å½ç«å½ä¼å³æ¸é¤¨ã¯11æ25æ¥ãå¤é¨å§è¨ã«ããéçºä¸ã ã£ãæ°ããªé¤¨å ãµã¼ãã¹ã·ã¹ãã ã®éçºç°å¢ã䏿£ã¢ã¯ã»ã¹ãåããåé¡ã§ãä¸é¨ã®å人æ å ±ããµã¼ãã¹ã®å©ç¨æ å ±ãªã©ãæ¼ããããå¯è½æ§ãããã¨çºè¡¨ããã 2025å¹´3æ15ï½27æ¥ã«é¢è¥¿é¤¨ãå©ç¨ãã943人åã®å©ç¨è IDã¨ã9æ24æ¥ï½10æ22æ¥ã«æ±äº¬æ¬é¤¨ãé¢è¥¿é¤¨ãã¾ãã¯å½éåã©ã峿¸é¤¨ã§é»åæ å ±ã®å°å·ãµã¼ãã¹ãå©ç¨ãã4360人åã®ç³ãè¾¼ã¿æ å ±4ä¸373ä»¶ãæ¼ããããå¯è½æ§ããããç³ãè¾¼ã¿æ å ±ã«ã¯å©ç¨è IDãæ°åãè³ææ å ±ãéé¡ãå©ç¨ç®çãªã©ãå«ã¾ããã 該å½è ã«ã¯åå¥ã«éç¥ãè¡ãã¨ããã25æ¥æç¹ã§ãå人æ å ±ãã¤ã³ã¿ã¼ãããä¸ã«å ¬éããããªã©ã®äºæ¬¡è¢«å®³ã¯ç¢ºèªããã¦ããªããã®ã®ãå館ã¯èº«ã«è¦ãã®ãªãä¸å¯©ãªé»è©±ãã¡ã¼ã«ã«ã¯å¿ããªãããæ³¨æãå¼ã³æãã¦ããã å館ã¯11æ5æ¥ã«ä¸æ£ã¢ã¯ã»ã¹ã確èªãå§è¨å ã®ã¤ã³ã¿ã¼ãããã¤ãã·ã¢ãã£ãï¼IIJï¼ãæ¥
This is open-source software written by hobbyists, maintained by a single volunteer, badly tested, written in a memory-unsafe language and full of security bugs. It is foolish to use this software to process untrusted data. As such, we treat security issues like any other bug. Each security report we receive will be made public immediately and won't be prioritized. ããã¯è¶£å³äººãã¡ã«ãã£ã¦éçºããããã£ãä¸äººã®ãã©ã³ãã£ã¢ã«ãã£
ãå¢ç°ããï¼å æ°ããªãããã§ããã大ä¸å¤«ã§ããï¼ãã¨ãè¨ããããï¼ ãªãã§ãã£ã¡ãã話ããããªãã¨å§ã¾ããªããã ãï¼ï¼ ãã£ã¡ã®æ§åããã£ã¡ãã伺ã£ã¦ãï¼ï¼ ãã£ã¨å´ãã£ã¦ãï¼ ãããã¼ã¼ãï¼ï¼
2è¦ç´ èªè¨¼ãªã©ã§ããã¿ã6æ¡ã®ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ãã§ãããå人çã«ä½ã¨ãªãæ°ã«ãªã£ã¦ãããã¨ãããã¾ããã ãã㯠åãæ°åã並ã¶ãã¨ãå¤ããª ã¨æããã¨ãããã¨ã§ãã ãã®è¨äºã§ã¯ ãåãæ°åã並ã¶ãã¨ããç´æãæ£ããã®ãï¼ ä½ãã®ç®ç (ä¾: å ¥åãæ¥½ã«ãã) ããã£ã¦ãããªã£ã¦ããã®ãï¼ ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ãã®çæã¢ã«ã´ãªãºã çã«ããããåããçã¾ãããããªãã®ãï¼ ã¨ããç´ æ´ãªçåã解決ãã¹ã調æ»ã»æ¤è¨¼ãã¦ã¿ã¾ããã ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ãã®ä»æ§ 6æ¡ã®ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ãï¼ä»¥ä¸ãOTPï¼ã¯ãå®ã¯å½éçã«æ¨æºåããã仿§ã«åºã¥ãã¦çæããã¦ãã¾ãã RFC 4226 - HOTP: An HMAC-Based One-Time Password Algorithm RFC 6238 - TOTP: Time-Based One-Time Password Algorithm HOTP
ã¢ãã¤ã«ãªã¼ãã¼ã§ååè©åã彿 å ±éä¿¡ã䏿£çºæ³¨â容çã§ç¡è·ç·å鮿ã»è¦è¦åº æäºéä¿¡ 社ä¼é¨2025å¹´11æ14æ¥05æ08åé ä¿¡ è¦è¦åºæ¬é¨ ãã½ã³ã³ãã¹ãã¼ããã©ã³ã§ååãäºåã«æ³¨æã決æ¸ãããã¢ãã¤ã«ãªã¼ãã¼ããæªç¨ããå¼å½ãã ã¾ãåã£ããªã©ã¨ãã¦ãè¦è¦åºãç§é»ç£çè¨é²ä¸æ£ä½åºã»åä¾ç¨ã¨è©æ¬ºå®¹çãªã©ã§ãç¡è·å è¤åµ©å¤§å®¹çè ï¼ï¼ï¼ï¼ï¼æ±äº¬é½å½åå¯ºå¸æ³çºï¼ãå鮿ãããã¨ãï¼ï¼æ¥ãææ»é¢ä¿è ã¸ã®åæã§åãã£ãã容çãèªãããå¤é£ãããã¨æã£ãããéããªãã£ããã¨è©±ãã¦ããã¨ããã åºå館ã«ï¼ï¼ï¼ï¼å䏿£æ³¨æããè©æ¬ºå®¹çã§ç¡è·ç·é®æâæç¥çè¦ ææ»é¢ä¿è ã«ããã¨ãå容çè ã¯æ±ºæ¸ãæ£å¸¸ã«è¡ãããã¨ããè彿 å ±ããµã¼ãã¼ã«éä¿¡ããæå£ã§ä¸æ£çºæ³¨ãç¹°ãè¿ãã¦ããã¨ã¿ãããååºãµã¤ãã¼ç¯ç½ªå¯¾ç課ã詳ãã調ã¹ã¦ããã å鮿容çã¯ï¼æï¼ï¼ï½ï¼ï¼æ¥ãã¢ãã¤ã«ãªã¼ãã¼ã®ãµã¼ãã¼ã«èå½ã®æ±ºæ¸å®äºæ å ±ãéä¿¡
1 ãã·ã¢ã¯ä¸é¨å°åã§ã¹ãã¼ããã©ã³ãªã©ããã¤ã³ã¿ã¼ãããã¸ã¢ã¯ã»ã¹ããã¢ãã¤ã«éä¿¡ãæä¹ çã«å¶éãå§ãã¾ããã ãã·ã¢ä¸é¨ã®ã¦ãªã¤ããã¹ã¯å¸ã®ä¸é¨å°åã§ã¯ç´2é±éãã¢ãã¤ã«éä¿¡ãã§ããªãç¶æ³ãç¶ãã¦ãã¾ãã å°å å½å±ã¯7æ¥ãã¢ãã¤ã«éä¿¡ãå¶éãã¦ãããã¨ãèªããã¦ã¯ã©ã¤ãä¾µæ»ãçµçµããã¾ã§ç¶ãå¯è½æ§ãããã¨çºè¡¨ãã¾ããã ã¦ãªã¤ããã¹ã¯å¸ã«ã¯ããã¼ã³ã®å·¥å ´ãã¨ãã«ã®ã¼æ½è¨ããããã¦ã¯ã©ã¤ãããã®ããã¼ã³æ»æã度ã ãåãã¦ãã¾ãã ãã®éä¿¡å¶éæªç½®ã¯ãã·ã¢æ¿åºã®æ±ºå®ã«ãããã®ã§ãä»å¾ã¯ãã·ã¢å ¨åã®ãéè¦æ½è¨ãã®å¨è¾ºã§å®æ½ãããå¯è½æ§ãããã¨ãã¦ãã¾ãã ããã¾ã§ã¯ããã¼ã³ãªã©ã«ããæ»æãåãã¦ããéã«å¨è¾ºã§ä¸æçã«ã¢ãã¤ã«éä¿¡ã鮿ããã¦ãã¾ããããä»å¾ã¯æä¹ çã«å¶éãããã¨ã¿ããã¾ãã å¶éã®å¯¾è±¡ã¨ãªãå°åã¯ãå½å®¶æ©å¯ãã ã¨ãã¦æããã«ããã¦ãã¾ããã
ä»äººã®ã¢ã«ã¦ã³ãã«ä¸æ£ã¢ã¯ã»ã¹ããæ¥½å¤©ã¢ãã¤ã«ã®éä¿¡ãµã¼ãã¹å¥ç´ãçµãã ã¨ãã¦ãå µåº«çè¦ã¯11æ¥ãå¼ççå é å¸ã®å»ºè¨ä½æ¥å¡ã®å°å¹´ï¼16ï¼ã¨ãåèå¸è¥èåºã®ç¡è·ãé·ç°ç幸容çè ï¼21ï¼ã䏿£ã¢ã¯ã»ã¹ç¦â¦
ãã¤ã¿ã¼éä¿¡ã¯6æ¥ãç±³ã¡ã¿ï¼æ§ãã§ã¤ã¹ããã¯ï¼ããèªç¤¾SNSä¸ã®è©æ¬ºãè²©å£²ç¦æ¢åãªã©ã®ä¸æ£åºåã«ããåå ¥ã2024å¹´ã®å£²ä¸é«ã®ç´1å²ã«ãããç´160åãã«ï¼ç´2å 4500ååï¼ã«ä¸ãã¨è¦ç©ãã£ã¦ããã¨å ±ããã24å¹´12æã®å 鍿æ¸ã«åºã¥ããå ±éã1æ¥ã«150åä»¶ã®è©æ¬ºåºåã表示ãã¦ãããªã©ã¨æ¨å®ãã䏿£åºåãåé¤ããã°äºæ¥ã«å½±é¿ãåºãæ¸å¿µã示ããã¦ããã¨ããã å ±éã«ããã¨ãã¡ã¿ã¯ãã§ã¤ã¹ããã¯ãã¤ã³ã¹ã¿ã°ã©ã ãã¯ããã¢ãããªã©ã®èªç¤¾SNSä¸ã§ãè©æ¬ºåºåã®éãæ¸¬å®ããè©æ¬ºçãªé»åååå¼ï¼ECï¼ãæè³ã¹ãã¼ã ãéæ³ãªãªã³ã©ã¤ã³ã«ã¸ããç¦æ¢ããã¦ããå»è¬åã®è²©å£²ããªã©ã®åºåããã£ãã¨ãã¦ããã
ãã©ã³ã¹ã»ããªã®ã«ã¼ãã«ç¾è¡é¤¨ã§10æ19æ¥ï¼ç¾å°æéï¼ãç·é¡8800ä¸ã¦ã¼ãï¼ç´156ååï¼ç¸å½ã®å®é£¾åãããã8åè¶³ããã§çã¾ããäºä»¶ã§ã館å ã«è¨ç½®ãããç£è¦ã«ã¡ã©ã«ã¢ã¯ã»ã¹ããããã®ãã¹ã¯ã¼ãããLOUVREãï¼ã«ã¼ãã«ï¼ã§ãã£ããã¨ã徿¥ã®ç£æ»ã§æããã«ãªã£ãã¨ããã ãªãã©ã·ãªã³ãã¢ã³ãã¬ãã¥ã¼ãªã©ãè¤æ°ã®ä»ã¡ãã£ã¢ãå ±ãããä»ã«ã大æã»ãã¥ãªãã£ä¼ç¤¾ã®ç¤¾åã§ãããTHALESãã¨ããåç´ãªãã¹ã¯ã¼ãã使ããã¦ããä»ã館å ã®ã·ã¹ãã ã§ã¯ãæ¢ã«ãµãã¼ããçµäºãã¦ãããWindows 2000ï¼XPï¼Server 2003ãã稼åãã¦ããã¨ããã ãªãã©ã·ãªã³ã«ããã°ãããããã»ãã¥ãªãã£ã·ã¹ãã ã«é¢ããèå¼±ï¼ãããããï¼æ§ã®ææã¯10å¹´åã«è¡ããã¦ããããæ¾ç½®ããã¦ãããæ¿åºããã®æåãæ¯æ´ãå ¥ã£ã¦ããå ¬çæ½è¨ã«ããã¦ããã»ãã¥ãªãã£å¯¾çã«å¯¾ããé¢å¿ã®ä½ããæµ®ã彫ãã¨ãªã£ãã é¢é£
éå»ã«ããããé害çã®äºæ ãçµé¨ãã¦ãã AWS ã®ã·ãã¢ã¨ã³ã¸ãã¢ãã¡ã¯ãã©ãã¸è¡ã£ã¦ãã¾ã£ãã®ã ããï¼ ãã®çã¯ãå½¼ããä¼ç¤¾ãå»ã£ã¦ãã¾ã£ãã¨ãããã¨ã ââ ããã AWS ã®ã·ã¹ãã ãå¤§è¦æ¨¡ã«åä½ããä»çµã¿ã«ã¤ãã¦ä½åå¹´ãããã¦è¦å´ãã¦ç²å¾ããçµç¹çç¥èã丸ãã¨æã£ã¦ã
ãã¸ã¿ã«æä»£ã«ããã¦ããã¹ã¯ã¼ãã¯ä¾ç¶ã¨ãã¦æãåºã使ç¨ãããèªè¨¼ææ®µã®ä¸ã¤ã§ãããããã徿¥ã®ãã¹ã¯ã¼ãããªã·ã¼ã®å¤ãããå®ã¯é广ã ã£ããã¨ããåç¥ã§ããããï¼ NISTï¼ç±³å½å½ç«æ¨æºæè¡ç ç©¶æï¼ãçºè¡ããSP 800-63B-4ã¯ããã¹ã¯ã¼ãã»ãã¥ãªãã£ã«é¢ããææ°ã®æéãæä¾ãã¦ãããããã¾ã§ã®ã常èããè¦ãå 容ãå«ã¾ãã¦ãã¾ããï¼å°éå®¶ã®éã§ã¯é·ãã常èã ã£ããã®ãªãã§ããâ¦ãï¼æ¬è¨äºã§ã¯ã伿¥å ã§ãã¹ã¯ã¼ãã使ã£ãã¦ã¼ã¶ã¼èªè¨¼ã·ã¹ãã ãæ å½ãããæ¹ãããã³ããããããªã·ã¼ã決ããæ å½è ãçµå¶è ã«åãã¦ããã®éè¦ãªææ¸ã®æ ¸å¿ããããããã解説ãã¾ãã ãã¹ã¯ã¼ãã®2ã¤ã®åé¡ NIST SP 800-63B-4ã§ã¯ããã¹ã¯ã¼ãã以ä¸ã®2種é¡ã«åé¡ãã¦ãã¾ãã 1. ãã¹ã¯ã¼ãï¼Passwordsï¼ ãµã¼ãã¼å´ã§æ¤è¨¼ãããç§å¯æ å ±ããã°ã¤ã³æã«ãµã¼ãã¼ã«éä¿¡ãããéä¸çã«æ¤è¨¼ããã¾ã
éè·ã叿ãã人ã«ä»£ãã£ã¦ä¼ç¤¾ã«ææãä¼ããéè·ä»£è¡ãµã¼ãã¹ãã¢ã¼ã ãªãã®éå¶ä¼ç¤¾ãã代è¡ã®ä»äºãéæ³ã«å¼è·å£«ã«ãã£ããããç´¹ä»æãåãåã£ãçããå¼·ã¾ã£ãã¨ãã¦ãè¦è¦åºã¯é¢ä¿å ã®ä¸ææç´¢ãè¡ã£ã¦ãâ¦
楽天ã¯20æ¥ãèªç¤¾ãµã¼ãã¹ã§ã·ã¹ãã é害ãçºçããã¨æããã«ãããæ£åããã®æç¹ã§ãã¤ã³ã¿ã¼ãããé販ãµã¤ããæ¥½å¤©å¸å ´ãããQRã³ã¼ã決æ¸ã楽天ãã¤ããªã©ãè¤æ°ãµã¼ãã¹ã§ãã°ã¤ã³ãå©ç¨ããã«ããç¶æ ã«ãªã£ã¦ããã å社ã«ããã¨ãé害ã¯åå11æããã«çºçããããèªç¤¾ã®ãã¼ã¿ã»ã³ã¿ã¼å ã®ä¸é¨ã·ã¹ãã ã®é害ã§ãå¤é¨ããã®ãµã¤ãã¼æ»æã«ãããã®ã§ã¯ãªããã¨ãã¦ããã 復æ§ä½æ¥ã宿½ããç¾å¨ãåãµã¼ãã¹ã§ä¸å ·åã¯è§£æ¶ã«åãã£ã¦ããã¨ãããåç¤¾ã®æ å½è ã¯ããè¿·æãããããã¦æ·±ãããã³ç³ãä¸ãã¾ããã¨è©±ããããçºé幸ã
æäººã®ä¿µä¸æºæ°ã¯20æ¥ãXãï¼æ§ãã¤ãã¿ã¼ï¼ãæ´æ°ããã¸ã£ã¼ã¹ã®å¤§è°·ç¿å¹³ææã®æ´»èºã§ãã¼ã ã¡ã¤ããâé ãæ±ããâã¨ãã表ç¾ã«éåæãæãã¤ã¤ãç´å¾ãããã¨ãæãããã ãåç»ãå¤§è°·ã®æ¬å¡æã«é ãæ±ãããã¸ã£ã¼ã¹ãã¤ã³ 大谷ã¯17æ¥ï¼æ¥æ¬æé18æ¥ï¼ã®ãã·ã§ãã«ãªã¼ã°åªå決å®ã·ãªã¼ãºã®ãã«ã¯ã¼ãºã¨ã®ç¬¬4æ¦ã§ãææã¨ãã¦å çºãã6åç¡å¤±ç¹ãæè ã¨ãã¦ã¯3æ¬å¡æãæ¾ã¡ããã¼ã ããªã¼ã°åªåã«å°ããã ã¡ã¸ã£ã¼ãªã¼ã°ã®æ´å²ã«æ®ãæ´»èºã ã£ãããç¹ã«4åã«æ¾ã£ã2æ¬ç®ã®ãé£è·é¢143ã¡ã¼ãã«ã®ç¹å¤§æ¬å¡æãæã£ãç´å¾ããã¸ã£ã¼ã¹ã®ãã³ãã®é¸æã驿ãã表æ ã話é¡ã¨ãªã£ãã ãã®éã宿³ã®ã¢ãã¦ã³ãµã¼ãããã¼ã ã¡ã¤ããé ãæ±ãã¦ãã¾ãï¼ããéããå£ããµããããªãã¨ãã£ã表æ ãã¨çµ¶å«ããããããã®è¡¨ç¾ã«ä¿µæ°ã¯éåæãè¦ããããã§ã18æ¥ã大谷ã¯ç´ æ´ããããã ãã©ãã¿ããªã®é©ããæåããã¢ãã¦ã³ãµã¼ããé ãæ±ã
å¹³ç´ ããã¢ã¹ã¯ã«ããå©ç¨ããã ãèª ã«ãããã¨ããããã¾ãã ç¾å¨ãã¢ã¹ã¯ã«Webãµã¤ãã«ã¦ã©ã³ãµã ã¦ã§ã¢ææã«ããã·ã¹ãã é害ãçºçãã¦ãããåæ³¨ãåºè·æ¥åã忢ãã¦ããã¾ãã å人æ å ±ã顧客ãã¼ã¿ãªã©ã®å¤é¨ã¸ã®æµåºãå«ããå½±é¿ç¯å²ã«ã¤ãã¦ã¯ç¾å¨èª¿æ»ãé²ãã¦ããããããæ¬¡ç¬¬ãç¥ãããããã¾ãã ã客æ§ã«ã¯å¤å¤§ãªããè¿·æããå¿é ããããããèª ã«ç³ã訳ãããã¾ããã ã³ã¼ãã¬ã¼ããµã¤ãã®ãç¥ããã¯ãã¡ã ãå½±é¿å 容ã â ãæ³¨æåä»ã®åæ¢ Webãµã¤ãã§ã¯ããè²·ãç©ã«ã´ç»é¢çã«é·ç§»ãããã¨ããå ´åã«ã¨ã©ã¼ç»é¢ã«é·ç§»ãããã¾ãã ï¼ã¨ã©ã¼ã«ãªãç»é¢ï¼ ã»ãè²·ãç©ã«ã´ ã»ã¬ã¸ ã»ã注æå 容å°å· ã¾ããFAXã§ã®ã注æã«ã¤ãã¦ãéä¿¡ã¨ã©ã¼ã¨ãªããåä»ãããã¨ãã§ãã¾ããã â åºè·ã®åæ¢ 2025å¹´10æ21æ¥æç¹ã§ãå±ãã§ãã¦ããªããæ³¨æã¯ãé æ¬¡ãã£ã³ã»ã«ããã¦ããã ãã¾ãã 詳細ã¯ãã¡ããã確èªãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}