{"id":14514,"date":"2017-11-06T07:00:32","date_gmt":"2017-11-05T22:00:32","guid":{"rendered":"http:\/\/www.techscore.com\/blog\/?p=14514"},"modified":"2018-11-14T16:33:43","modified_gmt":"2018-11-14T07:33:43","slug":"super-cookie","status":"publish","type":"post","link":"https:\/\/www.techscore.com\/blog\/2017\/11\/06\/super-cookie\/","title":{"rendered":"\u53cd\u5247\u30b9\u30ec\u30b9\u30ec !? Super Cookie \u3068\u306f"},"content":{"rendered":"

\"\"
\n\uff08Eugene Onischenko \/ Shutterstock.com\uff09<\/span><\/p>\n

\u3053\u3093\u306b\u3061\u306f\u3001\u4e2d\u5c71\u3067\u3059\uff08\u5199\u771f\u306f\u79c1\u3067\u306f\u3042\u308a\u307e\u305b\u3093\uff09\u3002
\n\u4ee5\u524d\u306e 3rd party Cookie \u3044\u305f\u3060\u304d\u307e\u3059<\/a> \u306b\u3066<\/p>\n

\nParasite Cookie \u306e\u5834\u5408\u3001\u30af\u30ed\u30b9\u30c9\u30e1\u30a4\u30f3\u3067\u30c8\u30e9\u30c3\u30ad\u30f3\u30b0\u3067\u304d\u306a\u3044\u3053\u3068\u304c\uff08\u696d\u8005\u5074\u306e\uff09\u8ab2\u984c\u3067\u3059\u3002
\n\u3057\u304b\u3057 Super Cookie \u3068\u547c\u3070\u308c\u308b\u65b9\u6cd5\u306a\u3089\u3070\u30af\u30ed\u30b9\u30c9\u30e1\u30a4\u30f3\u3067\u306e\u30c8\u30e9\u30c3\u30ad\u30f3\u30b0\u3082\u53ef\u80fd\u3067\u3059\u3002
\n\u3053\u3061\u3089\u306b\u3064\u3044\u3066\u306f\u5225\u9014\u3054\u7d39\u4ecb\u3057\u307e\u3059\u3002\n<\/p><\/blockquote>\n

\u3068\u7d50\u3073\u307e\u3057\u305f\u3002
\n\u305d\u3053\u3067\u3001\u4eca\u56de\u306f Super Cookie \u3068\u547c\u3070\u308c\u308b\u6280\u8853\u306b\u3064\u3044\u3066\u3054\u7d39\u4ecb\u3057\u305f\u3044\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n

\u4f8b\u3048\u3070\u3053\u3093\u306a Super Cookie<\/h2>\n

Super Cookie \u3068\u306f\u3001\u5404\u7a2e\u64ec\u4f3c Cookie \u6280\u8853\u306e\u7dcf\u79f0\u3067\u3001Flash \u306e LSO<\/a> \u3092\u5229\u7528\u3057\u305f\u30b7\u30f3\u30d7\u30eb\u306a\u5b9f\u88c5\u304b\u3089\u3001\u30d6\u30e9\u30a6\u30b6\u306e\u95b2\u89a7\u5c65\u6b74\uff08\u53c2\u8003 : css history knocker<\/a>\uff09\u3084 Criteo \u306e ITP \u5bfe\u7b56\u3068\u3057\u3066\u8a71\u984c\u306b\u306a\u3063\u305f HSTS \u6a5f\u80fd\u3092\u5229\u7528\u3057\u305f\u30c8\u30ea\u30c3\u30ad\u30fc\u306a\u5b9f\u88c5\u306a\u3069\u304c\u5b58\u5728\u3057\u307e\u3059\u3002<\/p>\n

\"\"<\/p>\n

\u4f8b\u3048\u3070 HSTS \u6a5f\u80fd\u3067\u306f\u30c9\u30e1\u30a4\u30f3\u6bce\u306b\u30d7\u30ed\u30c8\u30b3\u30eb\uff08HTTPS \u3092\u5229\u7528\u3059\u308b\u304b\u5426\u304b\uff09\u3092\u4e0d\u63ee\u767a\u9818\u57df\u306b\u8a18\u9332\u3057\u307e\u3059\u304c\u3001\u305d\u308c\u3092\u5229\u7528\u3057\u305f Super Cookie \u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u52d5\u4f5c\u539f\u7406\u3068\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n

    \n
  1. \u30d6\u30e9\u30a6\u30b6\u306b\u4ed8\u4e0e\u3059\u308b\u8b58\u5225\u5b50\uff08\u3053\u3053\u3067\u306f 256 \u30d3\u30c3\u30c8\u4e71\u6570\uff09\u3092\u751f\u6210\u3059\u308b = NN<\/li>\n
  2. \u4ee5\u4e0b\u306e\u3088\u3046\u306a 256 \u500b\u306e\u30c9\u30e1\u30a4\u30f3\u306b https: \u3067\u30a2\u30af\u30bb\u30b9\u3059\u308b\n
    \n https:\/\/00.tracking.com\/NN
    \n https:\/\/01.tracking.com\/NN
    \n ...
    \n https:\/\/FE.tracking.com\/NN
    \n https:\/\/FF.tracking.com\/NN\n <\/div>\n<\/li>\n
  3. \u5404 XX.tracking.com \u306e\u51e6\u7406\u6642 NN \u306e XX \u30d3\u30c3\u30c8\u76ee\u3092\u30c1\u30a7\u30c3\u30af\u3057\u3066\n
    \n 0 \u306e\u5834\u5408\u306f \"Strict-Transport-Security: max-age=expireTime\" \u3092\u5fdc\u7b54
    \n 1 \u306e\u5834\u5408\u306f \"Strict-Transport-Security: max-age=0\" \u3092\u5fdc\u7b54\n <\/div>\n<\/li>\n
  4. \u7d50\u679c\u3068\u3057\u3066\u8b58\u5225\u5b50 NN \u304c\u5229\u7528\u30d7\u30ed\u30c8\u30b3\u30eb\u60c5\u5831\u3068\u3057\u3066\u30d6\u30e9\u30a6\u30b6\u306b\u8a18\u9332\u3055\u308c\u308b<\/li>\n
  5. \u8b58\u5225\u5b50\u306e\u5fa9\u5143\u6642\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306a 256 \u500b\u306e\u30c9\u30e1\u30a4\u30f3\u306b http: \u3067\u30a2\u30af\u30bb\u30b9\u3059\u308b\n
    \n http:\/\/00.tracking.com\/
    \n http:\/\/01.tracking.com\/
    \n ...
    \n http:\/\/FE.tracking.com\/
    \n http:\/\/FF.tracking.com\/\n <\/div>\n<\/li>\n
  6. HTTPS \u3078\u306e\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u306e\u6709\u7121\u304b\u3089\u5404\u30d3\u30c3\u30c8\u3092\u5fa9\u5143\u3057\u3001\u6700\u7d42\u7684\u306b 256 \u30d3\u30c3\u30c8\u306e\u5024 NN \u3092\u5fa9\u5143<\/li>\n<\/ol>\n

    \u306a\u3093\u3068\u3044\u3046\u5275\u610f\u5de5\u592b !!
    \n\uff08\u3053\u306e\u5275\u610f\u5de5\u592b\u3092\u5efa\u8a2d\u7684\u306a\u7528\u9014\u306b\u5411\u3051\u3066\u307b\u3057\u3044 \u2026\u2026\uff09
    \n\u3055\u3089\u306b\u3053\u3093\u306a\u8a71\u984c\u3082\u3042\u308a\u307e\u3057\u305f\u3002<\/p>\n