Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
OSS で知ってほしい セキュリティのこと
Search
yu fujioka
July 28, 2024
0
100
OSS で知ってほしい セキュリティのこと
#techramen24conf で発表しなかった登壇資料です。
yu fujioka
July 28, 2024
Tweet
Share
More Decks by yu fujioka
See All by yu fujioka
about AWS Startup Security Baseline (AWS SSB)
fujiokayu
0
100
はじめよう DevSecOps
fujiokayu
1
230
golt.pdf
fujiokayu
1
250
Featured
See All Featured
Odyssey Design
rkendrick25
PRO
0
460
Agile that works and the tools we love
rasmusluckow
331
21k
Why Our Code Smells
bkeepers
PRO
340
58k
Have SEOs Ruined the Internet? - User Awareness of SEO in 2025
akashhashmi
0
230
The State of eCommerce SEO: How to Win in Today's Products SERPs - #SEOweek
aleyda
2
9.3k
Building a A Zero-Code AI SEO Workflow
portentint
PRO
0
230
Deep Space Network (abreviated)
tonyrice
0
33
How to Get Subject Matter Experts Bought In and Actively Contributing to SEO & PR Initiatives.
livdayseo
0
45
The Illustrated Guide to Node.js - THAT Conference 2024
reverentgeek
0
220
SEOcharity - Dark patterns in SEO and UX: How to avoid them and build a more ethical web
sarafernandez
0
100
Speed Design
sergeychernyshev
33
1.5k
Ecommerce SEO: The Keys for Success Now & Beyond - #SERPConf2024
aleyda
1
1.8k
Transcript
044Ͱͬͯ΄͍͠ ηΩϡϦςΟͷ͜ͱ UFDISBNFODPOG
SIerɺSoftware Engineerɺ֤छ੬ऑੑஅαʔϏεͷ্ཱͪ͛ ͔Βͷ PSIRT ͳͲɺΒ͘ηΩϡϦςΟΤϯδχΞɻ அαʔϏεΛ্ཱͪ͛Δͱ͖ݽ܉ฃಆͰݽಠΛטΈకΊͯ ͍͕ͨ OSS ʹॿ͚ΒΕΔɻOWASP Lifetime
Membership. ࠷ۙʢ2024/7ʣΞϓϦέʔγϣϯΤϯδχΞʹճؼɻ ʑϚΠΫϩαʔϏεͱ৮Ε߹͍ͬͯ·͢ɻ ͖ͳ੬ऑੑ 4FSWFS4JEF3FRVFTU'PSHFSZ ϓϩϑΟʔϧը૾ͷ τϦϛϯάํ๏ yu fujioka
044ͷηΩϡϦςΟͷ͓ 044ΛऔΓר͘ڴҖ ڴҖͷରࡦ 044ͷา͖ํ
1PMZ fi MMJPͷ͓ ݄ɺ1PMZ fi MMJPͷυϝΠϯͱ(JU)VCΞΧϯτ͕தࠃͷاۀ 'VOOVMMʹΑͬͯങऩ ಛఆ݅ԼͰѱҙͷ͋Δ8FCαΠτʹϦμΠϨΫτ͢ΔΑ͏ίʔυ͕ ೖ͞Εͨ యܕతͳαϓϥΠνΣʔϯ߈ܸ
9;ͷόοΫυΞͷ͓ +JB5BOͱ͍͏։ൃऀʹΑΔʹٴͿʮݙతͳʯ$POUSJCVUJPO Ξοϓσʔτ͕͍ͱ͍͏ۤʹΑΔίΞϝϯςφͷർฐ ͜͏ͨ͠Ϣʔβʔ͔ΒͷۤɺͦͷλΠϛϯά͔Β߈ܸͷҰͩͬͨՄೳੑ͕͋Δ ίΞϝϯςφͷࣗવͳަ͔ܶΒͷαϓϥΠνΣʔϯ߈ܸ +JB5BOࣗࠃՈతͳ߈ܸΞΫλʔʹΑͬͯ࡞ΒΕͨળྑͳ044ϝϯςφͱ͍͏ ϖϧιφʢͱݟΒΕ͍ͯΔʣͰ͋ΓɺதࠃͷΞΫλʔΛͬͨଞࠃʹΑΔ߈ܸͱௐ ͕ࠪग़͍ͯΔʢ͠ɺதࠃΛͬͨଞࠃΛͬͨୈࡾࠃͱ͔શવ͋Δʣ ͜͏ͨͬ͠औΓΛ044։ൃऀ͕ࣗӴ͢Δͷ͍͠͠ɺ ɹͦ͏ͨ͠ΛϝϯςφͨͪʹෛΘͤΔ͖Ͱͳ͍
ɹͳΜ͔44)ଓඵ͘Β͍͍ͳʙɺͬͯؾ͍ͮͨ"OESFT'SFVOE͕Ғେ͗͢Δ
'BLF74$PEF&YUFOTJPOͷ͓ 4FDVSJUZ3FTFBSDIFSِ͕ͷWTDPEFFYUFOTJPOΛެ։͠ɺِͷϨϏϡʔΛੜ ͠ɺ৭Μͳ։ൃऀʹΠϯετʔϧ͞Εɺ74$PEF.BSLFUQMBDFʢ݄ؒສ ϏϡʔΛ֫ಘ͢ΔϖʔδʣͰτϨϯυೖΓ͠ɺෳͷ࣌Ձ૯ֹेԯυϧنͷ #JH5FDIୡʹΠϯετʔϧ͞Εͨ 3FTFBSDIFSِͷ1SFUUJFS$PEFGPSNBUUFSͱ͍͏ѱҙͷ͋Δ&YUFOTJPOʹΠϯεύΠΞ͞ Εͨͱͷ͜ͱ %SBDVMB0 ffi DJBMͱ͍͏ਓؾͷςʔϚΛ฿ͨ͠%BSDVMB0
ff i DJBMΛ࡞ɺݩͷ ίʔυΛվม͠ιʔείʔυΛ౪͢ΔίʔυΛՃ ߈ܸͷ४උʹ͔͔ͬͨ࣌ؒͱͷ͜ͱ IUUQTNFEJVNDPN!BNJUBTTBSBGUIFTUPSZPGFYUFOTJPOUPUBMIPXXFIBDLFEUIFWTDPEFNBSLFUQMBDFDFBFE
αϓϥΠνΣʔϯ߈ܸ͕લఏͷ࣌Λ ੜ͖Δ͔͠ͳͦ͞͏ %PDLFS)VCʹެ։͞Ε͍ͯΔສҎ্ͷϦϙδτϦͷ͏ͪɺˋۙ͘ ʢສʣ͕ѱҙͷ͋ΔίϯςϯπΛϗετ͍ͯͨ͠ͱ͍͏ௐࠪใࠂ IUUQTKGSPHDPNCMPHBUUBDLTPOEPDLFSXJUINJMMJPOTPGNBMJDJPVTSFQPTJUPSJFTTQSFBE NBMXBSFBOEQIJTIJOHTDBNT τϩΠͷഅԽͨ͠K2VFSZ͕(JU)VC$%/ܦ༝Ͱ֦ࢄɹถηΩϡϦςΟاۀ ͕ܯࠂ IUUQTXXXJUNFEJBDPKQOFXTBSUJDMFTOFXTIUNM OQNQJQʹຮԆΔ5ZQP4RVBUUJOH
ͦͷଞΖΖ
IUUQTXXXHIJCMJKQXPSLTLJNJUBDIJ
ૣظݕ͢ΔΈ (JU)VCͷ%FQFOEBCPU"MFSUTͱԿ͔ʢաڈهࣄʣ %FQFOEFODZ(SBQI͔ΒϦϙδτϦʹؚ·ΕΔ044ͷ੬ऑੑΛݕग़ ݱʹ͓͍ͯඞਢͷػೳͱݴ͑Δ
4"45੩తղੳͷΈ (JU)VC%PDTίʔυεΩϟϯʹ͍ͭͯ ͕ࣗॻ͍ͨ044ͷղੳɺར༻͍ͨ͠044ͷ੬ऑੑݕग़ʹศར 4ZODͱ5BJOU5SBDLJOHͱ͍͏֓೦Ͱߴਫ਼ͳղੳΛߦ͏ʢͪΖΜِཅੑ͋Δʣ 4FDSFU4DBOOJOHྑ͍ͧ
ͦͷଞΖΖ ʮؾΛ͚ͭΔʯʢࠜੑʣ೦ͳ͕Β·ͩඞཁ खଧͪJOTUBMMؾΛ͚ͭΔɺग़ࣗͷո͍͠ͷΘͳ͍ͱ͔جຊಈ࡞ʹ 4#0.ʹظɻ͚Ͳ·ͩਓྨʹૣͦ͏ /FUXPSL'JSFXBMMػඍใͷΞʔΩςΫνϟɺ$41ͳͲͷ 4FDVSFIFBEFSɺࢹɺใऩूͳͲͷऔΓΈґવॏཁ ߈ܸ͞Εͯؾ͚ͮΔɺରॲͰ͖ΔΈͮ͘Γ 5SJWZͱ͍ͬͨ044ʹΑΔ੬ऑੑใͷૣظݕग़༗ޮ ʰφχϫۚ༥ʱ ੨༤ೋ
೦ͳ͕ΒɺݱͷιϑτΣΞ։ൃ·ͩ৻ॏʹา͔ͳ͍ͱ͍͚ͳ͍ ͚Ͳ৺ڧ͍ثͨ͘͞Μ͋ΔɻͦΕΒ044ʹࢁ͋Δɻ׆༻͠Α͏ 044ʹ͓ۚ͏ͷେࣄͩ͠ɺͦΕʹ߅͕͋Ε$POUSJCVUF͍ͯ͜͠ (JU)VC"EWBODFE4FDVSJUZ͍͍ͧ ৻ॏʹา͘ೣ
3FGFSFODF )PX8F)BDLFE.VMUJ#JMMJPO%PMMBS$PNQBOJFTJO.JOVUFT6TJOHB'BLF74$PEF&YUFOTJPO IUUQTNFEJVNDPN!BNJUBTTBSBGUIFTUPSZPGFYUFOTJPOUPUBMIPXXFIBDLFEUIFWTDPEFNBSLFUQMBDFDFBFE +'SPH4FDVSJUZSFTFBSDIEJTDPWFSTDPPSEJOBUFEBUUBDLTPO%PDLFS)VCUIBUQMBOUFENJMMJPOTPG NBMJDJPVTSFQPTJUPSJFT IUUQTKGSPHDPNCMPHBUUBDLTPOEPDLFSXJUINJMMJPOTPGNBMJDJPVTSFQPTJUPSJFTTQSFBENBMXBSFBOEQIJTIJOHTDBNT τϩΠͷഅԽͨ͠K2VFSZ͕(JU)VC$%/ܦ༝Ͱ֦ࢄɹถηΩϡϦςΟاۀ͕ܯࠂ IUUQTXXXJUNFEJBDPKQOFXTBSUJDMFTOFXTIUNM ܅ͨͪͲ͏ੜ͖Δ͔ʢʣ IUUQTXXXHIJCMJKQXPSLTLJNJUBDIJ
(JU)VCͷ%FQFOEBCPU"MFSUTͱԿ͔ IUUQT[FOOEFWZVVIVBSUJDMFTBCPVUHJUIVCBMFSU (JU)VC%PDTίʔυεΩϟϯʹ͍ͭͯ IUUQTEPDTHJUIVCDPNKBDPEFTFDVSJUZDPEFTDBOOJOHJOUSPEVDUJPOUPDPEFTDBOOJOHBCPVUDPEFTDBOOJOH