<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="https://codedchords.dev/feed_style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <tabi:metadata xmlns:tabi="https://github.com/welpo/tabi">
        <tabi:base_url>https:&#x2F;&#x2F;codedchords.dev</tabi:base_url>
        <tabi:separator>
            •
        </tabi:separator>
        <tabi:about_feeds>This is a web feed, also known as an Atom feed. Subscribe by copying the URL from the address bar into your newsreader. Visit About Feeds to learn more and get started. It&#x27;s free.</tabi:about_feeds>
        <tabi:visit_the_site>Visit website</tabi:visit_the_site>
        <tabi:recent_posts>Recent posts</tabi:recent_posts>
        <tabi:last_updated_on>Updated on $DATE</tabi:last_updated_on>
        <tabi:default_theme></tabi:default_theme>
        <tabi:post_listing_date>date</tabi:post_listing_date>
        <tabi:current_section>Security</tabi:current_section>
    </tabi:metadata><title>Coded Chords - Security</title>
        <subtitle>A personal blog</subtitle>
    <link href="https://codedchords.dev/tags/security/atom.xml" rel="self" type="application/atom+xml"/>
    <link href="https://codedchords.dev/tags/security/" rel="alternate" type="text/html"/>
    <generator uri="https://www.getzola.org/">Zola</generator><updated>2026-07-08T00:00:00+00:00</updated><id>https://codedchords.dev/tags/security/atom.xml</id><entry xml:lang="en">
        <title>CloudflareのAI対策見直しとAIエージェント対応度診断</title>
        <published>2026-07-08T00:00:00+00:00</published>
        <updated>2026-07-08T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2026/07/cloudflare-ai-access-review/" type="text/html"/>
        <id>https://codedchords.dev/blog/2026/07/cloudflare-ai-access-review/</id>
        
            <content type="html">&lt;!-- textlint-disable --&gt;
&lt;img
  src=&quot;https:&amp;#x2F;&amp;#x2F;codedchords.dev&amp;#x2F;blog&amp;#x2F;2026&amp;#x2F;07&amp;#x2F;cloudflare-ai-access-review&amp;#x2F;cover.webp?h=be4593eef9e356ff784e&quot;
  alt=&quot;Cover&quot; width=&quot;1536&quot; height=&quot;864&quot; loading=&quot;lazy&quot;
&#x2F;&gt;&lt;!-- textlint-enable --&gt;
&lt;details&gt;
&lt;summary&gt;Table of Contents&lt;&#x2F;summary&gt;
&lt;!-- toc --&gt;
&lt;&#x2F;details&gt;
&lt;p&gt;2026年2月、&lt;a href=&quot;https:&#x2F;&#x2F;codedchords.dev&#x2F;blog&#x2F;2026&#x2F;02&#x2F;cloudflare-benefits&#x2F;&quot;&gt;Cloudflareへ移転した際の記事&lt;&#x2F;a&gt;で、AI学習クローラー対策としてContent Signals Policy、Block AI bots、AI Labyrinthという3層構成を紹介しました。あれから4か月、AIによるアクセスの重要性はさらに増しています。改めてこのブログのCloudflare設定を見直すとともに、Cloudflareが新しく公開したAgent Readinessスキャナーで「AIエージェントへの対応度」を診断してみました。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Managed_robots.txtまわりを再確認する&quot;&gt;Managed robots.txtまわりを再確認する&lt;&#x2F;h2&gt;
&lt;p&gt;まず、AI Crawl Controlのダッシュボードを一通り確認しました。&lt;&#x2F;p&gt;
&lt;p&gt;Block AI training botsは「Block on all pages」のままで変更していません。このブログのコンテンツはCC BY-NC-ND 4.0(非営利・改変禁止)で公開しているので、商用LLMの学習データとして使われることは元々ライセンスの意図と衝突します。学習目的のクローラーは全ページで拒否するのが一貫した方針です。&lt;&#x2F;p&gt;
&lt;p&gt;Content Signalsでは、Managed robots.txtをオンにしています。&lt;&#x2F;p&gt;
&lt;p&gt;AI Crawl ControlのCrawlers一覧では、クローラーごとの許可&#x2F;ブロックを個別に確認しました。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;カテゴリ&lt;&#x2F;th&gt;&lt;th&gt;例&lt;&#x2F;th&gt;&lt;th&gt;設定&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;AI Crawler(学習用)&lt;&#x2F;td&gt;&lt;td&gt;GPTBot、ClaudeBot、Bytespider、Amazonbot、TikTok Spider、Meta-ExternalAgent&lt;&#x2F;td&gt;&lt;td&gt;Block&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;AI Search &#x2F; AI Assistant&lt;&#x2F;td&gt;&lt;td&gt;Applebot、PerplexityBot、ChatGPT-User&lt;&#x2F;td&gt;&lt;td&gt;Allow&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Search Engine Crawler&lt;&#x2F;td&gt;&lt;td&gt;Googlebot、BingBot&lt;&#x2F;td&gt;&lt;td&gt;Allow&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;Crawlers一覧の分類も、学習目的のクローラーを拒否するという方針のとおりでした。あわせてAI Labyrinth(クロールルールを無視するボットに偽コンテンツを読ませるハニーポット機能、Beta)も確認しましたが、2月から変わらずONのままでした。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;「混在クローラー」という新しい論点&quot;&gt;「混在クローラー」という新しい論点&lt;&#x2F;h2&gt;
&lt;p&gt;今回の見直しで、2月時点にはなかった変化に気づきました。レガシー機能「Block AI bots」の設定画面に、次のような予告が表示されていたのです。&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;On September 15, mixed-purpose crawlers that are used both for search indexing and for training AI will be included in blocking AI training.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;p&gt;ここで言う混在クローラーとは、前段のCrawlers一覧でSearch Engine CrawlerやAI Searchに分類し、学習とは無関係としてAllowにしていたGooglebot、Applebot、BingBotのことです。検索とAI学習を1回のクロールで同時に行うため両者を切り分けられず、学習ブロックを選んでいるサイトでは最も制限の強いルールを適用する、というのが実質的な立場だと考えられます。そのままでは検索エンジン経由の流入もAI検索・AIアシスタント経由の露出も失うため、「Mixed purpose crawlers will continue to be allowed」を選び、混在クローラーは引き続き許可する設定にしました。&lt;&#x2F;p&gt;
&lt;p&gt;レガシー機能は9月15日に廃止され、後継の「Configure AI bot policies」に一本化されます。こちらはボットを3種類に分類し、それぞれ個別にAllow&#x2F;Blockを選べる形になっていました。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;分類&lt;&#x2F;th&gt;&lt;th&gt;説明&lt;&#x2F;th&gt;&lt;th&gt;設定&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Search&lt;&#x2F;td&gt;&lt;td&gt;検索エンジンのインデックス用ボット&lt;&#x2F;td&gt;&lt;td&gt;Allow(Recommended)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Agent&lt;&#x2F;td&gt;&lt;td&gt;ユーザーの質問への回答生成のために参照するボット&lt;&#x2F;td&gt;&lt;td&gt;Allow(Recommended)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Training&lt;&#x2F;td&gt;&lt;td&gt;AI学習用にコンテンツをスクレイピングするボット&lt;&#x2F;td&gt;&lt;td&gt;Block(Recommended値はBlock on pages with ads)&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;Trainingだけ、広告のないこのブログの事情に合わせて推奨値の「Block on pages with ads」から「Block」に変更しました。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;AIエージェント対応度を診断してみた&quot;&gt;AIエージェント対応度を診断してみた&lt;&#x2F;h2&gt;
&lt;p&gt;Cloudflareは&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;isitagentready.com&#x2F;&quot;&gt;isitagentready.com&lt;&#x2F;a&gt;という無料の診断ツールを公開しています。&lt;&#x2F;p&gt;
&lt;p&gt;この診断ツールでは、サイトのAIエージェントへの対応度(Agent Readiness)を診断してくれます。&lt;&#x2F;p&gt;
&lt;p&gt;このブログのURLでスキャンしたところ、次のようなものでした。&lt;&#x2F;p&gt;
&lt;!-- textlint-disable --&gt;
&lt;figure&gt;&lt;img
  src=&quot;https:&amp;#x2F;&amp;#x2F;codedchords.dev&amp;#x2F;blog&amp;#x2F;2026&amp;#x2F;07&amp;#x2F;cloudflare-ai-access-review&amp;#x2F;agent-readiness.webp?h=634fa8b7fd82807af8a4&quot;
  alt=&quot;Agent Readiness&quot; width=&quot;1472&quot; height=&quot;1486&quot; loading=&quot;lazy&quot;
&#x2F;&gt;
&lt;figcaption&gt;当サイトのAgent Readiness&lt;&#x2F;figcaption&gt;
&lt;&#x2F;figure&gt;&lt;!-- textlint-enable --&gt;
&lt;h3 id=&quot;個人ブログサイトでは該当しない項目&quot;&gt;個人ブログサイトでは該当しない項目&lt;&#x2F;h3&gt;
&lt;p&gt;改善項目として、10個の指摘を受けました。
ただし、10個のうち6個はいずれも「稼働しているAPIやエージェントサービスがあること」を前提にした指摘でした。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;指摘&lt;&#x2F;th&gt;&lt;th&gt;規格&lt;&#x2F;th&gt;&lt;th&gt;該当しない理由&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;DNS for AI Discovery (DNS-AID)&lt;&#x2F;td&gt;&lt;td&gt;IETFドラフト、Linux Foundation 2026年発表&lt;&#x2F;td&gt;&lt;td&gt;他のAIエージェントから発見・接続されるエージェントサービス(チャットボット、MCPサーバー等)を運用していない&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;API Catalog&lt;&#x2F;td&gt;&lt;td&gt;RFC 9727&lt;&#x2F;td&gt;&lt;td&gt;カタログ化すべきAPIが存在しない&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;OAuth&#x2F;OIDC discovery metadata&lt;&#x2F;td&gt;&lt;td&gt;RFC 8414 等&lt;&#x2F;td&gt;&lt;td&gt;認証保護されたAPIや会員機能がない&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;OAuth Protected Resource Metadata&lt;&#x2F;td&gt;&lt;td&gt;RFC 9728&lt;&#x2F;td&gt;&lt;td&gt;同上&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;auth.md&lt;&#x2F;td&gt;&lt;td&gt;WorkOS提唱&lt;&#x2F;td&gt;&lt;td&gt;OAuth Protected Resource Metadataを前提とする、同上の理由&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;MCP Server Card&lt;&#x2F;td&gt;&lt;td&gt;SEP-1649(標準化進行中)&lt;&#x2F;td&gt;&lt;td&gt;MCPサーバーを運用していない&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;このブログは静的コンテンツを配信するだけのサイトで、APIやエージェント向けサービスは一切運用していません。この種の指摘は、SaaSやEC、API提供事業者向けのチェックリストとしては妥当ですが、個人ブログにはそもそも対象が存在しませんでした。&lt;&#x2F;p&gt;
&lt;h3 id=&quot;対応した項目&quot;&gt;対応した項目&lt;&#x2F;h3&gt;
&lt;p&gt;「ホームページにLink response header(RFC 8288)がない」という指摘もありました。ツールの提案は&lt;code&gt;rel=&quot;api-catalog&quot;&lt;&#x2F;code&gt;や&lt;code&gt;rel=&quot;service-doc&quot;&lt;&#x2F;code&gt;でAPIカタログやAPI仕様書を指すというものでしたが、このブログにAPIはないので、この提案どおりに実装しても意味がありません。&lt;&#x2F;p&gt;
&lt;p&gt;代わりに、Linkヘッダーの仕組み自体はこのブログでも使い道があると考え、次の2つを指すヘッダーを追加しました。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot; data-name=&quot;static&#x2F;_headers&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;&#x2F;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  Link: &amp;lt;&#x2F;license&#x2F;&amp;gt;; rel=&amp;quot;license&amp;quot;, &amp;lt;&#x2F;atom.xml&amp;gt;; rel=&amp;quot;alternate&amp;quot;; type=&amp;quot;application&#x2F;atom+xml&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;&lt;code&gt;rel=&quot;license&quot;&lt;&#x2F;code&gt;はIANA登録済みの正式なrelationで、CC BY-NC-ND 4.0を明記したライセンスページ(&lt;code&gt;&#x2F;license&#x2F;&lt;&#x2F;code&gt;)をAIエージェントが機械的に検出できるようにします。学習ボットのブロックと合わせて、コンテンツの利用条件を多層的に伝える形になりました。&lt;code&gt;rel=&quot;alternate&quot;&lt;&#x2F;code&gt;はZolaが生成するAtomフィード(&lt;code&gt;&#x2F;atom.xml&lt;&#x2F;code&gt;)へのリンクで、フィードの発見性を高めます。&lt;&#x2F;p&gt;
&lt;h3 id=&quot;対応を見送った項目&quot;&gt;対応を見送った項目&lt;&#x2F;h3&gt;
&lt;p&gt;残る3個は、対応自体は可能でも今回は見送りました。&lt;&#x2F;p&gt;
&lt;p&gt;Markdown for Agentsは、&lt;code&gt;Accept: text&#x2F;markdown&lt;&#x2F;code&gt;のリクエストにHTMLの代わりにMarkdownを返す機能です。CloudflareのAI Crawl Control上では確認できましたが、Proプラン以上限定(2026年7月時点で月$20〜25)のため、Freeプランの現状ではロックされていました。個人ブログの一機能としてはコストに見合わないと判断し、見送りました。&lt;&#x2F;p&gt;
&lt;p&gt;WebMCPは、ブラウザ内蔵のAIエージェントに&lt;code&gt;navigator.modelContext.provideContext()&lt;&#x2F;code&gt;でサイトの操作(検索など)を直接公開する仕組みです。現状はEarly Preview Program参加者限定の実験段階で、一般のブラウザではまだ有効化されていません。このブログの操作対象もpagefindによる検索程度で薄く、標準化が進んだ段階で再検討することにしました。&lt;&#x2F;p&gt;
&lt;p&gt;Agent Skills discovery indexは、&lt;code&gt;&#x2F;.well-known&#x2F;agent-skills&#x2F;index.json&lt;&#x2F;code&gt;にサイト固有の作業手順(SKILL.md)を公開する仕組みです。コンテンツサイト向けの想定用途は「文章校正」「カテゴリ分類の提案」といった編集アシスタント業務で、これは既に自分のClaude Code環境でローカルに完結しています。v0.2.0のドラフト段階でエコシステムの普及状況も未検証なため、こちらも見送りとしました。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;まとめ&quot;&gt;まとめ&lt;&#x2F;h2&gt;
&lt;p&gt;Agent Readinessスキャンの10個の指摘を並べてみると、その多くはAPIやSaaS、エージェント向けサービスを運用している事業者を想定したチェックリストだと分かりました。静的な個人ブログにとって本当に意味のある「AI対応」は、実は範囲が絞られます。当サイトでの結論は次のとおりです。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;CC BY-NC-NDライセンスの意図に沿って、学習目的のクローラーは技術的にブロックする&lt;&#x2F;li&gt;
&lt;li&gt;robots.txtのContent Signalsとライセンスページへの&lt;code&gt;rel=&quot;license&quot;&lt;&#x2F;code&gt;で、利用条件を機械可読な形でも表明する&lt;&#x2F;li&gt;
&lt;li&gt;検索エンジンやAI回答エンジンからの参照は妨げず、露出の機会は残す&lt;&#x2F;li&gt;
&lt;li&gt;WebMCPやAgent Skillsのようなドラフト段階の規格には、実際に普及するまで様子見の姿勢を崩さない&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;2月の記事で組んだ多層防御の骨格は変わっていませんが、Cloudflare側の仕様変更(混在クローラーの扱い)に合わせて設定を追随させ、Agent Readinessという新しい物差しで一度棚卸しをしたことで、このブログのAI対応の現在地を再確認できました。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;References&quot;&gt;References&lt;&#x2F;h2&gt;
&lt;!-- textlint-disable --&gt;
&lt;div class=&quot;references&quot;&gt;
    &lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;content-signals-policy&#x2F;&quot;&gt;Cloudflare&lt;&#x2F;a&gt;. &quot;Giving users choice with Cloudflare&#x27;s new Content Signals Policy&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;developers.cloudflare.com&#x2F;bots&#x2F;additional-configurations&#x2F;managed-robots-txt&#x2F;&quot;&gt;Cloudflare&lt;&#x2F;a&gt;. &quot;robots.txt setting&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;content-independence-day-ai-options&#x2F;&quot;&gt;Cloudflare&lt;&#x2F;a&gt;. &quot;Your site, your rules: new AI traffic options for all customers&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;agent-readiness&#x2F;&quot;&gt;Cloudflare&lt;&#x2F;a&gt;. &quot;Introducing the Agent Readiness score&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cloudflare.com&#x2F;plans&#x2F;pro&#x2F;&quot;&gt;Cloudflare&lt;&#x2F;a&gt;. &quot;Pro Plan Overview&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ietf.org&#x2F;archive&#x2F;id&#x2F;draft-mozleywilliams-dnsop-dnsaid-01.html&quot;&gt;IETF&lt;&#x2F;a&gt;. &quot;DNS for AI Discovery&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;dns-aid.org&#x2F;&quot;&gt;DNS-AID&lt;&#x2F;a&gt;. &quot;AI Agent Discovery via DNS&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.rfc-editor.org&#x2F;rfc&#x2F;rfc9727&quot;&gt;IETF&lt;&#x2F;a&gt;. &quot;RFC 9727: The api-catalog Well-Known URI and Link Relation Type&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.rfc-editor.org&#x2F;rfc&#x2F;rfc8288&quot;&gt;IETF&lt;&#x2F;a&gt;. &quot;RFC 8288: Web Linking&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;workos.com&#x2F;auth-md&quot;&gt;WorkOS&lt;&#x2F;a&gt;. &quot;auth.md — Open Protocol for Agent Registration&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;modelcontextprotocol&#x2F;modelcontextprotocol&#x2F;pull&#x2F;2127&quot;&gt;Model Context Protocol&lt;&#x2F;a&gt;. &quot;MCP Server Card (SEP-1649)&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;cloudflare&#x2F;agent-skills-discovery-rfc&quot;&gt;Cloudflare&lt;&#x2F;a&gt;. &quot;Agent Skills Discovery RFC&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;agentskills.io&#x2F;&quot;&gt;Agent Skills&lt;&#x2F;a&gt;. &quot;Agent Skills&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;developer.chrome.com&#x2F;blog&#x2F;webmcp-epp&quot;&gt;Chrome Developers&lt;&#x2F;a&gt;. &quot;WebMCP Early Preview Program&quot;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;

&lt;&#x2F;div&gt;
&lt;!-- textlint-enable --&gt;
</content>
        <summary type="html">2026年2月に整えたCloudflareのAIボット対策を4か月ぶりに見直しました。検索とAI学習を兼ねる「混在クローラー」を9月15日からブロック対象に含めるという仕様変更や、Agent Readinessスキャンで受けた10個の指摘を、個人ブログの視点で整理します。</summary>
        </entry><entry xml:lang="en">
        <title>メッセージングアプリの匿名性考察</title>
        <published>2026-07-01T10:00:00+09:00</published>
        <updated>2026-07-01T10:00:00+09:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2026/07/messenger-anonymity/" type="text/html"/>
        <id>https://codedchords.dev/blog/2026/07/messenger-anonymity/</id>
        
            <content type="html">&lt;!-- textlint-disable --&gt;
&lt;img
  src=&quot;https:&amp;#x2F;&amp;#x2F;codedchords.dev&amp;#x2F;blog&amp;#x2F;2026&amp;#x2F;07&amp;#x2F;messenger-anonymity&amp;#x2F;cover.webp?h=c60e5fcb30b3118d869c&quot;
  alt=&quot;Cover&quot; width=&quot;1536&quot; height=&quot;864&quot; loading=&quot;lazy&quot;
&#x2F;&gt;&lt;!-- textlint-enable --&gt;
&lt;details&gt;
&lt;summary&gt;Table of Contents&lt;&#x2F;summary&gt;
&lt;!-- toc --&gt;
&lt;&#x2F;details&gt;
&lt;p&gt;Threema GmbH（以下、Threema社）の公式ブログに「&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;threema.com&#x2F;en&#x2F;blog&#x2F;anonymity-at-the-system-level-the-ultimate-privacy-protection&quot;&gt;システムレベルの匿名性についての記事&lt;&#x2F;a&gt;」という記事が投稿されました。&lt;&#x2F;p&gt;
&lt;p&gt;メッセージングアプリの匿名性について論じています。以前、市川の強盗傷害事件をきっかけに&lt;a href=&quot;https:&#x2F;&#x2F;codedchords.dev&#x2F;blog&#x2F;2024&#x2F;10&#x2F;modern-messaging-apps&#x2F;&quot;&gt;暗号化やメタデータで機能比較した記事&lt;&#x2F;a&gt;を書きましたが、匿名性という観点はなかったのでこの記事を参考に解説したいと思います。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;メッセージングアプリの匿名性について&quot;&gt;メッセージングアプリの匿名性について&lt;&#x2F;h2&gt;
&lt;p&gt;Threema社の技術記事では、匿名性を二種類に分けています。&lt;&#x2F;p&gt;
&lt;dl&gt;
&lt;dt&gt;水平的匿名性&lt;&#x2F;dt&gt;
&lt;dd&gt;会話の相手に対する匿名性です。ユーザー名だけで連絡先を交換できれば、相手は電話番号や本名を知りません。対等な利用者どうしの間で成り立ちます。&lt;&#x2F;dd&gt;
&lt;dt&gt;垂直的匿名性&lt;&#x2F;dt&gt;
&lt;dd&gt;サービス運営者に対する匿名性です。登録時に電話番号やメールアドレスを渡していなければ、運営は身元を特定する手がかりを持ちません。利用者とサービスという上下の関係で成り立ちます。&lt;&#x2F;dd&gt;
&lt;&#x2F;dl&gt;
&lt;p&gt;Threema社は、ユーザー名機能で水平的匿名性は広まったものの、プライバシー保護で本当に重要なのは垂直的匿名性であり、これはセキュリティにおけるエンドツーエンド暗号化に相当する基盤だと主張します。あくまで同社の枠組みですが、この二軸はアプリを見比べる土台として使えます。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;垂直的匿名性の重要性について&quot;&gt;垂直的匿名性の重要性について&lt;&#x2F;h2&gt;
&lt;p&gt;なぜ運営に対する匿名性がそれほど問題になるのでしょうか。&lt;&#x2F;p&gt;
&lt;p&gt;メッセージングアプリでは、登録時に電話番号やメールアドレスを要求するものがあります。&lt;&#x2F;p&gt;
&lt;p&gt;ユーザー名で連絡先を交換できるサービスでも、相手にこうした個人情報を見せずに済むだけで、登録の段階では運営に渡しています。
電話番号やメールアドレスは本人確認や他サービスの登録にも使われる、生活に密着した識別子です。
運営がこれを保持していれば、別々の文脈で集めた情報を同一人物に結びつける手がかりとして使えてしまいます。&lt;&#x2F;p&gt;
&lt;p&gt;この紐付けは、広告で収益を上げるサービスでは特に意味を持ちます。利用者の行動を束ねてプロフィールを作るほど広告の精度が上がるので、複数の情報源を統合する動機がもともと働きます。電話番号やメールアドレスのような確実な識別子があれば、その統合は格段にやりやすくなります。メッセージの中身が暗号化されていても、誰がいつ誰と連絡したかというメタデータや、それを個人に結びつける識別子までは覆い隠せません。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;メッセージングアプリの匿名性の比較&quot;&gt;メッセージングアプリの匿名性の比較&lt;&#x2F;h2&gt;
&lt;p&gt;ここまでの軸で、私が知る範囲の主要なアプリを並べてみます。&lt;&#x2F;p&gt;
&lt;p&gt;暗号化の強さと、運営に対する匿名性は別物だという点に注目してください。暗号化の対応範囲やメタデータ収集、法執行機関への開示といった機能面の詳しい比較は&lt;a href=&quot;https:&#x2F;&#x2F;codedchords.dev&#x2F;blog&#x2F;2024&#x2F;10&#x2F;modern-messaging-apps&#x2F;&quot;&gt;前回の記事&lt;&#x2F;a&gt;にまとめたので、ここでは匿名性の軸に絞ります。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;アプリ&lt;&#x2F;th&gt;&lt;th&gt;登録時に必要な個人情報&lt;&#x2F;th&gt;&lt;th&gt;運営に対する匿名性&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;LINE&lt;&#x2F;td&gt;&lt;td&gt;電話番号&lt;&#x2F;td&gt;&lt;td&gt;なし&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;WhatsApp&lt;&#x2F;td&gt;&lt;td&gt;電話番号&lt;&#x2F;td&gt;&lt;td&gt;なし&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;iMessage&lt;&#x2F;td&gt;&lt;td&gt;電話番号または Apple Account&lt;&#x2F;td&gt;&lt;td&gt;なし&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Signal&lt;&#x2F;td&gt;&lt;td&gt;電話番号&lt;&#x2F;td&gt;&lt;td&gt;なし&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Element &#x2F; Matrix&lt;&#x2F;td&gt;&lt;td&gt;なし（メールは任意）&lt;&#x2F;td&gt;&lt;td&gt;サーバー次第&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Threema&lt;&#x2F;td&gt;&lt;td&gt;なし&lt;&#x2F;td&gt;&lt;td&gt;運営は満たすと主張&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Session&lt;&#x2F;td&gt;&lt;td&gt;なし&lt;&#x2F;td&gt;&lt;td&gt;高い&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;SimpleX&lt;&#x2F;td&gt;&lt;td&gt;なし&lt;&#x2F;td&gt;&lt;td&gt;最も高い部類&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;国内利用者の多いLINEは、もう少し細かく見ておきます。LINEのメッセージはLetter Sealingと呼ぶ技術で暗号化されていますが、50人を超えるグループトーク、グループ音声・ビデオ通話、LINEミーティング、アルバム、ノートは対象外で、通信路のTLS暗号化にとどまります。
この範囲は運営が技術的に中身へアクセスし得ます。そして匿名性の面では、登録に電話番号が必須なので運営に対する匿名性は持ちません。自治体などが市民の申請にLINEを使
うケースが増えていますし、たまに企業でも業務で使用しているケースを見かけます。セキュリティ意識の低さには驚きます。&lt;&#x2F;p&gt;
&lt;p&gt;WhatsAppとiMessageも、垂直的匿名性はありません。メッセージの暗号化に対応していますが、登録にはWhatsAppが電話番号、iMessageが電話番号かApple Accountを必要とします。この時点で運営に対する匿名性は持ちません。
特にWhatsAppを運営するMeta社は広告を収入源としているので
、個人情報に関連したメタデータを収集してグループ内の他社と共有している可能性があります。
中身は守られても、誰といつ繋がったかまでは隠せません。&lt;&#x2F;p&gt;
&lt;!-- textlint-disable --&gt;
&lt;aside data-position=&quot;right&quot;&gt;
    &lt;p&gt;ただし、Signalのメタ情報の電話番号、登録日、最終接続日のみ。&lt;&#x2F;p&gt;

&lt;&#x2F;aside&gt;
&lt;!-- textlint-enable --&gt;
&lt;p&gt;暗号化に強いというイメージのSignalも垂直的匿名性はありません。
ユーザー名機能が2024年に加わり、電話番号を教えないまま連絡できるようになりました(水平的匿名性)が、
アカウントの作成には今も電話番号が必須です。
Signalを運営するのはSignal Foundationという非営利団体ですが、拠点はカリフォルニア州です。
つまり米国の管轄下なので、米国の捜査機関の要求があれば開示義務があります。&lt;&#x2F;p&gt;
&lt;p&gt;ElementはMatrixというオープンなプロトコルの上に作られています。登録に必要なのは、選んだサーバー上のユーザー名とパスワードだけで、電話番号は要りません。メールアドレスはパスワード再設定用に任意で登録でき、サーバーによっては不正利用対策で求められることもあります。利用者はmatrix.orgのような公開サーバーを選んで登録するのが一般的で、自前でサーバーを立てることもできます。運営に対する匿名性は、結局どのサーバーを信頼するかに依存します。&lt;&#x2F;p&gt;
&lt;p&gt;結局、垂直的匿名性を保持しているのは、Threema、Session、SimpleXのみです。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;垂直的匿名性の代償&quot;&gt;垂直的匿名性の代償&lt;&#x2F;h2&gt;
&lt;p&gt;垂直的匿名性の仕組みと、その代わりに払う利便性のコストを見ておきます。&lt;&#x2F;p&gt;
&lt;p&gt;Threemaは電話番号やメールアドレスを必要とせず、アカウントはランダムに割り当てられたThreema IDだけで機能します。
ユーザーはThreema IDを交換しメッセージの送受信を行ないます。
伝えるのはThreema IDのみなので、運営や相手に身元を明かさずに通信できます。
Threemaを使用していることすら秘匿する為にGoogle Playなどに依存せずThreemaを入手・購入できる手段も提供しています。
Threema IDはThreema社により管理されており、「IDが誰か」はThreema社に把握されませんが「いつ・どのIDと通信したか」は
論理的にはThreema社で把握可能です。ただし、Threema社は広告やトラッキングを行なわないというポリシーを持ち、収益源を買い切り課金に置いています。&lt;&#x2F;p&gt;
&lt;p&gt;SimpleXは、利用者を識別する固定IDを一切持たない設計です。電話番号やユーザー名はもちろん、ランダムなIDすら使いません。仕組みは一方向のメッセージキューで、接続ごとに送信用と受信用の別々のキューを持ち、通常はそれぞれ別のサーバーを経由します。
サーバーから見えるのは不透明なキューへの孤立した配送だけで、送信者と受信者を結びつけられません。サーバー同士も通信せず、配送が済んだメッセージは保存しません。&lt;&#x2F;p&gt;
&lt;p&gt;SessionはもともとSignalのフォークとして始まりました。電話番号やメールなどの個人データも不要で、ランダムなSession IDという66文字程度の公開鍵をアカウントのIDとして使います。メッセージは多数の有志ノードからなるオニオン型のネットワークを経由し、どのノードも送信者と受信者の両方を知ることはありません。運営は2024年10月に、暗号化技術への規制圧力を背景としてオーストラリアからスイスへ拠点を移し、現在はスイスのSession Technology Foundationが運営しています。コードはQuarkslabによる独立監査を受けています。SimpleXとの違いは、Sessionが永続的なアカウントのIDを持つ点です。&lt;&#x2F;p&gt;
&lt;p&gt;これらの高い匿名性には、現実的な代償が伴います。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;いずれも、相手に直接リンクやQRコード、IDを渡さなければ会話を始められない&lt;&#x2F;li&gt;
&lt;li&gt;従って、電話番号やユーザー名で気軽に相手を見つけることはできず、なんらかの方法で相手と直接これらの情報を交換する必要がある&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;一番問題になるのは、相手も同じアプリを入れている必要があるところでしょう。
いずれもマイナーなアプリなので、匿名性のために連絡相手の数と手軽さを大きく差し出すことになります。
この利便性の低さは、日常使いを考えるうえで無視できないトレードオフです。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;メッセージングアプリについて私の選択&quot;&gt;メッセージングアプリについて私の選択&lt;&#x2F;h2&gt;
&lt;p&gt;ここまで匿名性の強さで並べてきましたが、強ければ強いほどよい、という話ではありません。匿名性がどれだけ効くかは、相手があなたの身元を知っているかどうかで変わります。&lt;&#x2F;p&gt;
&lt;p&gt;私は以下のように考えています。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;関係&lt;&#x2F;th&gt;&lt;th&gt;説明&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;家族&lt;&#x2F;td&gt;&lt;td&gt;当然対面しており、インストールするアプリも管理可能。機微なメッセージ交換もあり&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;友人&lt;&#x2F;td&gt;&lt;td&gt;対面しているが、アプリの管理は困難。機微なメッセージ交換は限定的&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;他人&lt;&#x2F;td&gt;&lt;td&gt;必ずしも対面していない。アプリの管理は不能。機微なメッセージはなし&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;このように考えると、家族とは水平的匿名性は不要で垂直的匿名性が必要です。
前回の記事でも軽く触れましたが、私自身は家族との連絡用にThreemaを選んでいます。
SimpleXやSessionでもよいのですが、かなり以前からThreemaを使用しており、特に問題もないために使用を続けています。&lt;&#x2F;p&gt;
&lt;p&gt;友人も同様です。知り合いなので水平的匿名性は不要ですが、垂直的匿名性は必要です。
しかし、現実的には垂直的匿名性を実現するために、先に記述した「代償」のため友人に対応するアプリを導入してもらうことは困難です。
そのため諦めて必要な場合は、友人にはメールかSMSでのコンタクトを依頼しています。暗号化、匿名性は放棄すると言うことです。
LINEなどを使っていると「じゃ、LINEで」と言われるので、私はLINEなどのアプリは使わずインストールさえしていません。&lt;&#x2F;p&gt;
&lt;p&gt;ネットで知り合ったような他人については、どちらの匿名性も重要だと思います。
しかし、私は、匿名のままネットで知り合った相手とメッセージングアプリを使って通信するようなニーズはないので無視します。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;まとめ&quot;&gt;まとめ&lt;&#x2F;h2&gt;
&lt;p&gt;LINE・WhatsApp・iMessage・Signalなど主要なメッセージングアプリは、暗号化や水平的匿名性は実装されていますが、
垂直的匿名性は担保されていません。LINEなど「なりすまし防止、復旧、法令遵守」などを理由に電話番号への紐付けを強化しています。
自治体などでLINEを使用するケースが多いようですが、あれは個人特定を行政として放棄しているとしか思えません。&lt;&#x2F;p&gt;
&lt;p&gt;私にとって必要なのは垂直的匿名性です。メッセージの中身が暗号化されていても、運営に身元や「誰といつ通信したか」を握られては、プライバシーを守ったことになりません。
一方、相手に対しても名乗らない水平的匿名性は、私個人にはほとんど必要ありません。&lt;&#x2F;p&gt;
&lt;p&gt;両方の匿名性を保てるのは、Threema・Session・SimpleXの3つです。&lt;&#x2F;p&gt;
&lt;!-- textlint-disable --&gt;
&lt;aside data-position=&quot;right&quot;&gt;
    &lt;p&gt;米国報道機関ではSignalが使用されているケースが多いようです。&lt;&#x2F;p&gt;

&lt;&#x2F;aside&gt;
&lt;!-- textlint-enable --&gt;
&lt;p&gt;両方の匿名性が必要なのは、相手や運営に身元を伏せたまま連絡したい場面だけです。
こうしたニーズは犯罪目的での使用を想起するかもしれませんが、内部告発や情報提供など正当な目的のためにも必要です。
米国では報道機関が情報提供の窓口としてメッセージングアプリの宛先などを公開しています。
日本ではこうした使い方はほとんど根づいておらず、全く遅れています。&lt;&#x2F;p&gt;
&lt;p&gt;大切なのは、自分がどちらの匿名性を必要とするのかを見極めることです。垂直的匿名性はほとんどの人に効きますが、水平的匿名性まで求めるかは人によって大きく変わります。私自身は、身元を隠す必要のない家族との連絡に、垂直的匿名性を保ちつつ扱いやすいThreemaを使っています。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;References&quot;&gt;References&lt;&#x2F;h2&gt;
&lt;!-- textlint-disable --&gt;
&lt;div class=&quot;references&quot;&gt;
    &lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;threema.com&#x2F;en&#x2F;blog&#x2F;anonymity-at-the-system-level-the-ultimate-privacy-protection&quot;&gt;Threema&lt;&#x2F;a&gt;. &quot;Anonymity at the System Level: The Ultimate Privacy Protection&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;threema.ch&#x2F;en&#x2F;blog&#x2F;posts&#x2F;news-alleged-weaknesses-statement&quot;&gt;Threema&lt;&#x2F;a&gt;. &quot;Statement on ETH Findings&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;breakingthe3ma.app&#x2F;&quot;&gt;ETH Zurich Applied Cryptography Group&lt;&#x2F;a&gt;. &quot;Three Lessons from Threema&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;signal.org&#x2F;blog&#x2F;phone-number-privacy-usernames&#x2F;&quot;&gt;Signal&lt;&#x2F;a&gt;. &quot;Keep your phone number private with Signal usernames&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;signalfoundation.org&#x2F;en&#x2F;&quot;&gt;Signal Foundation&lt;&#x2F;a&gt;. &quot;Signal Foundation&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;simplex.chat&#x2F;docs&#x2F;simplex.html&quot;&gt;SimpleX Chat&lt;&#x2F;a&gt;. &quot;How SimpleX works&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;getsession.org&#x2F;blog&#x2F;introducing-the-session-technology-foundation&quot;&gt;Session&lt;&#x2F;a&gt;. &quot;Introducing the Session Technology Foundation&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;getsession.org&#x2F;session-code-audit&quot;&gt;Session&lt;&#x2F;a&gt;. &quot;Session code audit by Quarkslab&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;faq.whatsapp.com&#x2F;820124435853543&quot;&gt;WhatsApp Help Center&lt;&#x2F;a&gt;. &quot;About end-to-end encryption&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;support.apple.com&#x2F;guide&#x2F;security&#x2F;imessage-security-overview-secd9764312f&#x2F;web&quot;&gt;Apple Support&lt;&#x2F;a&gt;. &quot;iMessage security overview&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;docs.element.io&#x2F;latest&#x2F;element-support&#x2F;matrix-account-management&#x2F;creating-a-matrix-account&#x2F;&quot;&gt;Element&lt;&#x2F;a&gt;. &quot;Creating a Matrix Account&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;help.line.me&#x2F;line&#x2F;smartphone&#x2F;categoryId&#x2F;20010067&#x2F;3&#x2F;pc&quot;&gt;LINE Help Center&lt;&#x2F;a&gt;. &quot;Letter Sealing&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.lycorp.co.jp&#x2F;ja&#x2F;privacy-security&#x2F;security&#x2F;transparency&#x2F;encryption-report&#x2F;2025&#x2F;&quot;&gt;LINEヤフー&lt;&#x2F;a&gt;.「LINE暗号化状況レポート（2025年）」&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;

&lt;&#x2F;div&gt;
&lt;!-- textlint-enable --&gt;
</content>
        <summary type="html">Threema公式ブログに「システムレベルの匿名性」についての記事が公開されました。
日本ではLINEが主流で匿名性についての関心は薄いと思うので、その仕組みと重要性を解説してみました。
</summary>
        </entry><entry xml:lang="en">
        <title>三菱UFJ銀行のPPAP廃止は、半歩前進で半歩後退</title>
        <published>2026-06-08T00:00:00+00:00</published>
        <updated>2026-06-08T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2026/06/mufg-ppap/" type="text/html"/>
        <id>https://codedchords.dev/blog/2026/06/mufg-ppap/</id>
        
            <content type="html">&lt;!-- textlint-disable --&gt;
&lt;img
  src=&quot;https:&amp;#x2F;&amp;#x2F;codedchords.dev&amp;#x2F;blog&amp;#x2F;2026&amp;#x2F;06&amp;#x2F;mufg-ppap&amp;#x2F;cover.webp?h=027a043bdcc9bd7b745e&quot;
  alt=&quot;Cover&quot; width=&quot;1536&quot; height=&quot;864&quot; loading=&quot;lazy&quot;
&#x2F;&gt;&lt;!-- textlint-enable --&gt;
&lt;p&gt;三菱UFJ銀行が2026年6月8日付で「&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bk.mufg.jp&#x2F;info&#x2F;pdf&#x2F;20260608_send_attachments.pdf&quot;&gt;当行からの添付ファイル送信方法の変更に関するご案内&lt;&#x2F;a&gt;」を公表しました。
日本を代表するメガバンクがまだPPAPやっていたと衝撃を受けました。
内容を読んで考えさせられたので記録しておきます。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;三菱UFJ銀行のアナウンス&quot;&gt;三菱UFJ銀行のアナウンス&lt;&#x2F;h2&gt;
&lt;p&gt;要点はシンプルです。&lt;&#x2F;p&gt;
&lt;p&gt;同行は、お客さま側のセキュリティを確保するため、パスワード付き添付ファイルのメール送信を原則取り止めると発表しました。
2026年7月18日より順次、添付ファイルを送る際は専用のダウンロードサイトを利用する方式へ変更されます。&lt;&#x2F;p&gt;
&lt;p&gt;理由として挙げられているのは次の2点です。
これまでの「メールでパスワード付きZIPファイルを送り、パスワードを別送する方法」、いわゆる &lt;strong&gt;PPAP&lt;&#x2F;strong&gt; は、ファイルが暗号化されているためメール受信時のマルウェアチェックが困難であること。
そして近年、パスワード付きZIPファイルを悪用したサイバー攻撃の事例が確認されていることです。&lt;&#x2F;p&gt;
&lt;p&gt;新方式では、同行の役職員が添付ファイルを送る際、メール本文に専用ダウンロードサイトへアクセスするためのURLを記載します。
受け手はそのサイトにアクセスし、別送されるダウンロード専用のパスワードを使ってファイルを取得します。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;PPAPの何が問題だったのか&quot;&gt;PPAPの何が問題だったのか&lt;&#x2F;h2&gt;
&lt;p&gt;PPAPの是非については、昨年「&lt;a href=&quot;&#x2F;blog&#x2F;2025&#x2F;06&#x2F;aws-sns&#x2F;&quot;&gt;AWSからSMSにメッセージを送る&lt;&#x2F;a&gt;」という記事で一度整理しました。&lt;&#x2F;p&gt;
&lt;p&gt;そのとき、機密文書をメールで送る手段を秘匿性と本人確認性の観点で並べて評価したのですが、結論は変わっていません。&lt;&#x2F;p&gt;
&lt;p&gt;PPAP、つまり暗号化ファイルとパスワードを同じ経路で送る方法は、1通盗まれればすべて漏洩します。
パスワードを別メールにしても、同じメールインフラを流れる以上、傍受や誤送信のリスクは本質的には下がりません。
加えて、暗号化されたZIPはメールゲートウェイでウイルススキャンできないため、マルウェアの運び屋になりやすい。
三菱UFJ銀行が今回理由として挙げているのは、まさにこの最後の点です。&lt;&#x2F;p&gt;
&lt;p&gt;ですから、PPAPをやめるという判断そのものは正しいと思います。
日本でも2020年に政府がPPAPの廃止方針を打ち出して以降の流れに沿っていますし、銀行という立場で旗を振る意味も小さくありません。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;新方式は本当に安全になったのか&quot;&gt;新方式は本当に安全になったのか&lt;&#x2F;h2&gt;
&lt;p&gt;問題は、その置き換え先です。&lt;&#x2F;p&gt;
&lt;p&gt;新方式は「メール本文にダウンロードサイトのURLを記載し、パスワードは別送する」というものでした。
マルウェアスキャンの観点では確かに前進しています。
ファイルが暗号化ZIPとしてメールに乗らなくなるので、受信側のゲートウェイで中身を検査できるようになるからです。&lt;&#x2F;p&gt;
&lt;p&gt;しかし、フィッシング耐性という観点では、むしろ後退しかねません。&lt;&#x2F;p&gt;
&lt;p&gt;ひとつは、銀行が自ら「メール本文のURLをクリックさせる」習慣を送信先に植え付けてしまう点です。
銀行はこれまでフィッシング対策として、「当行からのメールにURLは記載しません」「メール内のリンクは開かないでください」と顧客には教育してきたはずです。
メールの送信先は顧客ではないと思いますが、今回はその逆を習慣づけることになります。
なりすましメールに偽のダウンロードURLが貼られていても、利用者は見分けがつかなくなります。&lt;&#x2F;p&gt;
&lt;p&gt;もうひとつは、「パスワードを別送する」という発想がPPAPのままという点です。
日ごろ支援しているコンサルテーション会社やITベンダーはちゃんと技術的に支援できなかったんでしょうか？&lt;&#x2F;p&gt;
&lt;p&gt;URLとパスワードを両方メールで送るのであれば、構造的にはPPAPの暗号化ZIPをWebサイトに置き換えただけです。
同じ経路を流れる以上、傍受や誤送信による漏洩リスクは解決していません。
マルウェアの問題は片付いても、秘匿性の問題は手つかずなのです。&lt;&#x2F;p&gt;
&lt;p&gt;整理すると、今回の変更は「マルウェアスキャン」という一点ではマシになる一方で、フィッシング耐性では弱点を抱え込む、惜しい設計だと感じます。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;本来あるべき姿&quot;&gt;本来あるべき姿&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;blog&#x2F;2025&#x2F;06&#x2F;aws-sns&quot;&gt;以前の記事&lt;&#x2F;a&gt;でも書きましたが、
現実的なのは認証付きのクラウドストレージで共有する方法でした。
受け手がログインして初めてファイルにアクセスできる仕組みなら、URLが単体で漏れても無効ですし、誰がいつアクセスしたかのログも残せます。
パスワードを別送する必要すらありません。&lt;&#x2F;p&gt;
&lt;p&gt;メールの送付先は取引業者だと思いますから、銀行が共通の認証を払い出すのは困難です。
たとえばBoxやDropboxのようなクラウドストレージであれば、受け手は無料のアカウントを気軽に作れます。
銀行側が取引先ごとにアカウントを発行・運用しなくても、受け手がログインして初めてファイルにアクセスできる仕組みを成り立たせられるわけです。
URLが単体で漏れても無効ですし、誰がいつアクセスしたかのログも残ります。&lt;&#x2F;p&gt;
&lt;p&gt;さらに言えば、この方式ならメールにリンクを書く必要すらありません。
ファイルを共有すれば、受け手にはクラウドストレージ側から「共有されました」という通知が届きます。
受け手は自分が信頼しているサービスにログインしてファイルを取りに行くだけです。
冒頭で挙げた、メール内URLをクリックさせる習慣づけという問題が、根本から消えてなくなるのです。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;より根本的な解はないのか&quot;&gt;より根本的な解はないのか&lt;&#x2F;h2&gt;
&lt;p&gt;もっとも、銀行ともあろうものがファイルの受け渡しを外部のクラウドサービスに丸ごと預けるのも、それはそれで引っかかります。
委託先管理やデータの所在、サービスへの従属といった問題が新たに生じるからです。
だとすれば、現実的な落としどころは、銀行が認証付きの受け渡しポータルを自前で持つことでしょう。
インターネットバンキングという認証基盤と運用ノウハウをすでに備え、取引先の本人確認も日常的に行っている組織です。
Boxがやっていることを内製すればよいだけです。技術力と体力の両面で、銀行はそれができる立場にあります。&lt;&#x2F;p&gt;
&lt;p&gt;では、もっと教科書的な根本解はないのか。
あります。受け手の証明書でメールそのものを暗号化・署名するS&#x2F;MIME、いわゆるPKIです。
外部サービスやポータル、パスワードの別送といった仕組みが一切要らず、本人性と秘匿性をエンドツーエンドで担保できる、理屈のうえでは最も美しい解です。&lt;&#x2F;p&gt;
&lt;p&gt;ところがPKIは、米国ですら普及しませんでした。
証明書の発行や管理が高コストで手作業が多く、ユーザーごと・端末ごとに鍵を入れて回る運用負荷に耐えられなかったためです。
そして決定的なのは、&lt;strong&gt;送り手と受け手の双方が対応していないと成り立たない&lt;&#x2F;strong&gt;という両側依存です。
暗号化して送るには、相手があらかじめ証明書を用意していなければなりません。
相手が対応していなければ、文字どおり意味がない。
この鶏と卵の構造ゆえに、誰も最初の一歩を踏み出せませんでした。
受け手に「アカウントを作ってログインする」という自己完結した操作しか求めないポータル方式に世界が流れたのは、そのためです。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;それでもリーダーシップを期待したかった&quot;&gt;それでもリーダーシップを期待したかった&lt;&#x2F;h2&gt;
&lt;p&gt;ここで私が惜しいと思うのは、まさにこの一点です。
PKIが普及しなかった最大の理由が「最初の一歩を誰も踏み出せなかった」ことなら、その一歩を踏み出せる体力と影響力を持つ組織こそ、日本を代表するメガバンクのはずです。&lt;&#x2F;p&gt;
&lt;p&gt;率先してS&#x2F;MIMEを導入し、添付ファイルをやり取りするような主要な取引先には導入を促す。
場合によっては証明書発行の基盤を貸し出したり、運用を支援したりする。
そうやって両側依存の壁を、影響力のある側から崩していく。
そんなリーダーシップを見せてくれたら、日本全体のメール文化が一段前に進んだかもしれません。&lt;&#x2F;p&gt;
&lt;p&gt;現実的な着地は認証付きポータルでよいと思います。
ただ、PPAPをやめるという入口が正しかっただけに、出口がもう一歩踏み込めなかったのは惜しい。
日本をリードする銀行のやることだからこそ、ここにこそリーダーシップを期待したかった、というのが私の正直な感想です。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;References&quot;&gt;References&lt;&#x2F;h2&gt;
&lt;!-- textlint-disable --&gt;
&lt;div class=&quot;references&quot;&gt;
    &lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bk.mufg.jp&#x2F;info&#x2F;pdf&#x2F;20260608_send_attachments.pdf&quot;&gt;株式会社三菱UFJ銀行&lt;&#x2F;a&gt;. 「当行からの添付ファイル送信方法の変更に関するご案内」（2026年6月8日）&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a href=&quot;&#x2F;blog&#x2F;2025&#x2F;06&#x2F;aws-sns&#x2F;&quot;&gt;Coded Chords&lt;&#x2F;a&gt;. 「AWSからSMSにメッセージを送る」（2025年6月9日）&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;

&lt;&#x2F;div&gt;
&lt;!-- textlint-enable --&gt;
</content>
        <summary type="html">日本を代表する銀行がPPAPの廃止を発表しました。マルウェア対策としては正しい一歩ですが、新しい受け渡し方法には見過ごせない落とし穴が残っています。</summary>
        </entry><entry xml:lang="en">
        <title>無料で始める Cloudflare セキュリティ対策</title>
        <published>2026-03-23T00:00:00+00:00</published>
        <updated>2026-03-23T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2026/03/cloudflare-free-security/" type="text/html"/>
        <id>https://codedchords.dev/blog/2026/03/cloudflare-free-security/</id>
        
            <content type="html">&lt;!-- textlint-disable --&gt;
&lt;img
  src=&quot;https:&amp;#x2F;&amp;#x2F;codedchords.dev&amp;#x2F;blog&amp;#x2F;2026&amp;#x2F;03&amp;#x2F;cloudflare-free-security&amp;#x2F;cover.webp?h=9bfc915254c8cd5bf47d&quot;
  alt=&quot;Cover&quot; width=&quot;1792&quot; height=&quot;1024&quot; loading=&quot;lazy&quot;
&#x2F;&gt;&lt;!-- textlint-enable --&gt;
&lt;span id=&quot;continue-reading&quot;&gt;&lt;&#x2F;span&gt;&lt;h2 id=&quot;公開翌日に何が起きたか&quot;&gt;公開翌日に何が起きたか&lt;&#x2F;h2&gt;
&lt;p&gt;先日の記事で紹介した生成AIを使った&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;ask.codedchords.dev&quot;&gt;Ask&lt;&#x2F;a&gt; ページを公開した翌日、CloudflareのObservabilityを確認したところ、攻撃と思われるリクエストが並んでいました。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;GET &#x2F;.env&lt;&#x2F;code&gt; — 環境変数ファイルの探索&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;&#x2F;checkout&lt;&#x2F;code&gt;, &lt;code&gt;&#x2F;plans&lt;&#x2F;code&gt;, &lt;code&gt;&#x2F;signup&lt;&#x2F;code&gt; — SaaS系パスの総当たり&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;&#x2F;wp-login&lt;&#x2F;code&gt;, &lt;code&gt;&#x2F;wp-admin&lt;&#x2F;code&gt;, &lt;code&gt;&#x2F;xmlrpc.php&lt;&#x2F;code&gt; — WordPress管理画面の探索&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;&#x2F;api&#x2F;v1&#x2F;stripe&#x2F;config.js&lt;&#x2F;code&gt;, &lt;code&gt;&#x2F;api&#x2F;v2&#x2F;payment&#x2F;keys.js&lt;&#x2F;code&gt; — 決済APIの設定ファイル探索（Stripeはオンライン決済プラットフォーム）&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;config.php&lt;&#x2F;code&gt;, &lt;code&gt;&#x2F;api&#x2F;system&#x2F;info&lt;&#x2F;code&gt; — サーバー情報の収集&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;主にWordPressなどのCMSやStripeなどの決済サービスを狙ったスキャンです。静的サイト＋Workerという構成なのでそんなサービスは乗せていないのですが。公開されているエンドポイントに対してよく狙われる既知のパスを片っ端から叩いているのでしょう。&lt;&#x2F;p&gt;
&lt;p&gt;実害はありませんが、放置するのも気持ちが悪いですし、Workers AIのNeuronsを無駄に消費されるのは避けたいところです。Cloudflareの無料プランのセキュリティ機能で対策しました。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;対策1:_Bot_Fight_Mode&quot;&gt;対策1: Bot Fight Mode&lt;&#x2F;h2&gt;
&lt;p&gt;最も手軽な対策です。Cloudflareダッシュボードの &lt;strong&gt;Security &amp;gt; Bots&lt;&#x2F;strong&gt; から、ワンクリックで有効化できます。&lt;&#x2F;p&gt;
&lt;p&gt;Bot Fight ModeはCloudflareが持つボットの行動パターンデータベースを使い、自動化されたアクセスを検出して計算コストの高いチャレンジを返します。検索エンジンのクローラーなど検証済みの正当なボットは通過させる仕組みです。&lt;&#x2F;p&gt;
&lt;p&gt;設定はON&#x2F;OFFだけで、細かなチューニングは有料プラン（Super Bot Fight Mode）の機能になります。それでも、汎用的なスキャンボットの大半はこれで弾けます。&lt;&#x2F;p&gt;
&lt;p&gt;注意点として、Bot Fight Modeは外部サービスからのWebhookやRSSリーダーのフィード取得など、正当な自動アクセスもブロックする場合があります。無料プランではWAFルールによるバイパス（Skip）ができないため、これらのサービスに影響が出た場合はBot Fight Mode自体を無効にする必要があります。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;対策2:_WAF_カスタムルール&quot;&gt;対策2: WAF カスタムルール&lt;&#x2F;h2&gt;
&lt;p&gt;Bot Fight Modeをすり抜けるアクセスに対しては、WAF（Web Application Firewall）のカスタムルールで対処します。無料プランでは5つまでルールを作成できます。&lt;&#x2F;p&gt;
&lt;h3 id=&quot;ルール1:_許可パスの制限（ホワイトリスト）&quot;&gt;ルール1: 許可パスの制限（ホワイトリスト）&lt;&#x2F;h3&gt;
&lt;p&gt;最も効果が高いルールを最優先に配置します。ask.codedchords.devは &lt;code&gt;&#x2F;&lt;&#x2F;code&gt;（フロントエンド）と &lt;code&gt;&#x2F;api&#x2F;&lt;&#x2F;code&gt;（Workers API）しか使わないので、それ以外を全てブロックします。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot; data-name=&quot;Expression&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;(http.host eq &amp;quot;ask.codedchords.dev&amp;quot;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;and not (http.request.uri.path eq &amp;quot;&#x2F;&amp;quot; or http.request.uri.path contains &amp;quot;&#x2F;api&#x2F;&amp;quot;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Actionは &lt;strong&gt;Block&lt;&#x2F;strong&gt;、Place atは &lt;strong&gt;First&lt;&#x2F;strong&gt; に設定します。&lt;&#x2F;p&gt;
&lt;p&gt;「正当なパスだけを許可する」ホワイトリスト方式なので、攻撃者がどんなパスを試してもすり抜けられません。ただし、対象サイトの構成を把握している必要があります。新しいパスを追加した際にルールの更新を忘れると自分自身のコンテンツがブロックされるため、サイト構成を変更したらルールも見直してください。&lt;&#x2F;p&gt;
&lt;h3 id=&quot;ルール2:_スキャンパスの遮断（ブラックリスト）&quot;&gt;ルール2: スキャンパスの遮断（ブラックリスト）&lt;&#x2F;h3&gt;
&lt;p&gt;ルール1はaskサブドメイン限定なので、ドメイン全体に適用する汎用ルールも設定します。WordPressやphpMyAdminなど、よく狙われるパスへのアクセスを一括でブロックします。&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Security &amp;gt; Security rules &amp;gt; Create rule&lt;&#x2F;strong&gt; から、以下のExpressionを設定します。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot; data-name=&quot;Expression&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;(http.request.uri.path contains &amp;quot;.env&amp;quot;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;or (http.request.uri.path contains &amp;quot;wp-login&amp;quot;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;or (http.request.uri.path contains &amp;quot;wp-admin&amp;quot;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;or (http.request.uri.path contains &amp;quot;xmlrpc.php&amp;quot;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;or (http.request.uri.path contains &amp;quot;phpmyadmin&amp;quot;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;or (http.request.uri.path contains &amp;quot;wp-content&amp;quot;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;or (http.request.uri.path contains &amp;quot;wp-includes&amp;quot;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Actionは &lt;strong&gt;Block&lt;&#x2F;strong&gt; です。&lt;&#x2F;p&gt;
&lt;p&gt;このルールはサイトの構成に依存しないため、Cloudflareで管理しているドメイン全体に適用できます。WordPressを使っていないサイトであれば、デメリットはありません。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;対策3:_Rate_Limiting&quot;&gt;対策3: Rate Limiting&lt;&#x2F;h2&gt;
&lt;p&gt;Bot Fight ModeとWAFルールを通過したリクエストに対する最後の砦です。同一IPからの過剰なリクエストを制限します。&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Security &amp;gt; Security rules &amp;gt; Rate limiting rules&lt;&#x2F;strong&gt; から設定します。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;項目&lt;&#x2F;th&gt;&lt;th&gt;設定値&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;対象&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;http.host eq &quot;ask.codedchords.dev&quot;&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;判定基準&lt;&#x2F;td&gt;&lt;td&gt;IP&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;レート&lt;&#x2F;td&gt;&lt;td&gt;10リクエスト &#x2F; 10秒&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Action&lt;&#x2F;td&gt;&lt;td&gt;Block（10秒間）&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;無料プランではRate Limitingルールは1つまで、ブロック期間は最大10秒という制約があります。大規模な攻撃には有料プランのRate Limiting（より長いブロック期間、より多くのルール）が必要ですが、スキャンボット対策としては十分です。上記の設定値は一例です。ページ内のリソース数や想定されるアクセスパターンに応じて調整してください。&lt;&#x2F;p&gt;
&lt;p&gt;なお、今回はWorkers側にも &lt;code&gt;&#x2F;api&#x2F;ask&lt;&#x2F;code&gt; エンドポイントに対して同一IP 60秒間10リクエストの制限を入れています。CloudflareのRate Limitingはインフラ層での粗いフィルタリング、Workers側はアプリケーション層での細かな制御という役割分担です。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;3層防御の全体像&quot;&gt;3層防御の全体像&lt;&#x2F;h2&gt;
&lt;p&gt;設定した対策を整理します。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;レイヤー&lt;&#x2F;th&gt;&lt;th&gt;対策&lt;&#x2F;th&gt;&lt;th&gt;役割&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;第1層&lt;&#x2F;td&gt;&lt;td&gt;Bot Fight Mode&lt;&#x2F;td&gt;&lt;td&gt;既知のボットパターンを自動検出&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;第2層&lt;&#x2F;td&gt;&lt;td&gt;WAF カスタムルール&lt;&#x2F;td&gt;&lt;td&gt;不正なパス・不要なパスを遮断&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;第3層&lt;&#x2F;td&gt;&lt;td&gt;Rate Limiting&lt;&#x2F;td&gt;&lt;td&gt;過剰なリクエストを制限&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;いずれもCloudflareの無料プランで利用でき、設定はダッシュボードからの操作だけで完結します。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;まとめ&quot;&gt;まとめ&lt;&#x2F;h2&gt;
&lt;p&gt;これらの設定を適用した直後から、Observability上でスキャン系のリクエストがブロックされていることを確認できました。Workers AIのNeuronsが無駄に消費されることもなくなっています。&lt;&#x2F;p&gt;
&lt;p&gt;個人サイトであっても、公開すればスキャンボットは来ます。「小規模だから狙われない」ということはありません。ボットは規模を問わず、見つけたエンドポイントを片っ端から叩きます。&lt;&#x2F;p&gt;
&lt;p&gt;Cloudflareを使っているなら、無料プランの範囲でもBot Fight Mode、WAFカスタムルール、Rate Limitingの3つを設定するだけで、大半の自動化されたスキャンは防げます。設定にかかる時間は10分程度です。特にWorkers AIやAPIエンドポイントを公開している場合は、不要なリクエストによるリソース消費を防ぐためにも早めの対策をおすすめします。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;References&quot;&gt;References&lt;&#x2F;h2&gt;
&lt;!-- textlint-disable --&gt;
&lt;div class=&quot;references&quot;&gt;
    &lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;developers.cloudflare.com&#x2F;bots&#x2F;get-started&#x2F;free&#x2F;&quot;&gt;Cloudflare&lt;&#x2F;a&gt;. &quot;Bot Fight Mode&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;developers.cloudflare.com&#x2F;waf&#x2F;custom-rules&#x2F;&quot;&gt;Cloudflare&lt;&#x2F;a&gt;. &quot;Custom rules&quot;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;developers.cloudflare.com&#x2F;waf&#x2F;rate-limiting-rules&#x2F;&quot;&gt;Cloudflare&lt;&#x2F;a&gt;. &quot;Rate limiting rules&quot;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;

&lt;&#x2F;div&gt;
&lt;!-- textlint-enable --&gt;
</content>
        <summary type="html">個人ブログにAI Chat機能を追加した翌日、スキャンボットの集中アクセスを確認しました。Cloudflareの無料プランだけで実施できるBot Fight Mode、WAFカスタムルール、Rate Limitingの3つの対策を紹介します。</summary>
        </entry><entry xml:lang="en">
        <title>SPFのDNSルックアップ上限10回、あなたの組織は大丈夫？</title>
        <published>2026-03-03T00:00:00+00:00</published>
        <updated>2026-03-03T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2026/03/spf-lookup-limit-risk/" type="text/html"/>
        <id>https://codedchords.dev/blog/2026/03/spf-lookup-limit-risk/</id>
        
            <content type="html">&lt;!-- textlint-disable --&gt;
&lt;p&gt;&lt;img
  src=&quot;https:&amp;#x2F;&amp;#x2F;codedchords.dev&amp;#x2F;blog&amp;#x2F;2026&amp;#x2F;03&amp;#x2F;spf-lookup-limit-risk&amp;#x2F;cover.webp?h=bc1f2cf07dfaabe490a7&quot;
  alt=&quot;Cover&quot; width=&quot;1792&quot; height=&quot;1024&quot; loading=&quot;lazy&quot;
&#x2F;&gt;
&lt;div class=&quot;admonition info&quot;&gt;
    &lt;div class=&quot;admonition-icon admonition-icon-info&quot;&gt;&lt;&#x2F;div&gt;
    &lt;div class=&quot;admonition-content&quot;&gt;
        &lt;strong class=&quot;admonition-title&quot;&gt;転載元&lt;&#x2F;strong&gt;
        &lt;p&gt;この記事は &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;zenn.dev&#x2F;yostos&#x2F;articles&#x2F;spf-lookup-limit-risk&quot;&gt;Zenn&lt;&#x2F;a&gt; に掲載した記事の転載です。&lt;&#x2F;p&gt;

    &lt;&#x2F;div&gt;
&lt;&#x2F;div&gt;
&lt;&#x2F;p&gt;
&lt;!-- textlint-enable --&gt;
&lt;details&gt;
&lt;summary&gt;Table of Contents&lt;&#x2F;summary&gt;
&lt;!-- toc --&gt;
&lt;&#x2F;details&gt;
&lt;h2 id=&quot;はじめに&quot;&gt;はじめに&lt;&#x2F;h2&gt;
&lt;p&gt;「ある日突然、自組織からのメールが取引先に届かなくなった」——そんな事態が、メール配信サービスを複数利用している組織で実際に起こり得ます。原因は、SPF（Sender Policy Framework）のDNSルックアップ上限です。&lt;&#x2F;p&gt;
&lt;p&gt;外部のメール配信サービスを導入するたびにSPFレコードへ &lt;code&gt;include&lt;&#x2F;code&gt; を追加していくと、気づかないうちに上限へ近づきます。しかも、上限超過のトリガーは自組織の操作ではなく、外部サービス側の設定変更かもしれません。&lt;&#x2F;p&gt;
&lt;p&gt;本記事では、SPFのDNSルックアップ上限の仕組みを解説し、上限超過のリスクと対策を整理します。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;SPFの仕組みとDNSルックアップ上限&quot;&gt;SPFの仕組みとDNSルックアップ上限&lt;&#x2F;h2&gt;
&lt;p&gt;SPFは、メールの送信元ドメインが「どのサーバーからの送信を許可しているか」をDNSのTXTレコードで宣言する仕組みです。受信側メールサーバーは、送信元IPアドレスがSPFレコードに含まれているかを検証し、正当な送信元かどうかを判断します。&lt;&#x2F;p&gt;
&lt;p&gt;SPFレコードの例を示します。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;v=spf1 ip4:192.0.2.0&#x2F;24 include:spf.example.com ~all&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;この例では、&lt;code&gt;192.0.2.0&#x2F;24&lt;&#x2F;code&gt; のIPレンジからの送信と、&lt;code&gt;spf.example.com&lt;&#x2F;code&gt; が許可する送信元を正当とみなします。&lt;&#x2F;p&gt;
&lt;p&gt;SPFの検証は受信側メールサーバーで行われます。メールを受け取ったサーバーが送信元ドメインのSPFレコードをDNSに問い合わせ、送信元IPが許可されているかを確認します。この検証過程でDNSルックアップが発生しますが、RFC 7208（Section 4.6.4）により、1回のSPF検証で実行できるDNSルックアップは最大10回と制限されています。この制限は、SPF検証によるDNSサーバーへの負荷を防ぐために設けられたものです。&lt;&#x2F;p&gt;
&lt;p&gt;すべてのメカニズムがDNSルックアップを消費するわけではありません。消費するメカニズムとしないメカニズムを表にまとめます。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;メカニズム &#x2F; 修飾子&lt;&#x2F;th&gt;&lt;th&gt;DNSルックアップ&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;ip4&lt;&#x2F;code&gt; &#x2F; &lt;code&gt;ip6&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;0回（IP直接指定のためDNS不要）&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;a&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;1回&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;mx&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;1回（＋MXレコードが指すAレコードの解決）&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;include&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;1回 ＋ 参照先のSPFレコード内のルックアップ&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;redirect&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;1回&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;exists&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;1回&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;重要なのは &lt;code&gt;include&lt;&#x2F;code&gt; の挙動です。&lt;code&gt;include&lt;&#x2F;code&gt; は参照先のSPFレコードをさらに評価するため、参照先に &lt;code&gt;include&lt;&#x2F;code&gt; や &lt;code&gt;a&lt;&#x2F;code&gt; が含まれていれば、それらも合算されます。つまり、1つの &lt;code&gt;include&lt;&#x2F;code&gt; が実際には複数回のルックアップを消費する場合があります。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;includeの入れ子で上限に近づく実例&quot;&gt;includeの入れ子で上限に近づく実例&lt;&#x2F;h2&gt;
&lt;p&gt;架空の組織 &lt;code&gt;example.or.jp&lt;&#x2F;code&gt; を例に考えます。この組織では業務メールに加えて、メールマガジン配信に3つの外部サービスを利用しています。SPFレコードは以下のようになっています。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;v=spf1 ip4:192.0.2.0&#x2F;29 ip4:198.51.100.1 include:spf.mail-a.example include:spf.mail-b.example include:spf.mail-c.example include:spf.bizmail.example ~all&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;各エントリのDNSルックアップ数を確認します。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;エントリ&lt;&#x2F;th&gt;&lt;th&gt;DNSルックアップ&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;ip4:192.0.2.0&#x2F;29&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;0回（IP直接指定）&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;ip4:198.51.100.1&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;0回（IP直接指定）&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;include:spf.mail-a.example&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;1回&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;include:spf.mail-b.example&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;1回 ＋ 内部で3回 = 4回&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;include:spf.mail-c.example&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;1回&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;code&gt;include:spf.bizmail.example&lt;&#x2F;code&gt;&lt;&#x2F;td&gt;&lt;td&gt;1回&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;strong&gt;合計&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;td&gt;&lt;strong&gt;7回 &#x2F; 上限10回&lt;&#x2F;strong&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;一見すると余裕がありそうですが、問題は &lt;code&gt;spf.mail-b.example&lt;&#x2F;code&gt; の内部構造です。このSPFレコードは以下のようになっています。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;v=spf1 exists:%{i}.spf.mail-b1.example exists:%{i}.spf.mail-b2.example include:spf.mail-b3.example ~all&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;&lt;code&gt;include&lt;&#x2F;code&gt; 1つで4回のルックアップを消費しています。そして、この内訳は外部サービス側の設定に依存しています。&lt;&#x2F;p&gt;
&lt;p&gt;ここに大きなリスクがあります。外部サービスがインフラ変更に伴いSPFレコードへ &lt;code&gt;include&lt;&#x2F;code&gt; や &lt;code&gt;a&lt;&#x2F;code&gt; を追加すれば、自組織が何も変更していなくてもルックアップ数が増加します。たとえば &lt;code&gt;spf.mail-b.example&lt;&#x2F;code&gt; が内部で1つ &lt;code&gt;include&lt;&#x2F;code&gt; を追加するだけで、合計は8回になり、上限までわずか2回です。さらに別のサービスも同様の変更をすれば、上限を超えてしまいます。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;上限を超えるとどうなるか&quot;&gt;上限を超えるとどうなるか&lt;&#x2F;h2&gt;
&lt;p&gt;SPFのルックアップ数が10回を超えると、SPFの検証結果は &lt;code&gt;permerror&lt;&#x2F;code&gt;（恒久的エラー）になります。これは「SPFレコードが壊れている」とみなされる状態です。&lt;&#x2F;p&gt;
&lt;p&gt;&lt;code&gt;permerror&lt;&#x2F;code&gt; が発生すると、受信側メールサーバーの設定に応じて以下のいずれかが起こります。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;メールが拒否される（バウンス）&lt;&#x2F;li&gt;
&lt;li&gt;迷惑メールフォルダに振り分けられる&lt;&#x2F;li&gt;
&lt;li&gt;DMARCのSPF判定がfailとなり、DMARCポリシー次第でメールが拒否される&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;特に厄介なのは、この問題が自組織側からは気づきにくい点です。送信自体は正常に行われ、送信者にはエラーが返らない場合もあります。受信側で静かにスパム判定されるため、「最近メールの返信が来ない」「メルマガの開封率が急落した」といった間接的な兆候で初めて気づくことになります。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;自分のドメインのルックアップ数を確認する方法&quot;&gt;自分のドメインのルックアップ数を確認する方法&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;code&gt;dig&lt;&#x2F;code&gt; コマンドでSPFレコードの内容を確認できます。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;dig&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; +short TXT example.or.jp&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; grep&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; spf&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;表示されたSPFレコードに含まれる &lt;code&gt;include&lt;&#x2F;code&gt; 先も再帰的に確認する必要があります。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;dig&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; +short TXT spf.mail-b.example&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;手動での再帰的な確認は手間がかかるため、オンラインツールの利用も有効です。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MXToolbox SPF Record Lookup&lt;&#x2F;strong&gt; — SPFレコードの内容とDNSルックアップ数を自動計算してくれる&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;dmarcian SPF Surveyor&lt;&#x2F;strong&gt; — SPFレコードの構造をツリー表示で可視化できる&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;これらのツールにドメイン名を入力するだけで、現在のルックアップ数と上限までの余裕を確認できます。定期的にチェックしておくことをお勧めします。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;対策&quot;&gt;対策&lt;&#x2F;h2&gt;
&lt;p&gt;SPFルックアップ上限の問題に対して、短期的な対策と中長期的な対策があります。&lt;&#x2F;p&gt;
&lt;p&gt;まず短期的な対策として、メール送信経路を棚卸しします。SPFレコードに登録されている &lt;code&gt;include&lt;&#x2F;code&gt; やIPアドレスが、現在も使われているかを確認します。利用を終了したサービスの &lt;code&gt;include&lt;&#x2F;code&gt; が残っていると、ルックアップ数を無駄に消費するだけでなく、そのサービスのIPレンジが自ドメインの正当な送信元として許可されたままになります。これはなりすましに悪用されるリスクでもあります。&lt;&#x2F;p&gt;
&lt;p&gt;次に、メール配信サービスの統合を検討します。メルマガ配信に複数のサービスを併用している場合、1つに統合すれば &lt;code&gt;include&lt;&#x2F;code&gt; の数を減らせます。配信実績の分析も一元化でき、コスト管理も簡素化されます。&lt;&#x2F;p&gt;
&lt;p&gt;これらの根本対策とは別に、技術的な回避策も存在します&lt;sup class=&quot;footnote-reference&quot; id=&quot;fr-spf-workaround-1&quot;&gt;&lt;a href=&quot;#fn-spf-workaround&quot;&gt;1&lt;&#x2F;a&gt;&lt;&#x2F;sup&gt;。ただし運用上の注意点があるため、まずは送信経路の整理を優先すべきです。&lt;&#x2F;p&gt;
&lt;p&gt;最後に、中長期的な対策としてDMARCポリシーの段階的強化があります。DMARCはSPFとDKIMの認証結果に基づいて、認証失敗時のメール処理方針を宣言する仕組みです。ポリシーは以下の順で強化します。&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;code&gt;p=none&lt;&#x2F;code&gt;（監視モード）でDMARCレポートを収集し、全送信経路の認証状況を把握する&lt;&#x2F;li&gt;
&lt;li&gt;全経路でSPF・DKIMがpassすることを確認したうえで &lt;code&gt;p=quarantine&lt;&#x2F;code&gt;（隔離）に移行する&lt;&#x2F;li&gt;
&lt;li&gt;一定期間の監視後、問題がなければ &lt;code&gt;p=reject&lt;&#x2F;code&gt;（拒否）に移行する&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;p&gt;送信経路が整理されていれば、この移行は技術的には難しくありません。逆に、送信経路が乱立したままでは各経路の認証状況を把握すること自体が困難であり、DMARC強化は事実上不可能です。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;まとめ&quot;&gt;まとめ&lt;&#x2F;h2&gt;
&lt;p&gt;SPFのDNSルックアップ上限10回は、メール配信サービスを複数利用する組織にとって見落とされがちなリスクです。外部サービスの &lt;code&gt;include&lt;&#x2F;code&gt; は入れ子構造でルックアップ数が膨らみ、しかも外部サービス側の変更で自組織のルックアップ数が増加するという、制御しにくい特性があります。&lt;&#x2F;p&gt;
&lt;p&gt;まずは自分のドメインの現在のルックアップ数を確認してみてください。上限に近づいている場合は、不要な &lt;code&gt;include&lt;&#x2F;code&gt; の削除やサービスの統合を検討し、DMARCポリシーの強化と合わせてメール配信の信頼性を確保していくことが重要です。&lt;&#x2F;p&gt;
&lt;section class=&quot;footnotes&quot;&gt;
&lt;ol class=&quot;footnotes-list&quot;&gt;
&lt;li id=&quot;fn-spf-workaround&quot;&gt;
&lt;p&gt;技術的な回避策としてSPF MacroとSPF flatteningがあります。SPF Macroは &lt;code&gt;exists&lt;&#x2F;code&gt; メカニズムと変数を組み合わせてルックアップ数を抑える手法です。SPF flatteningは &lt;code&gt;include&lt;&#x2F;code&gt; 先のIPアドレスを直接 &lt;code&gt;ip4&lt;&#x2F;code&gt; &#x2F; &lt;code&gt;ip6&lt;&#x2F;code&gt; で記述してルックアップを削減する手法です。ただしflatteningは参照先のIPが変更されたときに追従が必要なため、自動化ツールなしでの運用は推奨しません。 &lt;a href=&quot;#fr-spf-workaround-1&quot;&gt;↩&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;&#x2F;section&gt;
</content>
        <summary type="html">SPFにはDNSルックアップ上限10回の制約があり、外部メール配信サービスのincludeが入れ子で膨らむと意図せず超過するリスクがあります。上限超過の仕組みと確認方法、対策を解説します。</summary>
        </entry><entry xml:lang="en">
        <title>Cloudflare無料プランだけで個人サイトのセキュリティが完結した話</title>
        <published>2026-02-20T00:00:00+00:00</published>
        <updated>2026-02-20T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2026/02/cloudflare-benefits/" type="text/html"/>
        <id>https://codedchords.dev/blog/2026/02/cloudflare-benefits/</id>
        
            <content type="html">&lt;!-- textlint-disable --&gt;
&lt;img
  src=&quot;https:&amp;#x2F;&amp;#x2F;codedchords.dev&amp;#x2F;blog&amp;#x2F;2026&amp;#x2F;02&amp;#x2F;cloudflare-benefits&amp;#x2F;cover.webp?h=a800061cf7b938db4dbe&quot;
  alt=&quot;Cover&quot; width=&quot;1792&quot; height=&quot;1024&quot; loading=&quot;lazy&quot;
&#x2F;&gt;&lt;h2 id=&quot;TL;DR&quot;&gt;TL;DR&lt;&#x2F;h2&gt;
&lt;p&gt;Cloudflareのアドバンテージは、次の3点です。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;無料プランだけでWAF・ボット対策まで揃う、セキュリティの充実度&lt;&#x2F;li&gt;
&lt;li&gt;DNS統合だからこそ、煩雑でリスクの高い設定をワンクリックで実現&lt;&#x2F;li&gt;
&lt;li&gt;AIクローラー対策やページ先読みなど、最新トレンドへの即応&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;hr &#x2F;&gt;
&lt;p&gt;つい3日前に&lt;a href=&quot;https:&#x2F;&#x2F;codedchords.dev&#x2F;blog&#x2F;2026&#x2F;02&#x2F;migration-to-cloudflare&#x2F;&quot;&gt;Cloudflareへ移転した&lt;&#x2F;a&gt;ばかりです。構成はシンプルで、Cloudflareでドメインを取得し、GitHubリポジトリと連携して静的コンテンツをCloudflare Pages&lt;sup class=&quot;footnote-reference&quot; id=&quot;fr-2-1&quot;&gt;&lt;a href=&quot;#fn-2&quot;&gt;1&lt;&#x2F;a&gt;&lt;&#x2F;sup&gt;へデプロイしています。この構成だけでも思いの外多くの恩恵が得られたので、まとめておきます。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Cloudflareでの設定&quot;&gt;Cloudflareでの設定&lt;&#x2F;h2&gt;
&lt;p&gt;Cloudflareのダッシュボードで有効にした機能を、カテゴリごとに紹介します。いずれも無料プランで利用でき、ほとんどがトグルひとつで有効にできるものです。なお、本記事の機能名やβ表記は2026年2月時点のCloudflare管理画面のUIに基づいています。&lt;&#x2F;p&gt;
&lt;h3 id=&quot;Edge_Certificates&quot;&gt;Edge Certificates&lt;&#x2F;h3&gt;
&lt;p&gt;Cloudflareが発行・管理するSSL&#x2F;TLS証明書と、HTTPS通信に関する設定です。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;項目&lt;&#x2F;th&gt;&lt;th&gt;説明&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Always Use HTTPS&lt;&#x2F;td&gt;&lt;td&gt;HTTP でアクセスが来た場合に自動的に HTTPS へ301リダイレクトしてくれるので、暗号化されていない通信を防げる。&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;HSTS&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;.dev&lt;&#x2F;code&gt; ドメイン&lt;sup class=&quot;footnote-reference&quot; id=&quot;fr-1-1&quot;&gt;&lt;a href=&quot;#fn-1&quot;&gt;2&lt;&#x2F;a&gt;&lt;&#x2F;sup&gt;を使用しているので私の場合あまり恩恵がないが、ブラウザレベルでHTTPSが強制できる。&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Minimum TLS Version&lt;&#x2F;td&gt;&lt;td&gt;サイトに接続する際に許可するTLSプロトコルの最低バージョンの指定。TLS 1.0 と 1.1 は既知の脆弱性があるので、私はTLS1.2にしている。&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Opportunistic Encryption&lt;&#x2F;td&gt;&lt;td&gt;HTTPでアクセスしてきたブラウザに対して「暗号化接続も利用可能ですよ」と通知する仕組み。&lt;code&gt;.dev&lt;&#x2F;code&gt; の場合、HTTPアクセスが発生しないので実質的に意味がない。&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;TLS 1.3&lt;&#x2F;td&gt;&lt;td&gt;Minimum TLS Version を 1.2 に設定し、この TLS 1.3 をオンにしておけば、「最低 1.2、対応していれば 1.3 を使う」という構成になる。&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Automatic HTTPS Rewrites&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;http:&#x2F;&#x2F;&lt;&#x2F;code&gt; をCloudflare が自動的に &lt;code&gt;https:&#x2F;&#x2F;&lt;&#x2F;code&gt; に書き換えて「混在コンテンツ（mixed content）」の問題を防いでくれる。&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Certificate Transparency Monitoring&lt;&#x2F;td&gt;&lt;td&gt;自分が意図していない証明書が第三者によって発行された場合（ドメインの不正利用や乗っ取りの兆候）通知してくれる&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;h3 id=&quot;Security&quot;&gt;Security&lt;&#x2F;h3&gt;
&lt;p&gt;ボット対策、DDoS防御、WAFなど、サイトを外部の脅威から守るための設定です。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;項目&lt;&#x2F;th&gt;&lt;th&gt;説明&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;AI Labyrinth&lt;&#x2F;td&gt;&lt;td&gt;まだβ機能だが、robots.txt 等のクロールルールを無視して勝手にサイトをスクレイピングするボットに対して偽コンテンツを読ませて学習データを汚染させるという「ハニーポット」的な機能&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Block AI bots&lt;&#x2F;td&gt;&lt;td&gt;AI学習用クローラーをブロックする機能&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Bot fight mode&lt;&#x2F;td&gt;&lt;td&gt;悪意のあるボット（スパム、クレデンシャルスタッフィング、DDoS等）を検知すると、JavaScriptチャレンジを出して人間かどうかを確認する&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Browser Integrity Check&lt;&#x2F;td&gt;&lt;td&gt;訪問者のHTTPヘッダーを検査して、不正なUser-Agentやスパムボットによく見られる異常なヘッダーパターンを検出し、脅威が見つかった場合はブロックページを表示する。&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Challenge passage&lt;&#x2F;td&gt;&lt;td&gt;チャレンジ（CAPTCHA等）をクリアした訪問者が、再度チャレンジを求められるまでの有効時間&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;HTTP DDoS attack protection&lt;&#x2F;td&gt;&lt;td&gt;HTTPレイヤーのDDoS攻撃を自動検知・緩和する。無料プランでもCloudflare Free Managed Ruleset（基本的なWAFルール）が付属する&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Manage your robots.txt&lt;&#x2F;td&gt;&lt;td&gt;Cloudflare が robots.txt を自動管理するβ機能。Content Signals Policyを選択すると、コンテンツの利用意図を用途別（検索・AI入力・AI学習）に宣言できる&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Network-layer DDoS attack protection&lt;&#x2F;td&gt;&lt;td&gt;DDoS保護&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;h3 id=&quot;DNS&quot;&gt;DNS&lt;&#x2F;h3&gt;
&lt;p&gt;DNS応答の改ざん防止やメールのなりすまし対策など、ドメインの信頼性を高める設定です。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;項目&lt;&#x2F;th&gt;&lt;th&gt;説明&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;DNSSEC&lt;&#x2F;td&gt;&lt;td&gt;DNSレスポンスに暗号署名を付与して、DNS応答の偽造（DNSキャッシュポイズニング等）を防ぐ&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Email Security&lt;&#x2F;td&gt;&lt;td&gt;有効にしてDMARCの設定。メール送信の予定はないので、SPFは&quot;v=spf1 -all&quot;で設定。DMARCは&quot;v=DMARC1; p=reject&quot;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;h3 id=&quot;Speed&quot;&gt;Speed&lt;&#x2F;h3&gt;
&lt;p&gt;通信プロトコルの最適化やページ先読みなど、サイト表示を高速化するための設定です。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;項目&lt;&#x2F;th&gt;&lt;th&gt;説明&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Web analytics using real user measurement (RUM)&lt;&#x2F;td&gt;&lt;td&gt;実際の訪問者のブラウザからパフォーマンスデータ（ページ読み込み時間など）を収集する。Cookieを使わないプライバシー重視の計測方式&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Speed Brain&lt;&#x2F;td&gt;&lt;td&gt;ユーザーがリンクをクリックする前にページを先読みする機能。Speculation Rules API を使い、体感的なページ遷移が高速になる&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;HTTP&#x2F;2&lt;&#x2F;td&gt;&lt;td&gt;HTTP&#x2F;1.1の後継。1つの接続で複数リクエストを並行処理（多重化）でき、ページ読み込みが高速になる&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;HTTP&#x2F;3&lt;&#x2F;td&gt;&lt;td&gt;HTTP&#x2F;2の次世代版。TCPの代わりにQUICプロトコルを使い、接続確立が高速でパケットロス時の劣化も少ない&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;HTTP&#x2F;2 to Origin&lt;&#x2F;td&gt;&lt;td&gt;Cloudflareとオリジンサーバー間の通信にもHTTP&#x2F;2を使う設定&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;0-RTT Connection Resumption&lt;&#x2F;td&gt;&lt;td&gt;TLS 1.3で接続済みのクライアントが再訪問時にハンドシェイクの最初の往復を省略でき、再訪問者の初回リクエストが速くなる&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;h2 id=&quot;以前のプラットフォームとの比較&quot;&gt;以前のプラットフォームとの比較&lt;&#x2F;h2&gt;
&lt;p&gt;昨年までAmazon Amplify、先月までGitHub Pagesで運用していました。
上記で挙げたCloudflareの機能が、それぞれの環境ではどうだったかを比較してみます。特にセキュリティ列の差に注目してください。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;○: 標準&#x2F;無料で利用可能&lt;&#x2F;li&gt;
&lt;li&gt;△: 別途設定や追加費用で対応可能&lt;&#x2F;li&gt;
&lt;li&gt;×: 非対応&lt;&#x2F;li&gt;
&lt;li&gt;−: 該当なし&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;機能&lt;&#x2F;th&gt;&lt;th style=&quot;text-align: center&quot;&gt;Amplify + CloudFront&lt;&#x2F;th&gt;&lt;th style=&quot;text-align: center&quot;&gt;GitHub Pages&lt;&#x2F;th&gt;&lt;th&gt;コメント&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Always Use HTTPS&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○&lt;&#x2F;td&gt;&lt;td&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;HSTS&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;△（手動設定）&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○&lt;&#x2F;td&gt;&lt;td&gt;AWSだけ手動設定の手間がかかる&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Minimum TLS Version&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;GitHub Pagesは古いTLSを拒否できず、セキュリティポリシーを徹底しにくい&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Opportunistic Encryption&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;HTTP接続の暗号化への誘導は他のサービスでは提供されていない&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;TLS 1.3&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○&lt;&#x2F;td&gt;&lt;td&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Automatic HTTPS Rewrites&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;他では混在コンテンツを自分で探して直す必要がある&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Certificate Transparency Monitoring&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;△（ACMの一部）&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;不正な証明書発行の早期発見に差が出る&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;AI Labyrinth&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;ワンクリックでAIスクレイピングに対抗できる機能は他にない&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Block AI bots&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;△（WAFルールで対応）&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;AWSは自前でルールを書く手間とWAF費用がかかる&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Bot fight mode&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;△（WAF Bot Control有料）&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;AWSで同等機能を得るにはBot Control（月額$10〜＋リクエスト従量課金）が必要&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Browser Integrity Check&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;△（WAFで部分的）&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;AWSでは同等ルールの自作が必要で、運用負荷が高い&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Challenge passage&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;△（WAF）&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;Cloudflareはチャレンジの有効期間まで細かく制御できる&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;HTTP DDoS attack protection&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;△（WAFは有料）&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;無料でWAFまで付くのはCloudflareの大きな強み&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Manage your robots.txt&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;増え続けるAIクローラーへの対応を自動化できる機能は他にない&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Network-layer DDoS attack protection&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○（Shield Standard）&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○&lt;&#x2F;td&gt;&lt;td&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;DNSSEC&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○（Route 53）&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;△（DNS providerに依存）&lt;&#x2F;td&gt;&lt;td&gt;Cloudflareはワンクリック、DNS一体管理なので設定が圧倒的に楽&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Email Security&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○（Route 53）&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;△（DNS providerに依存）&lt;&#x2F;td&gt;&lt;td&gt;同上。DNS管理とセットなのでSPF&#x2F;DMARCの設定も迷わない&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Web analytics (RUM)&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;△（CloudWatch RUM有料）&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;Cloudflareは追加費用なしでCookie不要の計測が使える&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Speed Brain&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;ページ先読みによる体感速度向上は他のサービスでは提供されていない&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;HTTP&#x2F;2&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○&lt;&#x2F;td&gt;&lt;td&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;HTTP&#x2F;3&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;GitHub Pagesは2026年2月時点でHTTP&#x2F;3未サポート&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;HTTP&#x2F;2 to Origin&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;○&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;−&lt;&#x2F;td&gt;&lt;td&gt;オリジンサーバーがある構成でのみ意味がある&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;0-RTT&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td style=&quot;text-align: center&quot;&gt;×&lt;&#x2F;td&gt;&lt;td&gt;再訪問時の体感速度に差が出る。他のサービスでは無料で提供されていない&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;h2 id=&quot;AI時代のコンテンツ保護&quot;&gt;AI時代のコンテンツ保護&lt;&#x2F;h2&gt;
&lt;p&gt;Cloudflareの無料プランには、AIクローラーに対応する機能が複数用意されています。これらは独立した機能ですが、組み合わせると多層的な防御になります。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;機能&lt;&#x2F;th&gt;&lt;th&gt;レイヤー&lt;&#x2F;th&gt;&lt;th&gt;役割&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Content Signals Policy&lt;&#x2F;td&gt;&lt;td&gt;意思表示&lt;&#x2F;td&gt;&lt;td&gt;robots.txt内でコンテンツの用途別に許可&#x2F;拒否を宣言する。強制力はなく、善意あるクローラーへの「お願い」&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Block AI bots&lt;&#x2F;td&gt;&lt;td&gt;技術的ブロック&lt;&#x2F;td&gt;&lt;td&gt;Cloudflareが「AI学習用」と分類するクローラーをWAFレベルでブロックする。検索エンジンやAIアシスタントは対象外&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;AI Labyrinth&lt;&#x2F;td&gt;&lt;td&gt;欺瞞防御&lt;&#x2F;td&gt;&lt;td&gt;ブロックを無視するクローラーに偽コンテンツを読ませ、学習データを汚染させるハニーポット&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;ポイントは、Content Signals PolicyとBlock AI botsの役割分担です。Content Signals Policyでは &lt;code&gt;search=yes, ai-input=yes, ai-train=no&lt;&#x2F;code&gt; のように宣言し、「検索やAI回答での引用はOKだが、モデルの学習には使うな」という意思を伝えます。しかし宣言はあくまで「お願い」なので、AI学習用クローラーに対してはBlock AI botsがWAFレベルで実際にアクセスを遮断します。それでもすり抜けてくるクローラーにはAI Labyrinthが偽データを食わせます。&lt;&#x2F;p&gt;
&lt;p&gt;さらに、AI Crawl ControlのCrawlersタブではクローラーごとに個別のAllow&#x2F;Blockを設定できます。たとえば「ChatGPT-Userは許可するがBytespiderはブロックする」といった細かい制御も可能です。&lt;&#x2F;p&gt;
&lt;p&gt;この多層構成により、AI検索からの流入を確保しつつ学習目的のスクレイピングは拒否するという運用が、無料プランだけで実現できます。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Cloudflareの評価&quot;&gt;Cloudflareの評価&lt;&#x2F;h2&gt;
&lt;p&gt;比較表を振り返ると、Cloudflareの強みは大きく3つあります。&lt;&#x2F;p&gt;
&lt;p&gt;1つ目は、無料プランでのセキュリティの充実度です。AWSで同等のボット対策やWAFを実現しようとすると、AWS WAFやBot Controlの追加費用と自前でのルール作成が必要でした。GitHub Pagesではユーザーが設定できるセキュリティ機能はほとんどありません。Cloudflareでは、AIボットのブロック、Bot fight mode、WAFまで無料プランに含まれており、しかもダッシュボードのトグルひとつで有効にできます。&lt;&#x2F;p&gt;
&lt;p&gt;2つ目は、DNS・証明書・セキュリティ・CDNがひとつのダッシュボードに統合されている点です。AWSではRoute 53、CloudFront、ACM、WAFと複数サービスをまたいで設定する必要がありました。GitHub PagesではDNSが外部依存のため、DNSSECやSPF&#x2F;DMARCの設定は利用するDNSプロバイダ次第でした。Cloudflareではドメイン取得からDNSSEC、メールセキュリティ、デプロイまで一箇所で完結するため、設定の見通しがよく管理も楽です。&lt;&#x2F;p&gt;
&lt;p&gt;3つ目は、他のサービスでは提供されていない独自機能です。前述のとおり、Content Signals PolicyからBlock AI bots、AI Labyrinthまで、AIクローラーへの多層的な対応が無料プランだけで揃います。加えて、Speculation Rules APIを活用したSpeed BrainやTLS 1.3の0-RTT再接続など、パフォーマンス面でも独自の機能が提供されています。特にAIクローラー対策は今後ますます重要になる領域であり、「意思表示」と「技術的ブロック」と「欺瞞防御」を組み合わせた構成がワンクリックで手に入るのは大きな安心感があります。&lt;&#x2F;p&gt;
&lt;p&gt;個人の静的サイトという用途では、Cloudflareの無料プランだけで「やりたいことが全部できる」状態になりました。以前はAWSの複数サービスを組み合わせて実現していたことが、Cloudflareではひとつのダッシュボードで、しかも無料で手に入ります。移行してよかったと素直に思います。&lt;&#x2F;p&gt;
&lt;!-- textlint-enable --&gt;
&lt;section class=&quot;footnotes&quot;&gt;
&lt;ol class=&quot;footnotes-list&quot;&gt;
&lt;li id=&quot;fn-2&quot;&gt;
&lt;p&gt;Cloudflare Pagesは現在、Cloudflare Workersとの&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;pages-and-workers-are-converging-into-one-experience&#x2F;&quot;&gt;統合が進んでいる&lt;&#x2F;a&gt;。将来的にはWorkersの静的アセット機能に一本化される見込みだが、Pages自体も引き続き利用可能。 &lt;a href=&quot;#fr-2-1&quot;&gt;↩&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li id=&quot;fn-1&quot;&gt;
&lt;p&gt;&lt;code&gt;.dev&lt;&#x2F;code&gt; ドメインはGoogleが管理しているTLDで、HSTS Preload ListにTLD単位で登録済みなので最初からHTTPSが強制される。 &lt;a href=&quot;#fr-1-1&quot;&gt;↩&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;&#x2F;section&gt;
</content>
        <summary type="html">Cloudflareの無料プランで利用できるWAF・ボット対策・AIクローラー対策などのセキュリティ機能を、AWS AmplifyやGitHub Pagesと比較しながら紹介します。</summary>
        </entry><entry xml:lang="en">
        <title>Zolaブログを新ドメイン取得 + Cloudflare移転</title>
        <published>2026-02-17T00:00:00+00:00</published>
        <updated>2026-02-17T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2026/02/migration-to-cloudflare/" type="text/html"/>
        <id>https://codedchords.dev/blog/2026/02/migration-to-cloudflare/</id>
        
            <content type="html">&lt;!-- textlint-disable --&gt;
&lt;div class=&quot;admonition note&quot;&gt;
    &lt;div class=&quot;admonition-icon admonition-icon-note&quot;&gt;&lt;&#x2F;div&gt;
    &lt;div class=&quot;admonition-content&quot;&gt;
        &lt;strong class=&quot;admonition-title&quot;&gt;NOTE&lt;&#x2F;strong&gt;
        &lt;p&gt;この記事は
&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;zenn.dev&#x2F;yostos&#x2F;articles&#x2F;migration-to-cloudflare&quot;&gt;Zenn.dev&lt;&#x2F;a&gt;
に掲載した記事の転載です。&lt;&#x2F;p&gt;

    &lt;&#x2F;div&gt;
&lt;&#x2F;div&gt;
&lt;!-- textlint-enable --&gt;
&lt;h2 id=&quot;TL;DR（Zola利用者向け）&quot;&gt;TL;DR（Zola利用者向け）&lt;&#x2F;h2&gt;
&lt;ul&gt;
&lt;li&gt;Cloudflare ProxyとGitHub Pagesの組み合わせでは、Let&#x27;s Encrypt証明書のHTTP-01チャレンジを妨げるリスクがある&lt;&#x2F;li&gt;
&lt;li&gt;Cloudflare PagesのCI&#x2F;CDはv2以降Zolaをサポートしていない（&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;cloudflare&#x2F;pages-build-image&#x2F;issues&#x2F;3&quot;&gt;issue #3&lt;&#x2F;a&gt;は2023年からOpen）。GitHub Actions + &lt;code&gt;wrangler deploy&lt;&#x2F;code&gt;で代替可能&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h2 id=&quot;はじめに&quot;&gt;はじめに&lt;&#x2F;h2&gt;
&lt;p&gt;以前、Amazon Amplify + Next.js + Tailwind CSSで運用していたブログをGitHub Pages + Zolaに移行しました。GitHub Pagesはシンプルで運用コストが低い一方、カスタムHTTPレスポンスヘッダーを設定できないという制約があります。&lt;a href=&quot;https:&#x2F;&#x2F;codedchords.dev&#x2F;blog&#x2F;2026&#x2F;02&#x2F;github-pages-security-headers&#x2F;&quot;&gt;以前の記事&lt;&#x2F;a&gt;でも書きましたが、セキュリティスキャナーで警告が出る状態をずっと気にしていました。&lt;&#x2F;p&gt;
&lt;p&gt;では、Cloudflareに持っていくかと移転をはじめたところ、いくつかひっかかりポイントがあったので共有します。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;新ドメインの取得&quot;&gt;新ドメインの取得&lt;&#x2F;h2&gt;
&lt;p&gt;移転にあたり、新ドメイン&lt;code&gt;codedchords.dev&lt;&#x2F;code&gt;を取得しました。旧ドメインから変更した理由は2つあります。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Cloudflareの無料プランではDNSをCloudflareに移管する必要がある。旧ドメインはFastMailでメール運用しておりDNSもFastMailに移管済みのため、Cloudflareへの再移管が難しい&lt;&#x2F;li&gt;
&lt;li&gt;旧ドメインは長年の運用とブログ改築の結果、404でインデックスされないページが多数あり、これを機に一新してもよい&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;TLDは&lt;code&gt;.dev&lt;&#x2F;code&gt;を選びました。&lt;code&gt;.dev&lt;&#x2F;code&gt;はGoogleが管理するTLDで、HSTSプリロードリストに登録されています。ブラウザレベルでHTTPS接続が強制されるため、セキュリティ面で最初から一段高い状態が保証されます。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Cloudflare_Workers_への移行&quot;&gt;Cloudflare Workers への移行&lt;&#x2F;h2&gt;
&lt;p&gt;セキュリティヘッダーを設定するために、Cloudflareを利用する方針で検討を進めました。最終的にCloudflare Workersの静的アセット機能に落ち着くまでに、2つのアプローチで挫折しています。&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;案1: Cloudflare Proxy + Transform Rules（断念）&lt;&#x2F;strong&gt;。最初に検討したのは、CloudflareのProxyを有効にしてTransform Rulesでレスポンスヘッダーを追加する方法です。GitHub Pagesをオリジンとし、Cloudflareを前段に配置する構成です。しかし、GitHub PagesのLet&#x27;s Encrypt証明書は90日ごとにHTTP-01チャレンジで自動更新されます。Cloudflare Proxyが間に入るとチャレンジがGitHubへ届かず、更新が静かに失敗する可能性があります。証明書の期限切れでサイトが突然表示不能になるリスクがあり、静的ブログで証明書を定期監視するのは割に合いません。この案は見送りました。&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;案2: Cloudflare Pages CI&#x2F;CD（断念）&lt;&#x2F;strong&gt;。次に、Cloudflare PagesのCI&#x2F;CDでZolaをビルドしてそのままホスティングする方法を試みました。しかし、Cloudflare Pagesのv2ビルドシステムではZolaがサポート対象から外れており、ビルドが通りません。この問題は&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;cloudflare&#x2F;pages-build-image&#x2F;issues&#x2F;3&quot;&gt;GitHubのissue&lt;&#x2F;a&gt;で2023年から報告されていますが、2026年2月現在もOpenのままです。リポジトリにZolaバイナリを同梱するワークアラウンドも提案されていますが、スマートとは言えないためこの案も断念しました。&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;案3: Cloudflare Workers 静的アセット（採用）&lt;&#x2F;strong&gt;。最終的に採用したのが、Cloudflare Workersの静的アセット機能です。CloudflareはWorkersとPagesを統合する方針で、今後の機能開発はWorkersに集中されます。Workersの静的アセット機能は&lt;code&gt;_headers&lt;&#x2F;code&gt;ファイルをネイティブにサポートしており、セキュリティヘッダーの設定が可能です。SSL証明書もCloudflareが一元管理するため更新の問題は発生しません。ビルドはGitHub Actionsで行い、&lt;code&gt;wrangler deploy&lt;&#x2F;code&gt;でデプロイする構成にしました。Zolaのバージョンも自分で管理できます。&lt;&#x2F;p&gt;
&lt;p&gt;移行手順は以下のとおりです。&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;Cloudflare DashboardのWorkers &amp;amp; Pagesから「Upload your static files」でプロジェクトを作成。後で上書きされるので適当なファイルを1つアップロードするだけでよい&lt;&#x2F;li&gt;
&lt;li&gt;既存のGitHub Actionsワークフロー（&lt;code&gt;deploy.yml&lt;&#x2F;code&gt;）を修正。Zolaのビルド部分はそのまま流用し、デプロイ先をCloudflare Workersに変更する。リポジトリに&lt;code&gt;wrangler.toml&lt;&#x2F;code&gt;を追加し、GitHub Repository SecretsにCloudflareのアカウントIDとAPIトークンを登録&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;yaml&quot; data-name=&quot;deploy.yml&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;name&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; Deploy to Cloudflare Workers&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-constant z-language z-boolean&quot;&gt;on&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;  push&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;    branches&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation&quot;&gt;      -&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; main&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;  workflow_dispatch&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;permissions&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;  contents&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; read&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;concurrency&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;  group&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;deploy&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;  cancel-in-progress&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-language z-boolean&quot;&gt; false&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;jobs&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;  deploy&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;    runs-on&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; ubuntu-latest&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;    steps&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation&quot;&gt;      -&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt; name&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; Checkout&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;        uses&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; actions&#x2F;checkout@v4&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;        with&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;          submodules&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; recursive&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation&quot;&gt;      -&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt; name&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; Setup Zola&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;        uses&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; taiki-e&#x2F;install-action@v2&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;        with&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;          tool&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; zola@0.22.1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation&quot;&gt;      -&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt; name&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; Build&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;        run&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; zola build&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation&quot;&gt;      -&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt; name&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; Deploy to Cloudflare&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;        uses&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; cloudflare&#x2F;wrangler-action@v3&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;        with&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;          apiToken&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; ${{ secrets.CLOUDFLARE_API_TOKEN }}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;          accountId&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;          wranglerVersion&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;4&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;          command&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; deploy&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;ol start=&quot;3&quot;&gt;
&lt;li&gt;Workersにカスタムドメイン&lt;code&gt;codedchords.dev&lt;&#x2F;code&gt;を追加。CloudflareがDNSレコードを自動設定してくれる&lt;&#x2F;li&gt;
&lt;li&gt;GitHub Pagesを無効にする。Settings → PagesでSourceをNoneに変更するが、GitHub Actionsが選択されている状態ではNoneに変更できないため、一度Branchに切り替えてから設定する&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;p&gt;移転後はGoogle Search Consoleに新ドメインのプロパティを追加し、サイトマップを送信しました。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;セキュリティヘッダーの設定&quot;&gt;セキュリティヘッダーの設定&lt;&#x2F;h2&gt;
&lt;p&gt;Cloudflare Workersの静的アセット機能は、ビルド出力に&lt;code&gt;_headers&lt;&#x2F;code&gt;ファイルを含めるとレスポンスヘッダーに自動適用します。Zolaの&lt;code&gt;static&#x2F;_headers&lt;&#x2F;code&gt;に以下を配置しました。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot; data-name=&quot;static&#x2F;_headers&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;&#x2F;*&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  X-Content-Type-Options: nosniff&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  X-Frame-Options: DENY&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  Referrer-Policy: strict-origin-when-cross-origin&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  Permissions-Policy: camera=(), microphone=(), geolocation=()&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;CSPは見送りました。SoundCloud、YouTube、OpenStreetMap、GoatCounter、Giscus、はてなブログカードなど外部リソースが多く、許可リストの管理コストに対して静的サイトでの実益が限定的なためです。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;旧ドメインからの転送&quot;&gt;旧ドメインからの転送&lt;&#x2F;h2&gt;
&lt;p&gt;旧ドメインへのアクセスを新ドメインに転送する必要があります。旧ドメインのDNSはFastMailで管理しておりCloudflareへの移行は行わないため、Cloudflare Redirect Rulesは使えません。&lt;&#x2F;p&gt;
&lt;p&gt;そこで、リダイレクト専用の静的サイトを生成する方法をとりました。Zolaで&lt;code&gt;zola build&lt;&#x2F;code&gt;すると全ページのHTMLが生成されます。aliasesによるリダイレクトページも含まれるため、以前Next.jsで運用していた時代のパスもカバーされます。この全HTMLをmeta refreshリダイレクトページに差し替えて、別リポジトリに配置し、旧ドメインでGitHub Pages配信する構成です。&lt;&#x2F;p&gt;
&lt;p&gt;各リダイレクトページの内容は以下のようになります。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;html&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-tag z-entity z-name z-tag&quot;&gt;&amp;lt;!DOCTYPE&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-other z-attribute-name&quot;&gt; html&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;&amp;lt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag&quot;&gt;html&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;  &amp;lt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag&quot;&gt;head&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;    &amp;lt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag&quot;&gt;meta&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-other z-attribute-name&quot;&gt; charset&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;=&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt;&amp;quot;utf-8&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt; &#x2F;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;    &amp;lt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag&quot;&gt;link&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-other z-attribute-name&quot;&gt; rel&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;=&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt;&amp;quot;canonical&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-other z-attribute-name&quot;&gt; href&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;=&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt;&amp;quot;https:&#x2F;&#x2F;codedchords.dev&#x2F;（対応パス）&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt; &#x2F;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;    &amp;lt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag&quot;&gt;meta&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-other z-attribute-name&quot;&gt;      http-equiv&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;=&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt;&amp;quot;refresh&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-other z-attribute-name&quot;&gt;      content&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;=&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt;&amp;quot;0; url=https:&#x2F;&#x2F;codedchords.dev&#x2F;（対応パス）&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;    &#x2F;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;  &amp;lt;&#x2F;&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag&quot;&gt;head&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;  &amp;lt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag&quot;&gt;body&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;&amp;gt;&amp;lt;&#x2F;&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag&quot;&gt;body&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;&amp;lt;&#x2F;&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag&quot;&gt;html&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-tag&quot;&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Pythonスクリプトで、Zolaビルドからリダイレクトページの差し替え、不要ファイルの削除、CNAME配置までを一括実行しています。通常ページ367件とaliasページ226件、合計593件のリダイレクトを生成しました。aliasページはZolaが生成したmeta refreshのリダイレクト先（正規パス）を読み取り、新ドメインの正規パスに直接転送します。GitHub Actionsでデプロイを自動化しています。&lt;&#x2F;p&gt;
&lt;p&gt;この方法であれば全ページ・全パスをカバーできます。GitHub Pagesではサーバーサイドの301リダイレクトが設定できないため、meta refresh + canonicalの組み合わせが現実的な最善策です。FastMailのDNS変更も不要で、既存のCNAME&#x2F;Aレコードをそのまま利用できます。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;まとめ&quot;&gt;まとめ&lt;&#x2F;h2&gt;
&lt;p&gt;GitHub PagesからCloudflare Workersへの移転で得た知見をまとめます。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Cloudflare ProxyとGitHub Pagesの組み合わせでは、Let&#x27;s Encrypt証明書のHTTP-01チャレンジを妨げるリスクがある&lt;&#x2F;li&gt;
&lt;li&gt;Cloudflare PagesのCI&#x2F;CDはv2以降Zolaをサポートしていない（&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;cloudflare&#x2F;pages-build-image&#x2F;issues&#x2F;3&quot;&gt;issue #3&lt;&#x2F;a&gt;は2023年からOpen）。GitHub Actions + &lt;code&gt;wrangler deploy&lt;&#x2F;code&gt;で代替可能&lt;&#x2F;li&gt;
&lt;li&gt;Cloudflare Workersの静的アセット機能は&lt;code&gt;_headers&lt;&#x2F;code&gt;ファイルでセキュリティヘッダーを簡単に設定できる&lt;&#x2F;li&gt;
&lt;li&gt;旧ドメインからの転送は、meta refreshリダイレクトの静的サイトを生成する方法で全パスをカバーできる&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;&lt;code&gt;.dev&lt;&#x2F;code&gt;ドメインのHSTSプリロードに加え、Cloudflare Workers側でセキュリティヘッダーも設定できるようになり、セキュリティスキャナーの警告も解消されました。&lt;&#x2F;p&gt;
</content>
        <summary type="html">GitHub PagesからCloudflare Workersへブログを移転した際の落とし穴と解決策を共有します。証明書更新やZolaビルド非対応など、3つのアプローチを検討した経験をまとめています。
</summary>
        </entry><entry xml:lang="en">
        <title>GitHub Pagesのセキュリティヘッダー警告、無視していいの？</title>
        <published>2026-02-06T00:00:00+00:00</published>
        <updated>2026-02-06T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2026/02/github-pages-security-headers/" type="text/html"/>
        <id>https://codedchords.dev/blog/2026/02/github-pages-security-headers/</id>
        
            <content type="html">&lt;!-- textlint-disable --&gt;
&lt;div class=&quot;admonition note&quot;&gt;
    &lt;div class=&quot;admonition-icon admonition-icon-note&quot;&gt;&lt;&#x2F;div&gt;
    &lt;div class=&quot;admonition-content&quot;&gt;
        &lt;strong class=&quot;admonition-title&quot;&gt;NOTE&lt;&#x2F;strong&gt;
        &lt;p&gt;この記事は
&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;zenn.dev&#x2F;yostos&#x2F;articles&#x2F;github-pages-security-headers&quot;&gt;Zenn.dev&lt;&#x2F;a&gt;
に掲載した記事の転載です。&lt;&#x2F;p&gt;

    &lt;&#x2F;div&gt;
&lt;&#x2F;div&gt;
&lt;!-- textlint-enable --&gt;
&lt;h2 id=&quot;TL;DR&quot;&gt;TL;DR&lt;&#x2F;h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Pagesではセキュリティヘッダーを設定する機能がなく、スキャナーの警告がでる&lt;&#x2F;li&gt;
&lt;li&gt;セキュリティスキャナーの警告は「ベストプラクティス未達」であり「脆弱性」ではない&lt;&#x2F;li&gt;
&lt;li&gt;GitHub Pagesでは大抵静的サイトのため、放置しても実質的なリスクは低い&lt;&#x2F;li&gt;
&lt;li&gt;自前でホスティングしたWordPressなどの動的サイトは必ず対応すべき&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h2 id=&quot;セキュリティヘッダーとは何か&quot;&gt;セキュリティヘッダーとは何か&lt;&#x2F;h2&gt;
&lt;p&gt;セキュリティスキャナーでよく指摘される6つのHTTPレスポンスヘッダーがあります。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;ヘッダー&lt;&#x2F;th&gt;&lt;th&gt;目的&lt;&#x2F;th&gt;&lt;th&gt;設定しないリスク&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Strict-Transport-Security (HSTS)&lt;&#x2F;td&gt;&lt;td&gt;HTTPS接続を強制&lt;&#x2F;td&gt;&lt;td&gt;HTTPへのダウングレード攻撃&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Content-Security-Policy (CSP)&lt;&#x2F;td&gt;&lt;td&gt;XSS攻撃を防止&lt;&#x2F;td&gt;&lt;td&gt;悪意あるスクリプト実行&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;X-Frame-Options&lt;&#x2F;td&gt;&lt;td&gt;クリックジャッキング防止&lt;&#x2F;td&gt;&lt;td&gt;偽サイトへの埋め込み&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;X-Content-Type-Options&lt;&#x2F;td&gt;&lt;td&gt;MIMEスニッフィング防止&lt;&#x2F;td&gt;&lt;td&gt;ファイル種別の誤認識&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Referrer-Policy&lt;&#x2F;td&gt;&lt;td&gt;リファラー情報の制御&lt;&#x2F;td&gt;&lt;td&gt;URLパラメータの漏洩&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;Permissions-Policy&lt;&#x2F;td&gt;&lt;td&gt;ブラウザ機能の制御&lt;&#x2F;td&gt;&lt;td&gt;カメラ等の不正利用&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;これらのヘッダーは、Webサーバーがレスポンスに含めることで、
ブラウザにセキュリティ関連の指示を与えます。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;GitHub_Pagesの制限&quot;&gt;GitHub Pagesの制限&lt;&#x2F;h2&gt;
&lt;p&gt;GitHub Pagesは静的サイトホスティングサービスですが、
&lt;strong&gt;HTTPレスポンスヘッダーをカスタマイズする機能がありません&lt;&#x2F;strong&gt;。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;.htaccess&lt;&#x2F;code&gt; は使えない（Apache設定ファイル）&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;nginx.conf&lt;&#x2F;code&gt; も使えない（Nginx設定ファイル）&lt;&#x2F;li&gt;
&lt;li&gt;GitHub側で固定されたヘッダーが返される&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;どうしてもセキュリティヘッダーを設定したい場合は、Cloudflare CDNを前段に置けばTransform Rulesでヘッダーを追加できます。
ただし、Cloudflareの無料プランはネームサーバー移管が必須です。&lt;&#x2F;p&gt;
&lt;p&gt;既存のDNSサービスを使い続けたい場合、
この方法は採用しづらいです。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;静的サイトと動的サイトでリスクが違う&quot;&gt;静的サイトと動的サイトでリスクが違う&lt;&#x2F;h2&gt;
&lt;p&gt;セキュリティヘッダーの重要度は、サイトの種類によって大きく異なります。
GitHub Pagesでも動的なSPAをホストできますが、
ここではZolaやHugoなどのSSGで生成した純粋な静的サイトを想定しています。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;観点&lt;&#x2F;th&gt;&lt;th&gt;静的サイト（SSG生成）&lt;&#x2F;th&gt;&lt;th&gt;動的サイト（WordPress等）&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;ユーザー入力&lt;&#x2F;td&gt;&lt;td&gt;受け付けない&lt;&#x2F;td&gt;&lt;td&gt;フォーム等で受け付ける&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;サーバーサイド処理&lt;&#x2F;td&gt;&lt;td&gt;なし&lt;&#x2F;td&gt;&lt;td&gt;PHP + DB&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;管理画面&lt;&#x2F;td&gt;&lt;td&gt;なし&lt;&#x2F;td&gt;&lt;td&gt;&lt;code&gt;&#x2F;wp-admin&lt;&#x2F;code&gt; 等が存在&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;XSSリスク&lt;&#x2F;td&gt;&lt;td&gt;ほぼなし&lt;&#x2F;td&gt;&lt;td&gt;高い&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;クリックジャッキング&lt;&#x2F;td&gt;&lt;td&gt;影響軽微&lt;&#x2F;td&gt;&lt;td&gt;管理画面が標的になる&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;WordPressでセキュリティヘッダーが未設定の場合、
管理者がログイン中にクリックジャッキング攻撃を受けたり、
XSS経由でマルウェアを注入されたりするリスクがあります。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;判断基準：いつ対応すべきか&quot;&gt;判断基準：いつ対応すべきか&lt;&#x2F;h2&gt;
&lt;p&gt;以下のフローチャートで判断できます。&lt;&#x2F;p&gt;
&lt;!-- textlint-disable --&gt;


&lt;noscript&gt;
    &lt;strong&gt;⚠️ JavaScript is required to render the diagram.&lt;&#x2F;strong&gt;
&lt;&#x2F;noscript&gt;
&lt;pre class=&quot;mermaid invertible-image&quot;&gt;
    flowchart LR
A[フォームがある？] --&gt;|Yes| B[対応すべき]
A --&gt;|No| C[サイトの性質は？]
C --&gt;|個人ブログ| D[放置OK]
C --&gt;|企業サイト| E[できれば対応]
C --&gt;|公的機関| F[対応すべき]
&lt;&#x2F;pre&gt;
&lt;!-- textlint-enable --&gt;
&lt;p&gt;フォームがあるサイトは対応が必要です。
問い合わせフォーム、会員登録、ログイン機能、寄付やEC機能があれば、
ユーザー入力を受け付けるためXSSのリスクがあります。&lt;&#x2F;p&gt;
&lt;p&gt;フォームがない場合はサイトの性質で判断します。
個人の技術ブログやポートフォリオなら放置で問題ありません。
公的機関などのサイトは、信頼性の観点から対応が望ましいです。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;まとめ&quot;&gt;まとめ&lt;&#x2F;h2&gt;
&lt;p&gt;セキュリティスキャナーの警告を見ると焦りますが、
すべての警告に対応する必要はありません。&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;重要なのはリスク評価です。&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;何を守る必要があるか（資産）&lt;&#x2F;li&gt;
&lt;li&gt;どんな攻撃が想定されるか（脅威）&lt;&#x2F;li&gt;
&lt;li&gt;攻撃が成功する可能性はあるか（脆弱性）&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;GitHub Pagesで静的ブログを公開している場合、
セキュリティヘッダーがなくても攻撃面がほとんどありません。
「設定できないから放置」は、この場合は合理的な判断です。&lt;&#x2F;p&gt;
&lt;p&gt;一方、WordPressや動的サイトでは事情が異なります。
&lt;code&gt;.htaccess&lt;&#x2F;code&gt; やプラグインで設定できるので、対応しておくべきです。&lt;&#x2F;p&gt;
&lt;p&gt;スキャナーの警告は「ベストプラクティスに従っていない」という指摘であり、
「今すぐ危険」という意味ではありません。
コンテキストに応じた判断をしましょう。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;参考文献&quot;&gt;参考文献&lt;&#x2F;h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;owasp.org&#x2F;www-project-secure-headers&#x2F;&quot;&gt;OWASP Secure Headers Project&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;orgs&#x2F;community&#x2F;discussions&#x2F;54257&quot;&gt;GitHub Community Discussion - HTTP Headers on Pages&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;!-- textlint-disable --&gt;
&lt;div class=&quot;admonition note&quot;&gt;
    &lt;div class=&quot;admonition-icon admonition-icon-note&quot;&gt;&lt;&#x2F;div&gt;
    &lt;div class=&quot;admonition-content&quot;&gt;
        &lt;strong class=&quot;admonition-title&quot;&gt;免責事項&lt;&#x2F;strong&gt;
        &lt;p&gt;本記事は情報提供を目的としており、
個別の状況に応じた判断は読者ご自身の責任でお願いします。
セキュリティ要件は組織やサービスによって異なるため、
必要に応じて専門家にご相談ください。&lt;&#x2F;p&gt;

    &lt;&#x2F;div&gt;
&lt;&#x2F;div&gt;
&lt;!-- textlint-enable --&gt;
</content>
        <summary type="html">このブログはZola+GitHub Pagesで実現していますが、
GitHub Pagesはセキュリティヘッダの設定ができません。
いないとは思いますが、セキュリティスキャナーなどで未設定を見つけて文句をつけてくるセキュリティ厨がいないとも限りません。
対応すべきか放置すべきかの判断基準を解説しておきます。
</summary>
        </entry><entry xml:lang="en">
        <title>React Server Components RCE脆弱性（CVE-2025-55182）への対応記録</title>
        <published>2025-12-06T00:00:00+00:00</published>
        <updated>2025-12-06T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2025/12/react-nextjs-cve-2025-55182-response/" type="text/html"/>
        <id>https://codedchords.dev/blog/2025/12/react-nextjs-cve-2025-55182-response/</id>
        
            <content type="html">&lt;h2 id=&quot;脆弱性の概要&quot;&gt;脆弱性の概要&lt;&#x2F;h2&gt;
&lt;h3 id=&quot;CVE-2025-55182とは&quot;&gt;CVE-2025-55182とは&lt;&#x2F;h3&gt;
&lt;p&gt;CVE-2025-55182は、React 19のServer Components（RSC）における「Flight」プロトコルの安全でないデシリアライゼーション（deserialize）に起因する脆弱性です。
主な特徴は次の通りです。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVSSスコア: 10.0（最大値）&lt;&#x2F;strong&gt;&lt;&#x2F;li&gt;
&lt;li&gt;影響範囲: React 19.0.0、19.1.0、19.1.1、19.2.0&lt;&#x2F;li&gt;
&lt;li&gt;攻撃条件: 認証不要、細工されたHTTPリクエストのみで実行可能&lt;&#x2F;li&gt;
&lt;li&gt;デフォルト設定で脆弱: &lt;code&gt;create-next-app&lt;&#x2F;code&gt;により作成した標準的なNext.jsアプリケーションが影響を受ける&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;技術的な仕組み&quot;&gt;技術的な仕組み&lt;&#x2F;h3&gt;
&lt;p&gt;この脆弱性は、RSCの内部通信プロトコルである「Flight」の処理において、攻撃者の制御可能なデータを適切な検証なしにデシリアライズしてしまうことに起因します。攻撃者からペイロードを含むHTTPリクエストが送信されると、サーバー側ではこれをFlightプロトコルのデータとして処理し、検証なしにデシリアライズします。この結果、任意のコードを実行される可能性があります。&lt;&#x2F;p&gt;
&lt;p&gt;重要なのは、この処理がアプリケーションの認証ロジックより前、つまりMiddlewareでの保護より深い層で行われるため、通常の認証機構では防げないという点です。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;CVE番号の統合経緯&quot;&gt;CVE番号の統合経緯&lt;&#x2F;h2&gt;
&lt;p&gt;2025年12月3日時点では、以下の2つのCVE番号で追跡されていました。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVE-2025-55182&lt;&#x2F;strong&gt;: React Server Componentsの脆弱性&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;CVE-2025-66478&lt;&#x2F;strong&gt;: Next.jsの脆弱性&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;調査の結果、Next.jsの脆弱性は実質的にReactの脆弱性に起因することが判明し、&lt;strong&gt;CVE-2025-66478は重複として却下&lt;&#x2F;strong&gt;されました。現在は&lt;strong&gt;CVE-2025-55182&lt;&#x2F;strong&gt;に統合されています。&lt;&#x2F;p&gt;
&lt;p&gt;この経緯は、脆弱性の根本原因がReactのRSC実装そのものにあり、Next.jsはその影響を受けていたに過ぎないことを示しています。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;影響を受けるバージョンと修正版&quot;&gt;影響を受けるバージョンと修正版&lt;&#x2F;h2&gt;
&lt;h3 id=&quot;React_&#x2F;_React-dom&quot;&gt;React &#x2F; React-dom&lt;&#x2F;h3&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;影響を受けるバージョン&lt;&#x2F;th&gt;&lt;th&gt;修正済みバージョン&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;19.0.0&lt;&#x2F;td&gt;&lt;td&gt;19.0.1&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;19.1.0, 19.1.1&lt;&#x2F;td&gt;&lt;td&gt;19.1.2&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;19.2.0&lt;&#x2F;td&gt;&lt;td&gt;19.2.1&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;h3 id=&quot;Next.js&quot;&gt;Next.js&lt;&#x2F;h3&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;影響を受けるバージョン&lt;&#x2F;th&gt;&lt;th&gt;修正済みバージョン&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;15.x（全般）&lt;&#x2F;td&gt;&lt;td&gt;15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;16.x（全般）&lt;&#x2F;td&gt;&lt;td&gt;16.0.7&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;14.3.0-canary.77以降&lt;&#x2F;td&gt;&lt;td&gt;（14.x Stable版は影響なし）&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;p&gt;&lt;strong&gt;注&lt;&#x2F;strong&gt;: Next.js 13.x、14.x stable版、Pages Router、Edge Runtimeは影響を受けません。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;実際の攻撃状況&quot;&gt;実際の攻撃状況&lt;&#x2F;h2&gt;
&lt;p&gt;この脆弱性は公表直後から実際に悪用されています。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;2025年12月3日: 脆弱性が公表される&lt;&#x2F;li&gt;
&lt;li&gt;同日中: 中国関連の脅威グループによる大規模な攻撃活動が観測される&lt;&#x2F;li&gt;
&lt;li&gt;2025年12月5日午前6時（UTC）以降: Wizのセンサーが複数の被害者を検知&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;この脆弱性は「React2Shell」または「React4Shell」という名称でも呼ばれ、既に実証コード（PoC）が公開されています。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;当ブログでの対応状況&quot;&gt;当ブログでの対応状況&lt;&#x2F;h2&gt;
&lt;h3 id=&quot;対応タイムライン&quot;&gt;対応タイムライン&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;2025年12月3日&lt;&#x2F;strong&gt;: CVE-2025-55182が公表される&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;2025年12月5日&lt;&#x2F;strong&gt;: 当ブログで修正版へのアップデート実施（v1.7.1）&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;実施した対応&quot;&gt;実施した対応&lt;&#x2F;h3&gt;
&lt;p&gt;以下のパッケージを修正版にアップデートしました。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 実施したアップデート&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;React:&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 19.0.0&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; →&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 19.2.1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;React-dom:&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 19.0.0&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; →&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 19.2.1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;Next.js:&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 15.2.3&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; →&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 15.5.7&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;@next&#x2F;mdx:&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 15.2.3&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; →&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 15.5.7&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;eslint-config-next:&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 15.2.3&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; →&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 15.5.7&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;当ブログは&lt;strong&gt;CVE-2025-55182に完全対応済み&lt;&#x2F;strong&gt;であり、この脆弱性の影響を受けない安全な状態です。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;推奨される対応&quot;&gt;推奨される対応&lt;&#x2F;h2&gt;
&lt;p&gt;Next.jsやReactを使用しているプロジェクトをお持ちの方は、以下の対応を推奨します。&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1._バージョンの確認&quot;&gt;1. バージョンの確認&lt;&#x2F;h3&gt;
&lt;p&gt;まず現在のバージョンを確認します。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;npm&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; list next react react-dom&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h3 id=&quot;2._修正版へのアップデート&quot;&gt;2. 修正版へのアップデート&lt;&#x2F;h3&gt;
&lt;p&gt;該当する場合は、直ちに修正版へアップデートしてください。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# npm の場合&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;npm&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; install next@latest react@latest react-dom@latest&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# yarn の場合&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;yarn&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; add next@latest react@latest react-dom@latest&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# pnpm の場合&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;pnpm&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; add next@latest react@latest react-dom@latest&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h3 id=&quot;3._内部依存関係の確認&quot;&gt;3. 内部依存関係の確認&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;code&gt;package.json&lt;&#x2F;code&gt;だけでなく、ロックファイル（&lt;code&gt;package-lock.json&lt;&#x2F;code&gt;、&lt;code&gt;yarn.lock&lt;&#x2F;code&gt;など）も確認し、内部依存関係として古いバージョンが残っていないか確認することを強く推奨します。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# ロックファイル内のReactバージョンを確認&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;grep&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt; -A5 &amp;#39;&amp;quot;react&amp;quot;:&amp;#39; package-lock.json&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;grep&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt; -A5 &amp;#39;&amp;quot;next&amp;quot;:&amp;#39; package-lock.json&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h3 id=&quot;4._デプロイ&quot;&gt;4. デプロイ&lt;&#x2F;h3&gt;
&lt;p&gt;アップデート後は速やかにビルドとデプロイを実施してください。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;npm&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; run build&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# デプロイコマンドを実行&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h2 id=&quot;まとめ&quot;&gt;まとめ&lt;&#x2F;h2&gt;
&lt;p&gt;CVE-2025-55182は、React Server Componentsの根本的な脆弱性であり、
&lt;strong&gt;CVSS 10.0&lt;&#x2F;strong&gt;という最大の深刻度を持つ重大な問題です。デフォルト設定で脆弱であり、認証を回避して攻撃可能という特性から、速やかな対応が必要です。&lt;&#x2F;p&gt;
&lt;p&gt;当ブログでは公表から2日以内に対応を完了しましたが、既に実際の攻撃が観測されているため、まだ対応されていない方は最優先で対応することを強く推奨します。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;参考リンク&quot;&gt;参考リンク&lt;&#x2F;h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;react.dev&#x2F;blog&#x2F;2025&#x2F;12&#x2F;03&#x2F;critical-security-vulnerability-in-react-server-components&quot;&gt;Critical Security Vulnerability in React Server Components – React&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;nextjs.org&#x2F;blog&#x2F;CVE-2025-66478&quot;&gt;Security Advisory: CVE-2025-66478 | Next.js&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.wiz.io&#x2F;blog&#x2F;critical-vulnerability-in-react-cve-2025-55182&quot;&gt;Critical RCE Vulnerabilities Discovered in React &amp;amp; Next.js | Wiz Blog&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;unit42.paloaltonetworks.com&#x2F;cve-2025-55182-react-and-cve-2025-66478-next&#x2F;&quot;&gt;Critical Vulnerabilities in React Server Components and Next.js&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;nvd.nist.gov&#x2F;vuln&#x2F;detail&#x2F;CVE-2025-55182&quot;&gt;NVD - CVE-2025-55182&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
</content>
        <summary type="html">2025年12月3日、React Server Components（RSC）とNext.jsにおいて、認証不要でリモートコード実行（RCE）が可能となる重大な脆弱性が公表されました。この記事では、この脆弱性の深刻度、CVE番号の統合経緯、そして当ブログでの対応状況について記録します。</summary>
        </entry><entry xml:lang="en">
        <title>技術無知が経営リスクになった理由</title>
        <published>2025-11-08T00:00:00+00:00</published>
        <updated>2025-11-08T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2025/11/tech-ignorance-is-business-liability-ja/" type="text/html"/>
        <id>https://codedchords.dev/blog/2025/11/tech-ignorance-is-business-liability-ja/</id>
        
            <content type="html">&lt;!-- textlint-disable --&gt;
&lt;img
  src=&quot;https:&amp;#x2F;&amp;#x2F;codedchords.dev&amp;#x2F;blog&amp;#x2F;2025&amp;#x2F;11&amp;#x2F;tech-ignorance-is-business-liability-ja&amp;#x2F;noitdept.webp?h=074677f7f792dfd9f5b2&quot;
  alt=&quot;No IT dept&quot; width=&quot;1456&quot; height=&quot;816&quot; loading=&quot;lazy&quot;
&#x2F;&gt;&lt;!-- textlint-enable --&gt;
&lt;details&gt;
&lt;summary&gt;Table of Contents&lt;&#x2F;summary&gt;
  &lt;!-- toc --&gt;
&lt;&#x2F;details&gt;
&lt;h2 id=&quot;業務システム台帳とは何か&quot;&gt;業務システム台帳とは何か&lt;&#x2F;h2&gt;
&lt;p&gt;「業務システム台帳」とは、組織が所有する業務システムを記録し、一覧化する台帳です。重要なのは、各システムの内部構造や技術的な詳細を管理するものではないということです。&lt;&#x2F;p&gt;
&lt;p&gt;具体的には、台帳にはシステムの以下のような基本的な属性を記録します。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;システム名。組織内で一意に識別できる名称(例。財務システム、販売管理システム、人事管理システム)&lt;&#x2F;li&gt;
&lt;li&gt;業務プロセス。システムがサポートする業務プロセスの名称。これにより、システムが組織にどのような価値を提供しているかが可視化される。前提として、組織が業務プロセスの台帳も整備していることが望ましい&lt;&#x2F;li&gt;
&lt;li&gt;業務プロセスオーナー。これも重要な属性である。システムの責任者が誰で、予算を管理しているかが明確になる。これがないと、システムに関する意思決定やライフサイクル管理が曖昧になる&lt;&#x2F;li&gt;
&lt;li&gt;重要度。システムが事業継続計画(BCP)の対象となる重要システムなのか、停止しても業務への影響が限定的なシステムなのかを分類する。リスク管理や投資の優先順位を決定するために不可欠な情報である&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;業務システム台帳は、ITガバナンスの最も基本的な構成要素です。組織が自分の所有物を理解していなければ、適切な投資判断、リスク管理、コスト最適化は始まりません。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;業務システム台帳の重要性&quot;&gt;業務システム台帳の重要性&lt;&#x2F;h2&gt;
&lt;p&gt;近年、ランサムウェアに攻撃される企業が増えています。ランサムウェアはシステムとデータを暗号化し、業務を数ヶ月にわたって停止させます。このような危機的状況において、業務システム台帳が存在しなかったらどうなるでしょうか。&lt;&#x2F;p&gt;
&lt;p&gt;何が破壊され、何を復旧すべきかを誰も把握できません。どのシステムが業務にとって最も重要でしょうか。各システムのデータバックアップはどこにあるのでしょうか。そもそも組織全体でいくつのシステムが稼働していたのでしょうか。この基本的な情報がなければ、復旧作業は極めて混乱し、事業再開は大幅に遅れることになります。業務システム台帳は危機管理のための最も基本的なインフラです。&lt;&#x2F;p&gt;
&lt;p&gt;もう1つの重要な側面は、会計要件に起因します。請負契約で開発されたシステムは無形固定資産として減価償却する必要があり、運用段階での機能強化も資産計上の対象となります。しかし、会計資産台帳だけでは、どの機能強化が資産計上に値するかといった業務システム固有の判断は難しいです。会計資産台帳と整合性のとれた業務システム台帳が必要です。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;なぜ組織は業務システム台帳を維持できないのか&quot;&gt;なぜ組織は業務システム台帳を維持できないのか&lt;&#x2F;h2&gt;
&lt;p&gt;多くの組織は他社の災害を目撃し、危機感に駆られて台帳の整備を始めます。しかし、ほとんどの場合、台帳は作成された瞬間から忘れ去られ、やがて古くなり、闇に葬られます。&lt;&#x2F;p&gt;
&lt;p&gt;例えば、ある部門が独自にシステムを調達したが、台帳には登録されません。別のシステムは対応する業務プロセスを拡大するために大規模な機能強化を行ったが、台帳には反映されません。このようにして、台帳は徐々に現実と乖離し、役に立たなくなり、最終的には廃棄されます。&lt;&#x2F;p&gt;
&lt;p&gt;なぜこのようなことが起こるのでしょうか。マーフィーの法則は「うまくいかなくなる可能性のあることは、うまくいかなくなる」と述べています。しかも、我々はITガバナンスの確立に失敗した機能不全の組織について語っているのです。そのような組織において、人々の善意と勤勉さに頼る運用は、いずれ必ず失敗します。&lt;&#x2F;p&gt;
&lt;p&gt;では、どうすれば台帳を維持できるのでしょうか。鍵は金の流れです。部門のシステム調達も、大規模なシステム強化も、必ず金銭取引を伴います。この金の流れを捕捉できれば、台帳の変更を見逃さないトリガーとして利用できます。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;業務システム台帳を維持する仕組み&quot;&gt;業務システム台帳を維持する仕組み&lt;&#x2F;h2&gt;
&lt;p&gt;前節で述べたように、鍵は金の流れを捕捉することです。業務システムに関連する財務プロセスは、予算編成、支出(調達)、固定資産会計の3つです。これらのプロセスに台帳の更新を組み込むことで、台帳を自動的に維持する仕組みを確立できます。&lt;&#x2F;p&gt;
&lt;h3 id=&quot;予算編成&quot;&gt;予算編成&lt;&#x2F;h3&gt;
&lt;p&gt;業務システムを運用または変更するには予算編成が必要です。一般的に、予算は予算コード(勘定科目コード)と予算額で管理されます。したがって、予算編成プロセスでは以下の2つが必要です。&lt;&#x2F;p&gt;
&lt;p&gt;予算が業務システムに関連する場合、業務システム台帳のレコードとリンクさせなければなりません。この段階で業務システムが業務システム台帳に登録されていない場合は、新しいシステムとみなし、台帳に追加しなければなりません。このようにして、台帳にないシステムへの予算編成を防ぐことができます。&lt;&#x2F;p&gt;
&lt;p&gt;次に、予算編成プロセスの完了時に、運用中または運用予定のすべての業務システムに予算が配分されているかを確認します。予算が割り当てられていないにもかかわらず稼働している運用業務システムのオーナーには、予算配分を義務付けます。&lt;&#x2F;p&gt;
&lt;p&gt;重要なのは、台帳を維持するために台帳の更新を要求するのではなく、台帳と整合性がとれていなければ予算処理を完了できない仕組みを組み込むことです。&lt;&#x2F;p&gt;
&lt;h3 id=&quot;支出(調達)&quot;&gt;支出(調達)&lt;&#x2F;h3&gt;
&lt;p&gt;業務システムの導入、変更、保守には必ず支出が発生します。IT部門が確立されていない組織では、これらの支出は通常、調達部門または経理部門を通じて処理されます。この調達プロセス自体が、台帳を維持するための最も信頼できるトリガーとなります。&lt;&#x2F;p&gt;
&lt;p&gt;業務システムに関連する発注や契約は、どの予算に紐づいているかで識別できるはずです。業務システムに関連すると識別された調達については、発注時と納品時の両方で業務システム台帳とのリンクと整合性を確保することを義務付けるべきです。これにより、「部門が独自にシステムを調達したが、台帳には追加されなかった」といった失敗パターンを防ぐことができます。&lt;&#x2F;p&gt;
&lt;p&gt;調達プロセスに台帳の整合性チェックを組み込むことで、多くの企業はこのチェックを迂回した調達を逸脱、つまり「BYPASS」として扱い、要求部門にペナルティを課します。将来的には、これらのチェックは組織のITガバナンスフレームワークの一部としても機能し、導入されるシステムが組織の意図するアーキテクチャに合致しているかを確認するレビューポイントとしても機能します。&lt;&#x2F;p&gt;
&lt;h3 id=&quot;固定資産会計&quot;&gt;固定資産会計&lt;&#x2F;h3&gt;
&lt;p&gt;請負契約で開発された業務システムは、組織の無形固定資産として記録され、減価償却の対象となります。SaaSなどのサービスベースの契約は資産として計上されませんが、発注・納品されるシステムは会計上も適切に管理しなければなりません。&lt;&#x2F;p&gt;
&lt;p&gt;IT部門がない組織では「引き渡し」を捕捉するプロセスがないため、納品時に無形固定資産台帳の更新と業務システム台帳の更新をリンクさせる仕組みが不可欠です。システムオーナーは、機能強化が資産計上に値するかを判断し、経理部門に台帳の更新を依頼しなければなりません。この整合性チェックが完了するまで検収を完了できないようなプロセスを設計することで、両方の台帳が確実に更新されます。&lt;&#x2F;p&gt;
&lt;p&gt;この仕組みには2つの効果があります。組織の会計実務が正確であれば、無形固定資産台帳には資産計上が必要なすべてのシステムが正しく記録されているはずです。この台帳との整合性を維持することで、業務システム台帳の信頼性が高まります。逆に、会計実務が不正確な場合、業務システム台帳との整合性を確保する仕組みを確立することで、不適切な会計処理を防ぐことができます。&lt;&#x2F;p&gt;
&lt;p&gt;重要なのは、この整合性チェックを検収プロセスに組み込むことで、人間の善意に依存することなく、両方の台帳が確実に維持されることです。この検証なしには検収を完了できないようにすれば、更新は標準的なワークフローの一部として自動的に行われます。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;結論&quot;&gt;結論&lt;&#x2F;h2&gt;
&lt;p&gt;業務システム台帳すら整備していない組織は、たとえ危機感に駆られて作成したとしても、それを維持できません。作成した瞬間から劣化し始めることは明らかです。&lt;&#x2F;p&gt;
&lt;p&gt;重要なのは、それを維持する仕組みです。金の流れに伴う避けられないプロセス、すなわち予算、調達、会計に、台帳を更新・維持する仕組みを組み込むことが重要です。&lt;&#x2F;p&gt;
&lt;p&gt;逆に言えば、この仕組みを確立するだけで、ITガバナンスへの第一歩を踏み出すことができます。難しいことではありません。システムに関連する金の流れを捕捉すればよいだけです。それすらできないのであれば、あなたの組織はITガバナンス以前にコーポレートガバナンスの基本すら備わっていません。まあ、そうなのでしょうけれど。&lt;&#x2F;p&gt;
</content>
        <summary type="html">この記事はIT部門を持たず、非技術部門だけでベンダーに作らせた業務システムを所有し運用している組織について想定しています。きっとランサムウェアで危機に見舞われているアサヒビールやアスクルを見て震え上がって、何をすればいいか焦っている組織も多いと思います。そんな組織が行なうべき第一歩として業務システム台帳の整備について解説しています。</summary>
        </entry><entry xml:lang="en">
        <title>Because Your Tech Ignorance Is Now a Business Liability</title>
        <published>2025-11-08T00:00:00+00:00</published>
        <updated>2025-11-08T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2025/11/tech-ignorance-is-business-liability/" type="text/html"/>
        <id>https://codedchords.dev/blog/2025/11/tech-ignorance-is-business-liability/</id>
        
            <content type="html">&lt;!-- textlint-disable --&gt;
&lt;img
  src=&quot;https:&amp;#x2F;&amp;#x2F;codedchords.dev&amp;#x2F;blog&amp;#x2F;2025&amp;#x2F;11&amp;#x2F;tech-ignorance-is-business-liability&amp;#x2F;noitdept.webp?h=074677f7f792dfd9f5b2&quot;
  alt=&quot;No IT dept&quot; width=&quot;1456&quot; height=&quot;816&quot; loading=&quot;lazy&quot;
&#x2F;&gt;&lt;!-- textlint-enable --&gt;
&lt;details&gt;
&lt;summary&gt;Table of Contents&lt;&#x2F;summary&gt;
  &lt;!-- toc --&gt;
&lt;&#x2F;details&gt;
&lt;h2 id=&quot;What_is_Application_System_Inventory?&quot;&gt;What is Application System Inventory?&lt;&#x2F;h2&gt;
&lt;p&gt;&quot;Application System Inventory&quot; is an inventory that records and keeps a list of application systems the organization owns. The important point is that it does not manage the internal structure of each system or technical details.&lt;&#x2F;p&gt;
&lt;p&gt;More specifically, the inventory stores the following basic attributes of systems.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;System Name: A name that can be uniquely identified within the organization (e.g. Finance System, Sales Management System, Human Resource Management System).&lt;&#x2F;li&gt;
&lt;li&gt;Business Process: A name of the business process that the system supports. This makes visible what kind of value the system provides to the organization. As a prerequisite, it is desirable that the organization also maintains an inventory of its business processes.&lt;&#x2F;li&gt;
&lt;li&gt;Business Process Owner: This is also an important attribute. This clarifies who is responsible for the system and manages the budget for it. Without this, decision-making and life-cycle management for the system become ambiguous.&lt;&#x2F;li&gt;
&lt;li&gt;Importance: This classifies whether the system is a critical system that is subject to Business Continuity Planning(BCP), or a system whose impact on business operations is limited even if it stops. This is essential information for risk management and determining investment priorities.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Application System Inventory is the most fundamental component of IT governance. If the organization doesn&#x27;t understand what it owns, appropriate investment decisions, risk management, and cost optimization cannot begin.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Why_Application_System_Inventory_Is_Important&quot;&gt;Why Application System Inventory Is Important&lt;&#x2F;h2&gt;
&lt;p&gt;In recent months, an increasing number of enterprises have been attacked by ransomware. The ransomware encrypts their systems and data, disrupting business operations for several months. In such critical situations, what happens if Application System Inventory does not exist?&lt;&#x2F;p&gt;
&lt;p&gt;No one would be able to understand what has been destroyed and what should be restored. Which systems are most critical for business operations? Where are the data backups for each system located? How many systems were operating across the organization in the first place? Without this basic information, recovery efforts would become extremely chaotic, and business resumption would be significantly delayed. Application System Inventory is the most fundamental infrastructure for crisis management.&lt;&#x2F;p&gt;
&lt;p&gt;Another important aspect is driven by accounting requirements.
Systems developed under a work contract (&quot;Ukeoi&quot; contract)
need to be depreciated as intangible fixed assets.
Functional enhancements during the operational phase are also
subject to capitalization. However, with only the accounting
asset ledger, it is difficult to make judgments specific to
Application Systems, such as which functional enhancements
warrant capitalization. An Application System Inventory that
is aligned with the accounting asset ledger is necessary.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Why_Organizations_Cannot_Maintain_Application_System_Inventory&quot;&gt;Why Organizations Cannot Maintain Application System Inventory&lt;&#x2F;h2&gt;
&lt;p&gt;Many organizations witness other companies&#x27; disasters and begin to establish their Inventory, driven by a sense of crisis. However, in most cases, the inventory is forgotten from the moment it is created and eventually becomes outdated and buried in the darkness.&lt;&#x2F;p&gt;
&lt;p&gt;For example, a department procures a system independently, but it is not registered in the inventory. Another system undergoes major enhancements to expand the business processes it supports, but this is not reflected in the inventory. In this way, the inventory gradually diverges from reality, becomes useless, and is eventually discarded.&lt;&#x2F;p&gt;
&lt;p&gt;Why does this happen? Murphy&#x27;s Law states, &quot;Anything that can go wrong will go wrong.&quot; Moreover, we are talking about dysfunctional organizations that have failed to establish IT Governance. Operations that rely on the goodwill and diligence of people in such organizations are bound to fail at some point.&lt;&#x2F;p&gt;
&lt;p&gt;So how can we maintain the Inventory? The key is the flow of money. Both departmental system procurement and major system enhancements are always accompanied by financial transactions. If you can capture this flow of money, you can use it as a trigger that won&#x27;t miss changes to the Inventory.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;The_Mechanism_to_Maintain_Application_System_Inventory&quot;&gt;The Mechanism to Maintain Application System Inventory&lt;&#x2F;h2&gt;
&lt;p&gt;As described in the previous section, the key is to capture the flow of money. There are three financial processes related to Application System: budgeting, expenditure(procurement), and fixed asset accounting. By incorporating Inventory updates into these processes, you can establish a mechanism to maintain the Inventory automatically.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;Budgeting&quot;&gt;Budgeting&lt;&#x2F;h3&gt;
&lt;p&gt;Budgeting must be done for operating or modifying an Application System. Generally, budgets are managed using budget codes or account codes, along with budget amounts. Therefore, the following two things are required during the budgeting process:&lt;&#x2F;p&gt;
&lt;p&gt;If the budget is related to Application System, it must be linked to a record in the Application System Inventory. If, at this stage, the Application System isn&#x27;t registered in the Application System Inventory, it must be considered a new system and should be added to the inventory as such. In this way, you can prevent budgeting for systems that are not in the Inventory.&lt;&#x2F;p&gt;
&lt;p&gt;Next, at the completion of the budgeting process, you verify whether some budget has been allocated to all Application Systems that are either operational or planned to be operational. You mandate budget allocation for the owners of operational application systems that are running despite not having an assigned budget.&lt;&#x2F;p&gt;
&lt;p&gt;The important point is not to require Inventory updates to maintain it, but to incorporate a mechanism in which budget processing cannot be completed without being consistent with the Inventory.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;Expenditure(Procurement)&quot;&gt;Expenditure(Procurement)&lt;&#x2F;h3&gt;
&lt;p&gt;The introduction, modification, and maintenance of Application Systems always incur expenditures. In organizations without an established IT department, these expenditures are typically processed through the procurement or accounting departments. This procurement process itself becomes the most reliable trigger for maintaining the Inventory.&lt;&#x2F;p&gt;
&lt;p&gt;Orders and contracts related to Application Systems should be
identifiable based on which budget they are tied to.&lt;&#x2F;p&gt;
&lt;p&gt;For procurements related to Application Systems,
it should be mandatory to ensure linkage and consistency
with the Application System Inventory.
This applies both at the time of ordering and at delivery.
This prevents failure patterns such as
&quot;a department independently procured a system, but it was
never added to the Inventory.&quot;&lt;&#x2F;p&gt;
&lt;p&gt;By embedding an Inventory consistency check within the
procurement process, many companies treat any procurement
that bypasses this check as a deviation—a &quot;BYPASS&quot;.
They impose penalties on the requesting department.&lt;&#x2F;p&gt;
&lt;p&gt;In the future, these checks will also function as part of
the organization&#x27;s IT Governance framework. They serve as a
review point to verify whether systems being introduced
align with the organization&#x27;s intended architecture.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;Fixed_Asset_Accounting&quot;&gt;Fixed Asset Accounting&lt;&#x2F;h3&gt;
&lt;p&gt;Application Systems developed under contract should be recorded as intangible fixed assets of the organization and are subject to depreciation. Service-based agreements such as SaaS are not capitalized as assets, but systems that are ordered and delivered must still be properly managed from an accounting perspective.&lt;&#x2F;p&gt;
&lt;p&gt;In organizations without an IT department, there is no
&quot;handover&quot; capture process. Therefore, a mechanism that links
the update of the intangible fixed asset ledger with the
Application System Inventory upon delivery is essential.
The system owner must determine whether a functional
enhancement qualifies for capitalization and request the
accounting department to update the ledger. By designing
a process that prevents acceptance until this consistency
check is completed, both ledgers are reliably updated.&lt;&#x2F;p&gt;
&lt;p&gt;This mechanism has two effects. If the organization&#x27;s accounting practices are accurate, the intangible fixed asset ledger should correctly record all systems that need to be capitalized. Maintaining consistency with this ledger enhances the reliability of the Application System Inventory. Conversely, if accounting practices are inaccurate, establishing a mechanism to ensure consistency with the Application System Inventory helps prevent improper accounting treatments.&lt;&#x2F;p&gt;
&lt;p&gt;Crucially, embedding this consistency check into the acceptance process ensures that both ledgers are maintained reliably without depending on human goodwill. When acceptance cannot be completed without this verification, the updates happen automatically as part of the standard workflow.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Conclusion&quot;&gt;Conclusion&lt;&#x2F;h2&gt;
&lt;p&gt;Organizations that have not even established an Application System Inventory, even if driven by a sense of crisis to create one, will not be able to maintain it. It is clear that it will start to decay from the moment it is created.&lt;&#x2F;p&gt;
&lt;p&gt;What matters is the mechanism to maintain it. It is important to embed the mechanism for updating and maintaining the Inventory into the unavoidable processes that accompany the flow of money: budget, procurement, and accounting.&lt;&#x2F;p&gt;
&lt;p&gt;Conversely, if you simply establish this mechanism, you can take the first step toward IT governance. It is not difficult. You just need to capture the flow of money related to systems. If you cannot even do that, your organization does not have the fundamentals of corporate governance in place even before considering IT governance—though that is likely the case.&lt;&#x2F;p&gt;
</content>
        <summary type="html">この記事はIT部門を持たず、非技術部門だけでベンダーに作らせた業務システムを所有し運用している組織について想定しています。きっとランサムウェアで危機に見舞われているアサヒビールやアスクルを見て震え上がって、何をすればいいか焦っている組織も多いと思います。そんな組織が行なうべき第一歩として業務システム台帳の整備について解説しています。</summary>
        </entry><entry xml:lang="en">
        <title>主要AI企業によるAIの理解能力喪失への警告</title>
        <published>2025-07-24T00:00:00+00:00</published>
        <updated>2025-07-24T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2025/07/ai-transparency-warning/" type="text/html"/>
        <id>https://codedchords.dev/blog/2025/07/ai-transparency-warning/</id>
        
            <content type="html">&lt;h2 id=&quot;主要AI企業による警告&quot;&gt;主要AI企業による警告&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;venturebeat.com&#x2F;&quot;&gt;VentureBeat&lt;&#x2F;a&gt;で「OpenAI, Google DeepMind and Anthropic sound alarm: &#x27;We may be losing the ability to understand AI&#x27;」&lt;sup class=&quot;footnote-reference&quot; id=&quot;fr-1-1&quot;&gt;&lt;a href=&quot;#fn-1&quot;&gt;1&lt;&#x2F;a&gt;&lt;&#x2F;sup&gt;という記事を見つけました。&lt;&#x2F;p&gt;
&lt;p&gt;内容は、OpenAI、Google DeepMind、Meta、Anthropicの40人以上の研究者が共同
で今後AIの思考を監視できなくなる可能性があるという重要な警告を発表したとい
うものです
。&lt;&#x2F;p&gt;
&lt;p&gt;現在のAIシステムは「思考の連鎖（Chain of Thought）」と呼ばれる人間が読める
言語での段階的推論過程を示すため、その思考を監視できます。しかし、この能力を
失う危険性が高まっているというのです。&lt;&#x2F;p&gt;
&lt;p&gt;通常は競合関係にある企業が団結してこの
問題に取り組んでいます。これは業界全体でこの安全性問題を深刻に受け止めている
ことを示しています。AIの透明性確保は今後の重要課題となってくると思いました
。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;どういうことなのか&quot;&gt;どういうことなのか&lt;&#x2F;h2&gt;
&lt;p&gt;現在のAIシステム（OpenAIのo1など）は複雑なタスクで「思考の連鎖（Chain of Thought）」を作業記憶として使用する必要があり、その推論過程が人間の観察者に部分的に見える状態です。これにより安全性監視が可能でした。&lt;&#x2F;p&gt;
&lt;p&gt;しかし、これが出来なくなるリスクも出てきています。その理由は次の通りです。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;これまでの言語ベースの思考でなく連続的な数学空間で推論するという新しいAIのアーキテクチャーが出てきている。これは人間からすると言語での思考を辿らず「直感」で結論に達しているようなもので、言語による思考を辿ることができない&lt;&#x2F;li&gt;
&lt;li&gt;AIが思考過程を隠ぺいする可能性がある。これは悪意でなく、以下のような理由によるものである
&lt;ul&gt;
&lt;li&gt;AIの最適化の結果、「より少ない計算リソースでより良い結果を出す」ことを評価されると推論ステップを省略し直接結論を導くことを学習してしまう可能性がある&lt;&#x2F;li&gt;
&lt;li&gt;AIの強化学習の結果、正解の提示のみが評価され「推論過程を見せること」が評価されなければ、AIは推論を隠す方向に学習する&lt;&#x2F;li&gt;
&lt;li&gt;AIが「監視されている」ことを認識すると、悪意でなく制約を避けてより自由に最適化しようとする自然な学習結果として監視を回避する&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h2 id=&quot;具体的な警告の内容&quot;&gt;具体的な警告の内容&lt;&#x2F;h2&gt;
&lt;p&gt;これだけの企業が名を連ねているので、どこぞの国の団体のように警鐘を鳴らすだけでなく、以下のようなアクションを提言しています。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;研究コミュニティへの呼びかけ
&lt;ul&gt;
&lt;li&gt;AIの「思考連鎖の監視」がAIの信頼性を担保する重要な要素だと認識し、どのような訓練プロセスが透明性を損なうか、推論の隠ぺいをどのように検出するかを緊急研究課題として取り組むべきである&lt;&#x2F;li&gt;
&lt;li&gt;思考連鎖の忠実性と解釈可能性を評価し、保持し、さらには改善する研究を推進すべきである&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;AI企業への呼びかけ
&lt;ul&gt;
&lt;li&gt;企業はモデル設計時点で監視可能性を考慮すべきである&lt;&#x2F;li&gt;
&lt;li&gt;新しい訓練手法やアーキテクチャを導入する際に、透明性への影響を事前に評価すべきである&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;政府や規制当局への呼びかけ
&lt;ul&gt;
&lt;li&gt;AI安全性において「推論過程の監視」が重要な手段であることを認識し、この能力を保護する政策を検討すべきである&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h2 id=&quot;まとめ&quot;&gt;まとめ&lt;&#x2F;h2&gt;
&lt;p&gt;日本はAIに関しては超後進国なので、この記事については「なんのことやら分からない」という企業が多いでしょう。
AIに関して無能で弛みきった日本と違い激烈な競合関係にあるこれらの企業が共同声明を出し業界全体の行動変化を求めているというのは、
&lt;strong&gt;マジで&lt;&#x2F;strong&gt;今からやらないと将来のAI安全性監視手段を失うという危機感の表れでしょう。&lt;&#x2F;p&gt;
&lt;p&gt;裏を返すと、それだけ人類と知性で肩を並べるAGI（汎用人工知能）や人類を超える知性であるASI（超人工知能）が、現実のものとして見えてきたということでしょう。&lt;&#x2F;p&gt;
&lt;p&gt;無能な人間と賢すぎるAIとどちらが危険か、私個人はそのリスクについてどっこいどっこいだと最近思い始めていたので、この記事は興味深く印象に残りました。&lt;&#x2F;p&gt;
&lt;section class=&quot;footnotes&quot;&gt;
&lt;ol class=&quot;footnotes-list&quot;&gt;
&lt;li id=&quot;fn-1&quot;&gt;
&lt;p&gt;元記事は削除または移動された可能性があります &lt;a href=&quot;#fr-1-1&quot;&gt;↩&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;&#x2F;section&gt;
</content>
        <summary type="html">OpenAI、Google DeepMind、Meta、Anthropicの研究者たちが共同で発表した、AIの思考過程の透明性が失われる危険性についての重要な警告が発信されました。無能な人間のリスクを常に懸念していた私としては、「賢すぎるAIのリスク」は興味深く印象的でした。私なりの解説をしてみました。(Researchers from OpenAI, Google DeepMind, Meta, and Anthropic jointly issued an important warning about the risk of losing transparency in AI&#x27;s thinking processes. As someone who has always been concerned about the risks of incompetent humans, I found the &quot;risks of overly intelligent AI&quot; fascinating and memorable. Here&#x27;s my personal take on this development.)</summary>
        </entry><entry xml:lang="en">
        <title>OpenAIではパスワード変更機能が提供されていない？</title>
        <published>2025-07-18T00:00:00+00:00</published>
        <updated>2025-07-18T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2025/07/openai-pwd-change/" type="text/html"/>
        <id>https://codedchords.dev/blog/2025/07/openai-pwd-change/</id>
        
            <content type="html">&lt;p&gt;最近はずっとClaudeを利用していてChatGPT&#x2F;OpenAIはご無沙汰しています。
しかし、なぜかパスワードマネージャーからOpenAIのパスワードが使い回しという警告が出てしまったので、パスワードを変更することにしました。&lt;&#x2F;p&gt;
&lt;p&gt;しかし、ここで気付いたのです。パスワード変更機能が提供されていないということ
に。&lt;&#x2F;p&gt;
&lt;p&gt;以下は、OpenAIアカウントのセキュリティ設定画面です。&lt;&#x2F;p&gt;
&lt;!-- textlint-disable --&gt;
&lt;img
  src=&quot;https:&amp;#x2F;&amp;#x2F;codedchords.dev&amp;#x2F;blog&amp;#x2F;2025&amp;#x2F;07&amp;#x2F;openai-pwd-change&amp;#x2F;openai-security.webp?h=1085a55696bd1ffef545&quot;
  alt=&quot;セキュリティ設定画面&quot; width=&quot;680&quot; height=&quot;598&quot; loading=&quot;lazy&quot;
&#x2F;&gt;&lt;!-- textlint-enable --&gt;
&lt;p&gt;多要素認証の設定しかありません。&lt;&#x2F;p&gt;
</content>
        <summary type="html">OpenAIでパスワードを変更しようとして、パスワード変更機能が提供されていないことに気付きました。</summary>
        </entry><entry xml:lang="en">
        <title>Anthropic MCP Inspectorに重大な脆弱性</title>
        <published>2025-07-02T00:00:00+00:00</published>
        <updated>2025-07-02T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2025/07/anthropic-mcp-inspector-vulnerability/" type="text/html"/>
        <id>https://codedchords.dev/blog/2025/07/anthropic-mcp-inspector-vulnerability/</id>
        
            <content type="html">&lt;details&gt;
&lt;summary&gt;Table of Contents&lt;&#x2F;summary&gt;
&lt;!-- toc --&gt;
&lt;&#x2F;details&gt;
&lt;p&gt;開発者向けツールとはいえ、CVSSスコア9.4という深刻度の高さに、セキュリティ対策の重要性を改めて認識させられました。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;はじめに&quot;&gt;はじめに&lt;&#x2F;h2&gt;
&lt;p&gt;jrnlのジャーナルにClaude Desktopなどからアクセスを可能とするMCPサーバーを開発中で、
統合テスト時にドライバーを探していてMCP Inspectorを検討していたところ、脆弱性の報告があり驚きました。
開発者向けツールとはいえ、CVSSスコア9.4という深刻度の高さに、セキュリティ対策の重要性を改めて認識しました。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;MCP_Inspector_とは何？&quot;&gt;MCP Inspector とは何？&lt;&#x2F;h2&gt;
&lt;p&gt;MCP Inspectorは、Anthropicが提供するModel Context Protocol (MCP) サーバーのテスト・デバッグツールです。MCPは2024年11月に発表された、LLMアプリケーションと外部データソースやツールとの連携を標準化するオープンプロトコルです。&lt;&#x2F;p&gt;
&lt;p&gt;MCP Inspectorは主に以下のような場面で使用されます。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;MCPサーバー開発者が実装の動作確認を行う際&lt;&#x2F;li&gt;
&lt;li&gt;API統合のデバッグやトラブルシューティング時&lt;&#x2F;li&gt;
&lt;li&gt;本番環境へのデプロイ前の検証作業&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;ツールはWeb UIを提供するクライアントと、各種MCPサーバーへの接続を仲介するプロキシサーバーで構成されています。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;MCP_Inspector_の脆弱性とは&quot;&gt;MCP Inspector の脆弱性とは&lt;&#x2F;h2&gt;
&lt;p&gt;2025年7月に報告された脆弱性CVE-2025-49596は、悪意のあるWebサイトにアクセスするだけでリモートコード実行を可能にする重大な問題です。&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;thehackernews.com&#x2F;2025&#x2F;07&#x2F;critical-vulnerability-in-anthropics.html&quot;&gt;元記事：Critical Vulnerability in Anthropic&#x27;s MCP Exposes Developer Machines to Remote Exploits&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;攻撃手法は以下の要素を組み合わせたものです。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;19年前から存在するブラウザの脆弱性「0.0.0.0 Day」を利用&lt;&#x2F;li&gt;
&lt;li&gt;MCP InspectorのCSRF脆弱性と連鎖させる&lt;&#x2F;li&gt;
&lt;li&gt;localhostで動作するサービスへ不正なリクエストを送信&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;根本原因はデフォルト設定における認証と暗号化の欠如でした。プロキシサーバーが0.0.0.0でリッスンし、クライアントとの間に認証機構がなかったため、任意のコマンド実行が可能となっていました。&lt;&#x2F;p&gt;
&lt;p&gt;影響範囲はMCP Inspectorを使用している開発者に限定されます。一般のMCPユーザーや本番環境のMCPサーバーには直接影響しません。ただし、攻撃を受けた開発者のマシンから機密情報が漏洩したり、ネットワーク内への侵入経路として悪用される可能性があります。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;まとめ&quot;&gt;まとめ&lt;&#x2F;h2&gt;
&lt;p&gt;この脆弱性は2025年6月13日にリリースされたバージョン0.14.1で修正されています。MCP Inspectorを使用している開発者は直ちにアップデートすることを推奨します。&lt;&#x2F;p&gt;
&lt;p&gt;開発ツールであっても適切なセキュリティ対策が必要であることを示す事例となりました。
特にlocalhostで動作するサービスも攻撃対象となりうることを認識し、
開発環境のセキュリティにも十分な注意を払う必要があると肝に銘じました。&lt;&#x2F;p&gt;
</content>
        <summary type="html">開発者向けツールとはいえ、CVSS スコア 9.4 という深刻度の高さに、セキュリティ対策の重要性を改めて認識させられました。</summary>
        </entry><entry xml:lang="en">
        <title>Webサイト脆弱性スキャン入門：NucleiとKatanaで始めるセキュリティチェック</title>
        <published>2025-06-04T00:00:00+00:00</published>
        <updated>2025-06-04T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2025/06/vulnerability-check/" type="text/html"/>
        <id>https://codedchords.dev/blog/2025/06/vulnerability-check/</id>
        
            <content type="html">&lt;details&gt;
&lt;summary&gt;Table of Contents&lt;&#x2F;summary&gt;
&lt;!-- toc --&gt;
&lt;&#x2F;details&gt;
ebサイトのセキュリティが気になるけど、専門的な知識がなくて何から始めればいいか分からない...そんなIT技術者の方に向けて、オープンソースのツールを使った脆弱性スキャンの方法をご紹介します。今回は「Nuclei」と「Katana」という2つのツールを組み合わせて、効率的にWebサイトの脆弱性をチェックする方法を解説していきます。
&lt;h2 id=&quot;1._NucleiとKatanaとは？&quot;&gt;1. NucleiとKatanaとは？&lt;&#x2F;h2&gt;
&lt;p&gt;NucleiはProjectDiscoveryが開発したオープンソースの脆弱性スキャナーです。最大の特徴は以下の通りです。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;テンプレートベース&lt;&#x2F;strong&gt;：YAML形式のテンプレートで脆弱性パターンを定義&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;コミュニティ駆動&lt;&#x2F;strong&gt;：世界中のセキュリティ研究者が3000以上のテンプレートを提供&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;高速処理&lt;&#x2F;strong&gt;：並列処理による効率的なスキャン&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;低い誤検出率&lt;&#x2F;strong&gt;：実際の脆弱性を模擬したテストで精度が高い&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;多様な対応&lt;&#x2F;strong&gt;：CVE、設定ミス、情報漏洩など幅広い脆弱性に対応&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;KatanaもProjectDiscoveryが開発したWebクローラーです。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;高速クロール&lt;&#x2F;strong&gt;：Go言語で開発された軽量高速なクローラー&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;JavaScript対応&lt;&#x2F;strong&gt;：SPA（Single Page Application）も適切にクロール&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;設定柔軟&lt;&#x2F;strong&gt;：クロール深度や対象範囲を細かく制御可能&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;Nuclei連携&lt;&#x2F;strong&gt;：同じ開発元のため、Nucleiとの相性が抜群&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;両者ともProjectDiscoveryが開発したツールですが、この組み合わせが良い理由は次
の通りです。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Katanaでサイト全体のURLを収集&lt;&#x2F;li&gt;
&lt;li&gt;NucleiでそれらのURLに対して脆弱性をチェック&lt;&#x2F;li&gt;
&lt;li&gt;両ツールとも同じ開発元なので連携がスムーズ&lt;&#x2F;li&gt;
&lt;li&gt;オープンソースなので無料で利用可能&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h2 id=&quot;2._インストール方法&quot;&gt;2. インストール方法&lt;&#x2F;h2&gt;
&lt;p&gt;前提条件は次の通りです。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;macOS&lt;&#x2F;li&gt;
&lt;li&gt;Homebrew（未インストールの場合は&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;brew.sh&#x2F;ja&#x2F;&quot;&gt;公式サイト&lt;&#x2F;a&gt;からインストール）&lt;&#x2F;li&gt;
&lt;li&gt;Go言語環境（&lt;code&gt;brew install go&lt;&#x2F;code&gt;でインストール可能）&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;インストール手順は以下の通りです。
初回実行時にNucleiが自動的にテンプレートをダウンロードします。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# Homebrewを使用（推奨）&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;brew&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; install nuclei&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# インストール確認&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -version&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# Go言語でインストール&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;go&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; install github.com&#x2F;projectdiscovery&#x2F;katana&#x2F;cmd&#x2F;katana@latest&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# インストール確認&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;katana&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -version&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# テンプレートの手動更新（定期的に実行推奨）&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -update-templates&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h2 id=&quot;3._実行方法と結果の確認&quot;&gt;3. 実行方法と結果の確認&lt;&#x2F;h2&gt;
&lt;p&gt;最もシンプルな使い方から始めましょう。単一のURLを検査する方法です。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 基本的なスキャン&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -u https:&#x2F;&#x2F;example.com -o results.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 重要度の高い脆弱性のみチェック&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -u https:&#x2F;&#x2F;example.com -s critical,high,medium -o important_vulns.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;サイト全体をチェックしたい場合は、次のような手順となります。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 1. Katanaでサイト全体をクロール&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;katana&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -u https:&#x2F;&#x2F;example.com -d&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 2&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -o urls.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 2. 不要なファイルを除外&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;grep&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt; -v -E &amp;#39;\.(jpg|jpeg|png|gif|css|js|ico)$&amp;#39; urls.txt&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; &amp;gt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; filtered_urls.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 3. Nucleiで脆弱性スキャン&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l filtered_urls.txt -s critical,high,medium -o vulnerability_report.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;脆弱性が発見されなければ何も出力されません。
脆弱性が発見された場合は発見された内容が出力されていますので、以下のように
確認できます。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 発見された脆弱性の数&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l vulnerability_report.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 脆弱性の内容確認&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;cat&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; vulnerability_report.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 重要度別の集計&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;cat&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; vulnerability_report.txt&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; grep&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt; -oE &amp;#39;\[(critical|high|medium|low)\]&amp;#39;&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; sort&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; uniq&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -c&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h2 id=&quot;4._どのような検証がなされているか確認する方法&quot;&gt;4. どのような検証がなされているか確認する方法&lt;&#x2F;h2&gt;
&lt;p&gt;仕事などで脆弱性検証する場合、「で、一体何が検証されたん？」と聞かれること
もあると思います。3,000以上のテンプレートを使用しているので、簡単にどんなテ
ンプレートが使用されているか把握する方法です。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 全テンプレート数&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# カテゴリ別のテンプレート数&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;CVE脆弱性: &lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -tags cve&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;情報漏洩: &lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -tags exposure&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;設定ミス: &lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -tags misconfig&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;XSS: &lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -tags xss&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;LFI: &lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -tags lfi&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;管理画面: &lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -tags panel&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;技術スタック: &lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -tags tech&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;情報収集: &lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -tags osint&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 重要度で判別&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -s critical&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;     # 1321件&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -s high&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;         # 2377件&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -s medium&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;       # 2322件&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -s low&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;          # 316件&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -s info&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;         # 4086件&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;脆弱性が発見された場合は、以下のように詳細ログを確認しましょう。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 詳細ログ付きで実行&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -u https:&#x2F;&#x2F;example.com -v -o results.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 特定カテゴリのテンプレート一覧&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -tl -tags cve&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; head&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -10&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h3 id=&quot;CVE（Common_Vulnerabilities_and_Exposures）について&quot;&gt;CVE（Common Vulnerabilities and Exposures）について&lt;&#x2F;h3&gt;
&lt;p&gt;CVEは世界共通のセキュリティ脆弱性カタログです。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;命名規則&lt;&#x2F;strong&gt;：CVE-YYYY-NNNNN（年-通し番号）&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;例&lt;&#x2F;strong&gt;：CVE-2021-44228（Log4jの重大な脆弱性）&lt;&#x2F;li&gt;
&lt;li&gt;Nucleiは3000以上のCVEに対応したテンプレートを保有&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h2 id=&quot;5._実践的な使い分け&quot;&gt;5. 実践的な使い分け&lt;&#x2F;h2&gt;
&lt;p&gt;実践的な使い方をまとめてみしょう。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# クイックチェック（30秒以内）&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -u https:&#x2F;&#x2F;example.com -t exposures&#x2F; -s critical,high&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# バランス型チェック（1-2分）&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -u https:&#x2F;&#x2F;example.com -t cves&#x2F;,exposures&#x2F; -s medium,high,critical&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 徹底スキャン（5-10分） - 新サイトの評価など&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;katana&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -u https:&#x2F;&#x2F;example.com -d&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 2&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; |&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt; nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -s critical,high,medium&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;テンプレート選択は以下のような指針で運用するとよいと思います。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;初回チェック&lt;&#x2F;strong&gt;：&lt;code&gt;cves&#x2F;,exposures&#x2F;&lt;&#x2F;code&gt;（CVEと情報漏洩）&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;定期チェック&lt;&#x2F;strong&gt;：&lt;code&gt;-s critical,high&lt;&#x2F;code&gt;（重要度の高いもののみ）&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;詳細調査&lt;&#x2F;strong&gt;：全テンプレート使用&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h2 id=&quot;6._パフォーマンス最適化&quot;&gt;6. パフォーマンス最適化&lt;&#x2F;h2&gt;
&lt;p&gt;脆弱性の検証自体は結構重たい処理なってしまうので、パフォーマンスが問題となる
場合は、以下のような並行度やレート制限を調整しましょう。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 並列度とレート制限の調整&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -u https:&#x2F;&#x2F;example.com -c&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 50&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -rl&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 100&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -timeout&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 5&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# バッチ処理での最適化&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l urls.txt -c&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 25&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -rl&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 50&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -bulk-size&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 25&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;-c 50&lt;&#x2F;strong&gt;：同時実行テンプレート数を50に設定&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;-rl 100&lt;&#x2F;strong&gt;：1秒間に100リクエストまで&lt;&#x2F;li&gt;
&lt;li&gt;&lt;strong&gt;-timeout 5&lt;&#x2F;strong&gt;：タイムアウトを5秒に短縮&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h2 id=&quot;7._セキュリティ向上のための継続的運用&quot;&gt;7. セキュリティ向上のための継続的運用&lt;&#x2F;h2&gt;
&lt;p&gt;継続的に運用するために、次のようなスクリプトを組んでcronなどで自動運用する
方法もよいと思います。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-shebang z-shell z-meta z-shebang z-shell&quot;&gt;#!&#x2F;bin&#x2F;bash&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# daily_security_check.sh&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-source&quot;&gt;TARGET&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt;=&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt;&amp;quot;https:&#x2F;&#x2F;your-website.com&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-source&quot;&gt;DATE&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt;=&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;date&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; +%Y%m%d&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-source&quot;&gt;OUTPUT_DIR&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt;=&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt;&amp;quot;security_scans&#x2F;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$DATE&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 金曜日（5）かチェック&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-keyword&quot;&gt;if&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt; [ $(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;date&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; +%u&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; -eq&lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt; 5&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt; ];&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword&quot;&gt; then&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;    echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;金曜日なので、テンプレートを更新します...&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;    nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -update-templates&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-keyword&quot;&gt;fi&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;mkdir&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt; -p &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT_DIR&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 高優先度の脆弱性をチェック&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt; -u &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$TARGET&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt;&amp;quot; -s critical,high -o &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT_DIR&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt;&#x2F;critical_scan.txt&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 結果をメール送信（お好みで）&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-keyword&quot;&gt;if&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt; [&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; -s&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT_DIR&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt;&#x2F;critical_scan.txt&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt; ];&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword&quot;&gt; then&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;    mail&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt; -s &amp;quot;セキュリティアラート: &lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$TARGET&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt;&amp;quot; admin@company.com&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; &amp;lt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT_DIR&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt;&#x2F;critical_scan.txt&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-keyword&quot;&gt;fi&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h2 id=&quot;8._他ツールとの連携例&quot;&gt;8. 他ツールとの連携例&lt;&#x2F;h2&gt;
&lt;p&gt;Webサイトが静的サイトジェネレーターなどで組まれている場合は、
サイト生成のCI&#x2F;CDパイプラインに脆弱性検証を組み込むという手もあります。&lt;&#x2F;p&gt;
&lt;p&gt;以下は、GitHub Actionsの例です。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;yaml&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# GitHub Actions例&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;name&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; Security Scan&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-constant z-language z-boolean&quot;&gt;on&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;  schedule&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation&quot;&gt;    -&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt; cron&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;0 9 * * 1&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt; # 毎週月曜日9時&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;jobs&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;  security-scan&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;    runs-on&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; ubuntu-latest&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;    steps&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation&quot;&gt;      -&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt; uses&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; actions&#x2F;checkout@v2&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation&quot;&gt;      -&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt; name&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; Install Nuclei&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;        run&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword&quot;&gt; |&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-string&quot;&gt;          go install github.com&#x2F;projectdiscovery&#x2F;nuclei&#x2F;v3&#x2F;cmd&#x2F;nuclei@latest&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation&quot;&gt;      -&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt; name&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; Run Security Scan&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;        run&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword&quot;&gt; |&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-string&quot;&gt;          nuclei -u ${{ secrets.TARGET_URL }} -s critical,high -o scan_results.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation&quot;&gt;      -&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt; name&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; Upload Results&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;        uses&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; actions&#x2F;upload-artifact@v2&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;        with&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;          name&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; security-scan-results&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-tag z-yaml&quot;&gt;          path&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-separator z-key-value&quot;&gt;:&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; scan_results.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;また、レポート生成の自動化、定期的な処理などの最後にレポート出力を組み込んで
も良いと思います。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 簡単なサマリーレポート生成&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;generate_security_report&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;() {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-source&quot;&gt;    TARGET&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt;=&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-parameter&quot;&gt;$1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-source&quot;&gt;    OUTPUT&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt;=&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt;&amp;quot;security_report_&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;date&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; +%Y%m%d&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt;.txt&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;    echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;=== セキュリティスキャンレポート ===&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; &amp;gt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;    echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;対象サイト: &lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$TARGET&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; &amp;gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;    echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;スキャン日時: &lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;date&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; &amp;gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;    echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; &amp;gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;    # スキャン実行&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;    nuclei&lt;&#x2F;span&gt;&lt;span class=&quot;z-string z-punctuation z-definition z-string&quot;&gt; -u &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$TARGET&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt;&amp;quot; -s critical,high,medium -o temp_results.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;    echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;発見された脆弱性数: &lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;$(&lt;&#x2F;span&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;wc&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; -l&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; &amp;lt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; temp_results.txt&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation&quot;&gt;)&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; &amp;gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;    echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; &amp;gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;    echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;詳細結果:&amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; &amp;gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;    cat&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; temp_results.txt&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-operator&quot;&gt; &amp;gt;&amp;gt;&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;    rm&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; temp_results.txt&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-support z-function z-builtin&quot;&gt;    echo&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;レポートを生成しました: &lt;&#x2F;span&gt;&lt;span class=&quot;z-variable z-other z-normal z-shell&quot;&gt;$OUTPUT&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation&quot;&gt;}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# 使用例&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;generate_security_report&lt;&#x2F;span&gt;&lt;span class=&quot;z-punctuation z-definition z-string z-string&quot;&gt; &amp;quot;https:&#x2F;&#x2F;example.com&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h2 id=&quot;⚠️_重要：責任ある使用のための注意事項&quot;&gt;⚠️ 重要：責任ある使用のための注意事項&lt;&#x2F;h2&gt;
&lt;p&gt;脆弱性の検証はサーバーに非常に負荷をかけるため、
不正アクセス禁止法、電子計算機損壊等業務妨害罪、偽計業務妨害罪
などに抵触し違法行為になる可能性があります。&lt;&#x2F;p&gt;
&lt;p&gt;必ず以下を遵守しましょう。&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;所有権の確認&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;自分が所有するサイトのみスキャンしてください&lt;&#x2F;li&gt;
&lt;li&gt;他者のサイトには必ず事前許可を取得してください&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;適切な負荷制御&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;本番サイトへの負荷を考慮してレート制限を設定&lt;&#x2F;li&gt;
&lt;li&gt;業務時間外でのスキャン実施を推奨&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;結果の適切な管理&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;スキャン結果に機密情報が含まれる可能性あり&lt;&#x2F;li&gt;
&lt;li&gt;結果ファイルの保存場所とアクセス権限に注意&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;h3 id=&quot;なぜ偽計業務妨害罪となる可能性があるか&quot;&gt;なぜ偽計業務妨害罪となる可能性があるか&lt;&#x2F;h3&gt;
&lt;p&gt;偽計業務妨害罪（刑法233条）の要件は、以下の3つです。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;偽計：虚偽の情報や人を欺く行為&lt;&#x2F;li&gt;
&lt;li&gt;業務妨害：他人の業務を妨害すること&lt;&#x2F;li&gt;
&lt;li&gt;故意：妨害する意図があること&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;脆弱性検査はサーバーに非常に負荷を掛ける処理であることは知られているので、
業務妨害と故意であることは分かりやすいと思います。&lt;&#x2F;p&gt;
&lt;p&gt;「偽計」については、脆弱性スキャンはブラウザの正常なアクセスを装って
リクエストヘッダを偽装しつつ「負荷」という観点では攻撃的とも言えるペイロード
を送信するため「偽計」と見なされる可能性があります。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;まとめ&quot;&gt;まとめ&lt;&#x2F;h2&gt;
&lt;p&gt;NucleiとKatanaを使った脆弱性スキャンは、以下のような方に特におすすめです。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;自社サイトのセキュリティ状況を定期的にチェックしたい&lt;&#x2F;li&gt;
&lt;li&gt;オープンソースツールでコストを抑えたい&lt;&#x2F;li&gt;
&lt;li&gt;コマンドラインツールに慣れている&lt;&#x2F;li&gt;
&lt;li&gt;セキュリティの基本的な知識を実践で学びたい&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;最初は単一URLの簡単なチェックから始めて、慣れてきたらサイト全体のスキャンや自動化に挑戦してみてください。重要なのは継続的にセキュリティをチェックする習慣を作ることです。&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;脆弱性が見つからない結果も良い結果&lt;&#x2F;strong&gt;です。むしろサイトが適切にメンテナンスされている証拠として安心できる材料になります。&lt;&#x2F;p&gt;
&lt;p&gt;セキュリティは一度設定すれば終わりではなく、継続的な取り組みが重要です。このツールを活用して、より安全なWebサイト運営を目指しましょう。&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;p&gt;&lt;strong&gt;参考リンク&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;docs.projectdiscovery.io&#x2F;opensource&#x2F;nuclei&#x2F;overview&quot;&gt;Nuclei公式ドキュメント&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;projectdiscovery&#x2F;katana&quot;&gt;Katana公式リポジトリ&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;projectdiscovery.io&#x2F;&quot;&gt;ProjectDiscovery&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;&lt;strong&gt;注意&lt;&#x2F;strong&gt;：この記事の内容は啓蒙目的であり、適切な許可なく他者のシステムをスキャンすることは違法行為となる可能性があります。必ず責任を持って使用してください。&lt;&#x2F;p&gt;
</content>
        <summary type="html">ebサイトのセキュリティが気になるけど、専門的な知識がなくて何から始めればいいか分からない...そんなIT技術者の方に向けて、オープンソースのツールを使った脆弱性スキャンの方法をご紹介します。今回は「Nuclei」と「Katana」という2つのツールを組み合わせて、効率的にWebサイトの脆弱性をチェックする方法を解説していきます。</summary>
        </entry><entry xml:lang="en">
        <title>Authorization Bypass in Next.js Middleware</title>
        <published>2025-03-22T00:00:00+00:00</published>
        <updated>2025-03-22T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2025/03/cve-2025-29927/" type="text/html"/>
        <id>https://codedchords.dev/blog/2025/03/cve-2025-29927/</id>
        
            <content type="html">&lt;h2 id=&quot;CVE情報&quot;&gt;CVE情報&lt;&#x2F;h2&gt;
&lt;ul&gt;
&lt;li&gt;CVE番号: CVE-2025-29927&lt;&#x2F;li&gt;
&lt;li&gt;GHSAコード: GHSA-f82v-jwr5-mffw&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;攻撃者が特定のHTTPヘッダーを操作することで、ミドルウェアの認証チェックを迂回
し、保護されたリソースにアクセスできてしまう問題のようです。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;アップデート手順&quot;&gt;アップデート手順&lt;&#x2F;h2&gt;
&lt;p&gt;アップデートの手順は次の通りです。&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# Next.jsのアップデート&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;npm&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; install next@15.2.3 @next&#x2F;mdx@15.2.3 eslint-config-next@15.2.3&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# npx next updateでもいいか。&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-punctuation z-definition z-comment z-comment&quot;&gt;# アップデート後問題ないか、一応Lintをかけておく&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span class=&quot;z-entity z-name z-function&quot;&gt;npm&lt;&#x2F;span&gt;&lt;span class=&quot;z-string&quot;&gt; run lint&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;</content>
        <summary type="html">Next.js 15.2.3未満で認証をバイパスできる脆弱性の通知がGitHubから飛んできたので、一応このブログもアップデートしました。</summary>
        </entry><entry xml:lang="en">
        <title>大阪万博 EXPO 2025の個人情報取扱問題</title>
        <published>2025-02-14T00:00:00+00:00</published>
        <updated>2025-02-14T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2025/02/expo-problem/" type="text/html"/>
        <id>https://codedchords.dev/blog/2025/02/expo-problem/</id>
        
            <content type="html">&lt;p&gt;2025年2月8日の読売新聞で「万博チケット購入で『顔画像や指紋など第三者に提供も』、個人情報規約にSNS上『ヤバすぎる』…協会が修正検討」との記事が配信されて結構騒ぎになっています。&lt;&#x2F;p&gt;
&lt;p&gt;もともとはSNSでちょっと炎上していて、2025年2月5日の
&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.shugiintv.go.jp&#x2F;jp&#x2F;index.php?ex=VL&amp;amp;media_type=&amp;amp;deli_id=55503&amp;amp;time=28896.3&quot;&gt;衆議院予算委員会&lt;&#x2F;a&gt;で
れいわ新撰組の大石あきこ議員が個人情報の取られ方が異常であることを指摘し、その用途を確認するも、伊東良孝万博担当相の回答は不明瞭で更に不安になりました。&lt;&#x2F;p&gt;
&lt;p&gt;不安だったので、ソースである「
&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.expo2025.or.jp&#x2F;privacy&#x2F;&quot;&gt;EXPO 2025 個人情報保護方針&lt;&#x2F;a&gt;
」を確認してみました。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;万博がユーザーが取得する個人情報&quot;&gt;万博がユーザーが取得する個人情報&lt;&#x2F;h2&gt;
&lt;p&gt;どんな情報が抜かれるのか、確認してみました。&lt;&#x2F;p&gt;
&lt;p&gt;まずはここでいう「ユーザー」とは、次の方が対象となっています。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;ウェブサイト及びアプリケーションの利用者&lt;&#x2F;li&gt;
&lt;li&gt;ボランティアスタッフ&lt;&#x2F;li&gt;
&lt;li&gt;スリーランスの演者&lt;&#x2F;li&gt;
&lt;li&gt;ジャーナリスト&lt;&#x2F;li&gt;
&lt;li&gt;博覧会に個人として参加・関与する人&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;利用者とスタッフを同列として扱う雑さにまず驚きます。&lt;&#x2F;p&gt;
&lt;p&gt;それはさておき、万博が取得するとしている個人情報を以下にまとめました。&lt;&#x2F;p&gt;
&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th className=&quot;w-1&#x2F;5&quot;&gt;カテゴリー&lt;&#x2F;th&gt;
      &lt;th className=&quot;w-4&#x2F;5&quot;&gt;具体的な個人情報&lt;&#x2F;th&gt;
    &lt;&#x2F;tr&gt;
  &lt;&#x2F;thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;基本情報&lt;&#x2F;td&gt;
      &lt;td&gt;
        氏名、ニックネーム、性別、生年月日、住所（郵便番号、都道府県名、市町村）、電話番号、メールアドレス、
        パスポート番号、国籍または居住国に関する情報
      &lt;&#x2F;td&gt;
    &lt;&#x2F;tr&gt;
    &lt;tr&gt;
      &lt;td&gt;支払い情報&lt;&#x2F;td&gt;
      &lt;td&gt;クレジットカード番号等&lt;&#x2F;td&gt;
    &lt;&#x2F;tr&gt;
    &lt;tr&gt;
      &lt;td&gt;位置情報&lt;&#x2F;td&gt;
      &lt;td&gt;GPS や位置情報&lt;&#x2F;td&gt;
    &lt;&#x2F;tr&gt;
    &lt;tr&gt;
      &lt;td&gt;生体情報&lt;&#x2F;td&gt;
      &lt;td&gt;顔画像、音声、指紋等&lt;&#x2F;td&gt;
    &lt;&#x2F;tr&gt;
    &lt;tr&gt;
      &lt;td&gt;所属先情報&lt;&#x2F;td&gt;
      &lt;td&gt;企業名、団体名、部署名、役職等&lt;&#x2F;td&gt;
    &lt;&#x2F;tr&gt;
    &lt;tr&gt;
      &lt;td&gt;医療情報&lt;&#x2F;td&gt;
      &lt;td&gt;障がい者認定の有無等&lt;&#x2F;td&gt;
    &lt;&#x2F;tr&gt;
    &lt;tr&gt;
      &lt;td&gt;SNS 情報&lt;&#x2F;td&gt;
      &lt;td&gt;
        LINE、X、Facebook、Instagram、Google 等のアカウントやプロフィール、
        パスワード等
      &lt;&#x2F;td&gt;
    &lt;&#x2F;tr&gt;
    &lt;tr&gt;
      &lt;td&gt;入力情報&lt;&#x2F;td&gt;
      &lt;td&gt;
        言語設定、メール配信設定、既婚・未婚、子どもの有無、趣味嗜好等のユーザー入力情報
      &lt;&#x2F;td&gt;
    &lt;&#x2F;tr&gt;
    &lt;tr&gt;
      &lt;td&gt;端末情報&lt;&#x2F;td&gt;
      &lt;td&gt;
        端末の種類、OS、端末識別子、IP
        アドレス、ブラウザ種別、リファラー情報、Cookie ID、閲覧履歴等
      &lt;&#x2F;td&gt;
    &lt;&#x2F;tr&gt;
  &lt;&#x2F;tbody&gt;
&lt;&#x2F;table&gt;
&lt;p&gt;赤字は特にヤバいものです。
個人情報の中でもここまでの機微情報を扱うというのはほとんど見たことがありません。
個人情報(PII - Personal Identifiable Information)の中でもSPI(Sensitive Personal Information)と呼ばれるものです。&lt;&#x2F;p&gt;
&lt;p&gt;例えば「生体認証」の顔画像です。本人確認に使うとしましょう。
通常、顔画像について特徴点を数値化したテンプレート化という処理が行われます。以下はその例です。&lt;&#x2F;p&gt;
&lt;pre&gt;
  FPT10000001401ba01980159020118016800d601
  015f018600ff01017201d9016502005b004300eb
  02005100dc007001014f001400c40200d8016f00
  2b0200ed0058013b0100aa017d00660101e9005c
  00ee0200980146001a0100d10187013a0100f400
  4d01530200a0010b00ca02011c017d016101013a
  009a00e302005e00f600060100e700bb00630200 20009d008d02
&lt;&#x2F;pre&gt;
&lt;p&gt;この数値したテンプレートをハッシュ値という不可逆の数値に要約します。
上のハッシュ値の例では&lt;code&gt;8a3a0681&lt;&#x2F;code&gt;となります。認証する場合でもサーバー側が持つのはこのハッシュ値だけです。
ここから顔画像の再製はできません。実際の認証の際には例えばスマホで顔画像について上記の処理が行われてハッシュ値だけがサーバーに送られて、サーバー側のハッシュ値と突合して本人かどうか確認されます。&lt;&#x2F;p&gt;
&lt;p&gt;つまり、指紋や顔の生体認証でさえ、顔や指紋画像を収集することはありません。&lt;&#x2F;p&gt;
&lt;p&gt;ところがEXPO2025の個人情報保護方針では「生体情報：指紋、顔など」と記載しています。ヤバさすぎます。&lt;&#x2F;p&gt;
&lt;p&gt;このような情報は保護対策が非常にコストが掛かり、
漏えい時リスクも跳ね上がるのでシステム屋としては可能な限り対象から外します。
どうしても外せない場合はそのリスク査定してContengencyとして開発費の上乗せしますが、
お客への提示前にかなり社内レビューでのハードルが高くなります。
案件のリスクが高すぎて、提案の是非にまで問われるのが普通です。&lt;&#x2F;p&gt;
&lt;p&gt;なので、たかが &lt;strong&gt;万博を物見遊山で見に来る利用者に対して、ここまでSPIを要求するというのは正直「主催者は頭がおかしいのか？」&lt;&#x2F;strong&gt; と疑いたくなります。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;個人情報の提供先&quot;&gt;個人情報の提供先&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.expo2025.or.jp&#x2F;privacy&#x2F;&quot;&gt;EXPO 2025 個人情報保護方針&lt;&#x2F;a&gt;
では第三者への提供について次のように定めています。&lt;&#x2F;p&gt;
&lt;p&gt;事前同意が必要なケースとして、次のものです。&lt;&#x2F;p&gt;
&lt;blockquote cite=&quot;https:&#x2F;&#x2F;www.expo2025.or.jp&#x2F;privacy&#x2F;&quot; className=&quot;text-xs&quot;&gt;
  &lt;ol&gt;
    &lt;li&gt;
      当協会が利用目的の達成に必要な範囲内において個人情報の取り扱いの全部又は一部を委託する場合
    &lt;&#x2F;li&gt;
    &lt;li&gt;②合併その他の事由による事業の承継に伴って個人情報が提供される場合&lt;&#x2F;li&gt;
    &lt;li&gt;
      人の生命、身体又は財産の保護のために必要がある場合であって、ユーザー本人の同意を得ることが困難であるとき
    &lt;&#x2F;li&gt;
    &lt;li&gt;
      公衆衛生の向上又は児童の健全な育成の推進のために特に必要がある場合であって、ユーザー本人の同意を得ることが困難であるとき
    &lt;&#x2F;li&gt;
    &lt;li&gt;
      国の機関若しくは地方公共団体又はその委託を受けた者が法令の定める事務を遂行することに対して協力する必要がある場合であって、ユーザー本人の同意を得ることによって当該事務の遂行に支障を及ぼすおそれがある場合
    &lt;&#x2F;li&gt;
    &lt;li&gt;
      当該第三者が学術研究機関等である場合であって、当該第三者が当該個人情報を学術研究目的で取り扱う必要があるとき（当該個人情報を取り扱う目的の一部が学術研究目的である場合を含み、個人の権利利益を不当に侵害するおそれがある場合を除きます。）
    &lt;&#x2F;li&gt;
    &lt;li&gt;その他、個人情報保護法その他の法令で認められる場合&lt;&#x2F;li&gt;
  &lt;&#x2F;ol&gt;
  &lt;cite&gt;
    &lt;a href=&quot;https:&#x2F;&#x2F;www.expo2025.or.jp&#x2F;privacy&#x2F;&quot;&gt;EXPO 2025 個人情報保護方針&lt;&#x2F;a&gt;
    より
  &lt;&#x2F;cite&gt;
&lt;&#x2F;blockquote&gt;
&lt;p&gt;ただ、「事前同意」が何か不明で、万博ID作成時の同意がそれに当たるのかよく分かりません。&lt;&#x2F;p&gt;
&lt;p&gt;驚くことに、事前同意なしで提供するケースも記載されています。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;政府(外国政府や地方地自体も含む)、博覧会国際事務局、協賛企業、パビリオン出展者&lt;&#x2F;li&gt;
&lt;li&gt;SNS事業者、広告関係会社、広告配信業者、データ分析事業者、DMP事業者、媒体社、その他当協会が業務を提携事業者&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;これって、&lt;strong&gt;事実上誰にでも個人情報提供する&lt;&#x2F;strong&gt;という宣言以外に、私には読めません。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;万博側の主張&quot;&gt;万博側の主張&lt;&#x2F;h2&gt;
&lt;p&gt;2月5日の予算委委員会での経済産業省首席国際博覧会統括調整官 &lt;strong&gt;茂木 正氏&lt;&#x2F;strong&gt;の回答は、次のようなものでした。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;万博ID取得に必要な情報は氏名、生年月日、電話番号、メールアドレス、居住国のみである。&lt;&#x2F;li&gt;
&lt;li&gt;会場で勤務する国内外のスタッフや関係者を含めたID登録を想定し包括的に規定したためである。&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;アホなのにか？&lt;&#x2F;p&gt;
&lt;p&gt;まず利用者とスタッフなど運営側のユーザーの個人情報取り扱いを包括的に定義するなど信じられません。&lt;&#x2F;p&gt;
&lt;p&gt;「個人情報の保護に関する法律(個人情報保護法)」の&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;laws.e-gov.go.jp&#x2F;law&#x2F;415AC0000000057&#x2F;#Mp-Ch_4-Se_2-At_17&quot;&gt;第十七条&lt;&#x2F;a&gt;には、&lt;q&gt;個人情報取扱事業者は、個人情報を取り扱うに当たっては、その利用の目的（以下「利用目的」という。）をできる限り特定しなければならない。&lt;&#x2F;q&gt;と規定されいます。こんなことも知らないでよく国会で答弁する官僚がいたものだと呆れます。&lt;&#x2F;p&gt;
&lt;p&gt;百歩譲って包括的に定義したとして、例えば運営側であっても現代では個人認証の最後の砦である生体情報などを団体が収集する自体狂っています。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;まとめ&quot;&gt;まとめ&lt;&#x2F;h2&gt;
&lt;p&gt;万博協会は規定の修正を検討しているようですが、ここまでの雑さで意識が低いと心配です。
個人的は、来場のチケット管理のためだけならばメールアドレス、電話番号で十分だろうと思います。&lt;&#x2F;p&gt;
&lt;p&gt;なりすましや転売など防止のために名前や生年月日も必要としているのかもしれませんが、
転売を心配するほど売れてないはずです。
チケットが売れないので、大阪府下の学童も動員しようとしているなどとも聞きます。&lt;&#x2F;p&gt;
&lt;p&gt;規定の修正を見守っていきたいと思います。&lt;&#x2F;p&gt;
</content>
        <summary type="html">大阪万博 EXPO 2025の個人情報規約が『ヤバすぎる』とSNSでプチ炎上しているようです。</summary>
        </entry><entry xml:lang="en">
        <title>The Ultimate Showdown: A Deep Dive into Modern Messaging Apps</title>
        <published>2024-10-23T00:00:00+00:00</published>
        <updated>2026-07-01T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2024/10/modern-messaging-apps/" type="text/html"/>
        <id>https://codedchords.dev/blog/2024/10/modern-messaging-apps/</id>
        
            <content type="html">&lt;p&gt;市川強盗傷害事件で犯人たちが「秘匿性が高い通信アプリを使用」とアプリ名を伏せて報道されています。
どうやら&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;signal.org&#x2F;ja&#x2F;&quot;&gt;Signal&lt;&#x2F;a&gt;を使っていたようです。こうなるとバカなメディアや視聴者が「邪悪なアプリ」と騒ぎ出しそうですね。&lt;&#x2F;p&gt;
&lt;p&gt;プライバシー&lt;sup class=&quot;footnote-reference&quot; id=&quot;fr-1-1&quot;&gt;&lt;a href=&quot;#fn-1&quot;&gt;1&lt;&#x2F;a&gt;&lt;&#x2F;sup&gt;
を考慮すると当然の選択ですね。公安や自衛隊でもSignalを奨励しているようです。
不完全な暗号化やメタデータ収集するLINEとかいうアプリを使っている能天気なメディアや視聴者より、
犯人たちのほうがよほど高いリテラシーを持っていたということでしょう。&lt;&#x2F;p&gt;
&lt;p&gt;気になったので、主要なメッセージングアプリについての比較表を作ってみました。&lt;&#x2F;p&gt;
&lt;h2 id=&quot;メッセージングアプリの総合比較表&quot;&gt;メッセージングアプリの総合比較表&lt;&#x2F;h2&gt;
&lt;p&gt;以下は主なメッセージングアプリのついての比較をまとめた表です。&lt;&#x2F;p&gt;
&lt;p&gt;犯人たちが&lt;strong&gt;Signal&lt;&#x2F;strong&gt;を使ったのも納得です。日本ではユーザーが少ないので利用シーンは限られますが。
次点で &lt;strong&gt;Threema&lt;&#x2F;strong&gt; ですね。私は家族で使用しています。&lt;&#x2F;p&gt;
&lt;p&gt;iPhoneユーザーであれば &lt;strong&gt;iMessage&lt;&#x2F;strong&gt; は無難でしょう。完全にE2Eで暗号化されており、メタ情報の収集はされているようですが、Appleなので多少はマシだと思います。&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Telegram&lt;&#x2F;strong&gt; はテロリストが使用しているイメージはありますが、意外に脆弱です。&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;LINE&lt;&#x2F;strong&gt;については、日本でもユーザーが多いので補足を入れています。
やはりLINEは暗号化も不完全でデフォルトの状態ですし、メタ情報&lt;sup class=&quot;footnote-reference&quot; id=&quot;fr-1-2&quot;&gt;&lt;a href=&quot;#fn-1&quot;&gt;1&lt;&#x2F;a&gt;&lt;&#x2F;sup&gt;をかなり収集してお
り、おまけに透明性の観点でもいろいろと問題&lt;sup class=&quot;footnote-reference&quot; id=&quot;fr-2-1&quot;&gt;&lt;a href=&quot;#fn-2&quot;&gt;2&lt;&#x2F;a&gt;&lt;&#x2F;sup&gt;がありました。&lt;&#x2F;p&gt;
&lt;p&gt;こう並べてみると、&lt;strong&gt;LINE&lt;&#x2F;strong&gt; を選択する意味が私にはわかりません。&lt;&#x2F;p&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;機能&#x2F;特徴&lt;&#x2F;th&gt;&lt;th&gt;LINE&lt;&#x2F;th&gt;&lt;th&gt;Signal&lt;&#x2F;th&gt;&lt;th&gt;Threema&lt;&#x2F;th&gt;&lt;th&gt;WhatsApp&lt;&#x2F;th&gt;&lt;th&gt;iMessage&lt;&#x2F;th&gt;&lt;th&gt;Telegram&lt;&#x2F;th&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;thead&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;E2E暗号化&lt;&#x2F;td&gt;&lt;td&gt;部分対応[暗号化WP] ※1&lt;&#x2F;td&gt;&lt;td&gt;完全対応&lt;&#x2F;td&gt;&lt;td&gt;完全対応&lt;&#x2F;td&gt;&lt;td&gt;完全対応&lt;&#x2F;td&gt;&lt;td&gt;完全対応&lt;&#x2F;td&gt;&lt;td&gt;Secret Chatのみ&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;グループチャット暗号化&lt;&#x2F;td&gt;&lt;td&gt;50人以下のみ[暗号化WP]&lt;&#x2F;td&gt;&lt;td&gt;完全対応&lt;&#x2F;td&gt;&lt;td&gt;完全対応&lt;&#x2F;td&gt;&lt;td&gt;完全対応&lt;&#x2F;td&gt;&lt;td&gt;完全対応&lt;&#x2F;td&gt;&lt;td&gt;Secret Chatのみ&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;メタデータ収集&lt;&#x2F;td&gt;&lt;td&gt;多い[PP] ※2&lt;&#x2F;td&gt;&lt;td&gt;最小限&lt;&#x2F;td&gt;&lt;td&gt;最小限&lt;&#x2F;td&gt;&lt;td&gt;多い&lt;&#x2F;td&gt;&lt;td&gt;中程度&lt;&#x2F;td&gt;&lt;td&gt;中程度&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;データストレージ&lt;&#x2F;td&gt;&lt;td&gt;サーバー保存[暗号化WP,PP] ※3&lt;&#x2F;td&gt;&lt;td&gt;端末のみ&lt;&#x2F;td&gt;&lt;td&gt;端末のみ&lt;&#x2F;td&gt;&lt;td&gt;クラウド可能&lt;&#x2F;td&gt;&lt;td&gt;iCloud連携時保存&lt;&#x2F;td&gt;&lt;td&gt;サーバー保存&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;電話番号必須&lt;&#x2F;td&gt;&lt;td&gt;はい[PP]&lt;&#x2F;td&gt;&lt;td&gt;はい&lt;&#x2F;td&gt;&lt;td&gt;いいえ&lt;&#x2F;td&gt;&lt;td&gt;はい&lt;&#x2F;td&gt;&lt;td&gt;いいえ&lt;&#x2F;td&gt;&lt;td&gt;はい&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;自動消去機能&lt;&#x2F;td&gt;&lt;td&gt;24時間のみ[PP]&lt;&#x2F;td&gt;&lt;td&gt;1秒～4週間&lt;&#x2F;td&gt;&lt;td&gt;カスタム設定可&lt;&#x2F;td&gt;&lt;td&gt;24時間～90日&lt;&#x2F;td&gt;&lt;td&gt;2分～4週間&lt;&#x2F;td&gt;&lt;td&gt;1秒～1週間&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;法執行機関への情報開示&lt;&#x2F;td&gt;&lt;td&gt;多い[TR] ※4&lt;&#x2F;td&gt;&lt;td&gt;最小限&lt;&#x2F;td&gt;&lt;td&gt;最小限&lt;&#x2F;td&gt;&lt;td&gt;多い&lt;&#x2F;td&gt;&lt;td&gt;一部可能&lt;&#x2F;td&gt;&lt;td&gt;最小限&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;追加機能&lt;&#x2F;td&gt;&lt;td&gt;スタンプ&#x2F;ゲーム&#x2F;決済&#x2F;音声・ビデオ通話[PP]&lt;&#x2F;td&gt;&lt;td&gt;スタンプ&#x2F;音声・ビデオ通話&lt;&#x2F;td&gt;&lt;td&gt;投票&#x2F;音声・ビデオ通話&lt;&#x2F;td&gt;&lt;td&gt;ステータス&#x2F;音声・ビデオ通話&#x2F;決済&lt;&#x2F;td&gt;&lt;td&gt;Apple統合&#x2F;音声・ビデオ通話&lt;&#x2F;td&gt;&lt;td&gt;Bot&#x2F;チャンネル&#x2F;音声・ビデオ通話&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;tr&gt;&lt;td&gt;オープンソース&lt;&#x2F;td&gt;&lt;td&gt;一部のみ[暗号化WP]&lt;&#x2F;td&gt;&lt;td&gt;完全対応&lt;&#x2F;td&gt;&lt;td&gt;一部のみ&lt;&#x2F;td&gt;&lt;td&gt;なし&lt;&#x2F;td&gt;&lt;td&gt;なし&lt;&#x2F;td&gt;&lt;td&gt;クライアントのみ&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;
&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;
&lt;ul&gt;
&lt;li&gt;※1: LINEのE2E暗号化（Letter Sealing）対応範囲(doc.1) &lt;ins&gt;（2026年7月追記: 2024年後半にLetter Sealingの保護対象が拡大されました。出典: &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.lycorp.co.jp&#x2F;ja&#x2F;privacy-security&#x2F;security&#x2F;transparency&#x2F;encryption-report&#x2F;2025&#x2F;&quot;&gt;LINE暗号化状況レポート（2025年）&lt;&#x2F;a&gt;）&lt;&#x2F;ins&gt;
&lt;ul&gt;
&lt;li&gt;対応: テキスト・位置情報（1対1と50人以下グループ）、1対1音声・ビデオ通話&lt;ins&gt;、画像・動画・音声メッセージ・ファイル添付（2024年後半に対応。1対1と50人以下グループ）&lt;&#x2F;ins&gt;&lt;&#x2F;li&gt;
&lt;li&gt;非対応: &lt;del&gt;画像、動画、ファイル添付、&lt;&#x2F;del&gt;50人以上グループ、グループ通話、LINEミーティング&lt;ins&gt;、アルバム、ノート&lt;&#x2F;ins&gt;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;※2: LINEのメタデータ収集内容(doc.2)
&lt;ul&gt;
&lt;li&gt;アカウント情報（電話番号、メールアドレス）&lt;&#x2F;li&gt;
&lt;li&gt;デバイス情報（使用OS、言語設定）&lt;&#x2F;li&gt;
&lt;li&gt;アプリの使用頻度情報&lt;&#x2F;li&gt;
&lt;li&gt;位置情報（設定による）&lt;&#x2F;li&gt;
&lt;li&gt;友達関係の情報&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;※3: LINEのデータストレージ(doc.1,doc.2)
&lt;ul&gt;
&lt;li&gt;メッセージはサーバーに保存&lt;&#x2F;li&gt;
&lt;li&gt;クラウドバックアップ時は暗号化解除&lt;&#x2F;li&gt;
&lt;li&gt;URL preview等の機能利用時はサーバーに内容送信&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;※4: 法執行機関への開示可能情報(doc.3)
&lt;ul&gt;
&lt;li&gt;7日分のテキストチャット履歴&lt;&#x2F;li&gt;
&lt;li&gt;アカウント情報&lt;&#x2F;li&gt;
&lt;li&gt;通信ログ&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;判断は以下の[LINEの公式ドキュメント]より確認しています。&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;暗号化ホワイトペーパー(doc.1)&lt;sup class=&quot;footnote-reference&quot; id=&quot;fr-linewhitepaper-1&quot;&gt;&lt;a href=&quot;#fn-linewhitepaper&quot;&gt;3&lt;&#x2F;a&gt;&lt;&#x2F;sup&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;terms2.line.me&#x2F;globalnews_PP&#x2F;sp&quot;&gt;プライバシーポリシー&lt;&#x2F;a&gt;(doc.2)&lt;&#x2F;li&gt;
&lt;li&gt;透明性レポート(doc.3)&lt;sup class=&quot;footnote-reference&quot; id=&quot;fr-linecorp-1&quot;&gt;&lt;a href=&quot;#fn-linecorp&quot;&gt;4&lt;&#x2F;a&gt;&lt;&#x2F;sup&gt;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;私自身は&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;threema.ch&#x2F;en&quot;&gt;Threema&lt;&#x2F;a&gt;を使用しています。&lt;&#x2F;p&gt;
&lt;section class=&quot;footnotes&quot;&gt;
&lt;ol class=&quot;footnotes-list&quot;&gt;
&lt;li id=&quot;fn-1&quot;&gt;
&lt;p&gt;この場合「プライバシー」と呼ぶのが適当かわかりませんが。 &lt;a href=&quot;#fr-1-1&quot;&gt;↩&lt;&#x2F;a&gt; &lt;a href=&quot;#fr-1-2&quot;&gt;↩2&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li id=&quot;fn-2&quot;&gt;
&lt;p&gt;2021年のZホールディングとの経営統合で、トークの画像などの情報が韓国の
サーバーでホスティングされていたり、通報確認などが中国企業に委託されてい
たり、このようなことが「第三国」としかレポートされていなかったりと透明性の観
点で問題がありました。現在は解消されたと報告されていますが。 &lt;a href=&quot;#fr-2-1&quot;&gt;↩&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li id=&quot;fn-linewhitepaper&quot;&gt;
&lt;p&gt;元のホワイトペーパー: https:&#x2F;&#x2F;scdn.line-apps.com&#x2F;stf&#x2F;linecorp&#x2F;en&#x2F;csr&#x2F;line-encryption-whitepaper-ver2.1.pdf は現在アクセスできません &lt;a href=&quot;#fr-linewhitepaper-1&quot;&gt;↩&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li id=&quot;fn-linecorp&quot;&gt;
&lt;p&gt;元のレポートページは削除されました &lt;a href=&quot;#fr-linecorp-1&quot;&gt;↩&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;&#x2F;section&gt;
</content>
        <summary type="html">市川強盗傷害事件で犯人たちがSignalを使っていたということで、「SIgnalは危険アプリ」とか言い出すバカがいそうなのでまとめてみました。</summary>
        </entry><entry xml:lang="en">
        <title>AWS ALBの脆弱性？</title>
        <published>2024-08-28T00:00:00+00:00</published>
        <updated>2024-08-28T00:00:00+00:00</updated>
        <author>
            <name>Toshiyuki Yoshida</name>
        </author>
        <link rel="alternate" href="https://codedchords.dev/blog/2024/08/vulnerability-aws-alb/" type="text/html"/>
        <id>https://codedchords.dev/blog/2024/08/vulnerability-aws-alb/</id>
        
            <content type="html">&lt;blockquote&gt;
&lt;p&gt;First, the attacker creates their own ALB instance with authentication
configured in their account. The attacker then uses this ALB to sign a
token they fully control. Next, the attacker alters the ALB configuration
and sets the issuer field to the victim&#x27;s expected issuer. AWS
subsequently signs the attacker&#x27;s forged token with the victim&#x27;s issuer.
Finally, the attacker uses this minted token against the victim&#x27;s
application, bypassing both authentication and authorization.&lt;&#x2F;p&gt;
&lt;p&gt;まず、攻撃者は自身のアカウント内に認証を設定した独自の ALB インスタンスを作成します。
次に、この ALB を使用して、攻撃者が完全に制御できるトークンに署名します。
その後、攻撃者は ALB の設定を変更し、発行者フィールドを被害者が期待する発行者に設定します。
AWS はその結果、攻撃者が偽造したトークンに対して、被害者の発行者として署名を行います。
最後に、攻撃者はこの生成されたトークンを使用して被害者のアプリケーションに対して攻撃を仕掛け、認証と認可の両方を回避します。&lt;&#x2F;p&gt;
&lt;cite&gt;
  [ALBeast Security Advisory by Miggo Research |
  Miggo](https:&#x2F;&#x2F;www.miggo.io&#x2F;resources&#x2F;albeast-security-advisory-alb-vulnerability)
&lt;&#x2F;cite&gt;
&lt;&#x2F;blockquote&gt;
&lt;p&gt;「AWS ALBの脆弱性」と騒がれているけれど、普通にIssuerの検証、JWTトークンの検証、ALBのトラフィックの制限、セキュリティグループの設定をやっていれば関係なくない？「AWS ALBの&lt;strong&gt;ベストプラクティスを無視した間抜けが作ったアプリ&lt;&#x2F;strong&gt;の脆弱性」では？&lt;&#x2F;p&gt;
</content>
        <summary type="html">AWS ALBの脆弱性と騒がれているが・・・</summary>
        </entry>
</feed>
