䟵害ããããµãŒããŒã®å©ããåããŠã®ã¿å¯èœã§ãã
ããã¥ã¡ã³ãã¯ã©ãã«ãããŸããïŒ
https://keybase.io/docsä»åŸæ°ãæã®ãã¡ã«ãããã¥ã¡ã³ãã®äœæã«ããå€ãã®æéãè²»ãããŸãã
NCCã«ãããã®ã¹ããŒãã¡ã³ãã®è©³çŽ°ã«ã€ããŠã¯ãããã ããæ»æè
ã¯ããã§ãŒã³å
ã®åŸç¶ã®ãªã³ã¯ãåãæšãŠãããšã«ãããsigchainã®æŽæ°ãæåŠãããããŠãŒã¶ãŒã®sigchainã以åã®ç¶æ
ã«ããŒã«ããã¯ãããããããšãã§ããŸãã
ããŒããŒã¹ã¯ããµãŒããŒã€ã³ãã©ã¹ãã©ã¯ãã£ããŠãŒã¶ãŒèå¥åã®1ã€ã®çã®è¡šçŸããã£ããã£ããããšã匷å¶ããäžå€ã®è¿œå å°çšãããªãã¯ããŒã¿æ§é ãåºç¯å²ã«äœ¿çšããŸãã 䟵害ããããµãŒããŒãããŒã«ããã¯ã§ããªããããªæ¹æ³ã§ãããã€ã¹ã®ãªã³ãŒã«ãšã°ã«ãŒãã¡ã³ããŒã®åé€ãä¿èšŒã§ããŸãã ãµãŒããŒãäžè²«æ§ã®ãªããã¥ãŒã衚瀺ããããšã決å®ããå Žåããã®åå·®ã¯äžå€ã®ãããªãã¯ã¬ã³ãŒãã®äžéšã«ãªããŸãã ããŒããŒã¹ã®é¡§å®¢ãŸãã¯ãµãŒãããŒãã£ã®ç£æ»äººã¯ãæ»æåŸãã€ã§ãäžäžèŽãæ€åºã§ããŸãã ãããã®ä¿èšŒã¯ã競å補åã®ä¿èšŒãã¯ããã«äžåããæºåž¯é»è©±ãèšç®èœåãéãããŠããã客æ§ã®å®éçãªå¶éãèæ
®ããŠãã»ãŒæé©ã§ãããšèããŠããŸãã
ç°¡åã«èšãã°ãKeybaseã¯ä»äººã®çœ²åãçºæããããšã¯ã§ããŸããã ä»ã®ãµãŒããŒãšåæ§ã«ãããŒã¿ãä¿æã§ããŸãã ããããç§ãã¡ã®éæãªããŒã¯ã«ããªãŒã¯ãããããéåžžã«çæéä¿åããããã«èšèšãããŠãããåžžã«çºèŠå¯èœã§ãã
Keybaseã¯ã¢ã«ãŠã³ãã®ãªã»ãããã©ã®ããã«åŠçããŸããïŒ
ããŒããŒã¹ãŠãŒã¶ãŒãå®éã«ãã¹ãŠã®ããã€ã¹ã倱ã£ããšãïŒæ°ããããã€ã¹ãè¿œå ããããããã€ãã倱ã£ããããã®ã§ã¯ãªãïŒããªã»ããããå¿
èŠããããŸãã ã¢ã«ãŠã³ãããªã»ããããåŸããŠãŒã¶ãŒã¯åºæ¬çã«æ°èŠã§ããããŠãŒã¶ãŒåã¯åãã§ãã 圌ã¯ãã¹ãŠã®éµã倱ã£ããããããªã»ããæ瀺ãã«çœ²åããããšã¯ã§ããŸããã ãã®ä»£ãããKeybaseãµãŒããŒã¯ãMerkleããªãŒã«æ¶å»äžèœãªã¹ããŒãã¡ã³ããã³ãããããŸããããã¯ãªã»ãããæå³ããŸãã ã¯ã©ã€ã¢ã³ãã¯ããããã®æ瀺ãããŒã«ããã¯ããããšãäžå¯èœã«ããŸãã å°æ¥ã®èšäºã§ã¯ãç¹å®ã®ã¡ã«ããºã ã«ã€ããŠè©³ãã説æããŸãã
ãã®ãŠãŒã¶ãŒã¯ãæ°ããããŒã䜿çšããŠIDæ€èšŒïŒTwitterãGithubãªã©ïŒãå床远å ããå¿
èŠããããŸãã
ãµãŒããŒã¯ã誰ãã®ããŒã¯ã«ããªãŒãªãŒããåã«äº€æããŠããŸã£ããç°ãªãããŒã®ã»ãããã¢ããã¿ã€ãºã§ããŸããïŒ
NCCã®äœæè
ã¯ãMerkleããªãŒãªãŒããå®å
šã«äº€æããããã®çã®ããŒã»ãããå®å
šã«æ°ããåœã®ã»ããã«çœ®ãæãããæµå¯ŸçãªããŒããŒã¹ãµãŒããŒãæ€èšããŠããŸãã æ»æãµãŒããŒã«ã¯2ã€ã®ãªãã·ã§ã³ããããŸãã ãŸããBobã1ã€ã®ãã©ãŒã¯ã«å
¥ããŠãBobãå¥ã®ãã©ãŒã¯ã«å
¥ããŠäžçã®ç¶æ
ããã©ãŒã¯ã§ããŸãã 第äºã«ã圌ã¯ãæ£ããããããŒã®ã»ãããå«ãããŒã¯ã«ããªãŒã®ããŒãžã§ã³ãšåœã®ã»ãããå«ãä»ã®ããŒãžã§ã³ãå
¬éããããšã§ããããŒããããããšãã§ããŸãã ãããšå®æçã«å¯Ÿè©±ãããŠãŒã¶ãŒã¯ã以åã«ããŠã³ããŒãããããã®å±¥æŽã®ããŒãžã§ã³ããµãŒããŒããããŠã³ããŒãããæ°ããããŒãžã§ã³ã®æå¹ãªãã¬ãã£ãã¯ã¹ã§ããããšã確èªããããããã®æ»æãçºèŠããŸãã ãã¹ãŠã®ããŒããŒã¹ã®æŽæ°ãã¹ãã£ã³ãããµãŒãããŒãã£ã®ããªããŒã¿ãŒããã®æ»æã«æ°ã¥ããŸãã ãµãŒãããŒãã£ã®ããŒããŒã¹ããªããŒã¿ãŒãäœæããå Žåã¯ã倧ããªå ±é
¬ãæäŸã§ããŸãã Keybaseã®
max
ãåç
§ããŠãã ããã
ããã§ãªããã°ãããã«èªåŸåããªããŒã¿ãŒã®äœæãèšç»ããããšèããŠããŸããç§ãæåŸãŸã§èªãã ããšãä¿¡ããããŸããïŒ
ããªãã¯ãããèªã¿ãŸãããããããšããã äžã«ã¹ã¯ããŒã«ããŸãããïŒ