1. ð ã¯ããã«
Web ãå匷ãå§ãããšå¿ ãåºãŠãã CookieïŒã¯ãããŒïŒãã§ãã
ããã°ã€ã³æ å ±ãèŠããŠããããã€ïŒã
ããã©ãŠã¶ã«ä¿åãããã£ãŠèãããã©âŠïŒã
ãã»ãã¥ãªãã£ãé£ãããâŠã
ãšãããåãããªããŸãŸé²ãã§ããŸãããšãå€ãã§ãã
ãã®èšäºã§ã¯ãåå¿è ã§ããCookieãšã¯ããã ïŒããšèª¬æã§ããããã«åãããããããããæ·±æãããŸãã
2. ð HTTPã¯âã¹ããŒãã¬ã¹âãšãã倧åæ
HTTP 㯠ã¹ããŒãã¬ã¹ïŒç¶æ ãèŠããªãïŒ ãããã³ã«ã§ãã
æ¯åãªã¯ãšã¹ããæ¥ããã³ã«ãµãŒããŒã¯
ãããªã誰ïŒã
ãšãªããŸãã
ðïž å³è§£ïŒã¹ããŒãã¬ã¹ã®äžç
ãµãŒããŒã¯ååã®ç¶æ
ãèŠããŠããªãâŠ
ããã§ç»å Žããã®ã Cookie ã§ã ðª
3. ðª Cookie ã¯ãã¯ãããŒã®ããããïŒå°ããªã¡ã¢æžã
Cookie ã¯ãµãŒããŒããã©ãŠã¶ãžæž¡ã å°ããªããŒã¿ã®æçïŒã¡ã¢ïŒ ã
ðª å³è§£ïŒã¯ãããŒã®ããããæã£ãŠããã€ã¡ãŒãž
ãã©ãŠã¶ãã¯ãããŒãæž¡ããŠãããã®ã§ããµãŒããŒã¯ããã®äººã¯ãã®äººã ãªïŒããšåããããã§ãã
4. ð Cookieã®äžèº«ã¯ã©ããªã£ãŠããïŒ
Cookie ã¯ä»¥äžã®ãããªããŒãšå€ïŒå±æ§ã§æ§æãããŠããŸãã
sessionid=abc123xyz;
Path=/;
HttpOnly;
Secure;
SameSite=Lax;
ðŠ å³è§£ïŒCookieã®æ§é
ãŸãã§ å°ããªèšå®ãã¡ã€ã« ã®ãããªæãã§ãã
5. ðŸ Cookie ã¯ã©ãã«ä¿åãããã®ïŒ
çã㯠ãã©ãŠã¶ã
Chrome / Safari / Firefox ãªã©åãã©ãŠã¶ãèªåã§ Cookie ã管çããŸãã
ðŸ å³è§£ïŒä¿åå Žæã®ã€ã¡ãŒãž
6. ð Cookie ã®æµãïŒååãæ¬¡åã¢ã¯ã»ã¹ïŒ
â ååãã°ã€ã³æïŒCookie ãã»ããïŒ
â æ¬¡åã¢ã¯ã»ã¹ïŒèªåã§Cookieãéä¿¡ïŒ
ãã©ãŠã¶ãæ¯å Cookie ã® âãããâ ïŒã«ã®ãäŒå¡èšŒã¿ãããªãã®ïŒ ãæž¡ããŠãããã®ã§ããµãŒããŒã¯ãã®éµã«å¯Ÿå¿ããæ å ±ãåãåºããããã®ãŠãŒã¶ãŒã ïŒããšå€æã§ããä»çµã¿ã«ãªã£ãŠããŸãã
7. ð Cookie ã䜿ããšãã®ã»ãã¥ãªãã£æ³šæç¹
Cookie ãæ±ãéã¯ã以äžã®4ã€ãç¹ã«éèŠã§ãã
â HttpOnlyïŒJavaScriptããèªãŸããªãïŒ
- â XSS æ»æã§ Cookie ãçãŸããã®ãé²ã
- â LocalStorage ã«ä¿åãããšçãŸãããã
â¡ SecureïŒHTTPSã ãã§éä¿¡ïŒ
â éä¿¡ã®çèŽã§ Cookie ãæãããã®ãé²ã
⢠SameSite Lax/StrictïŒCSRF察çïŒ
â ä»ãµã€ãããåæã«éä¿¡ãããæ»æãé²ã
⣠éèŠæ å ±ãçŽæ¥å ¥ããªãïŒçµ¶å¯ŸNGïŒ
â ãã¹ã¯ãŒãã»ã¡ãŒã«ã¢ãã¬ã¹
â ã©ã³ãã ãªã»ãã·ã§ã³ããŒã¯ã³
sessionid=ã©ã³ãã æåå âããã¯ãªãã±ãŒïŒ
8. ðª Cookie ãš LocalStorage ã®éãïŒå³è§£ã€ãïŒ
| é ç® | Cookie | LocalStorage |
|---|---|---|
| ãµãŒããŒãžèªåéä¿¡ | â | â |
| 容é | 4KB | 5MB |
| JS ããèªããïŒ | HttpOnlyãªãäžå¯ | ãã€ã§ãå¯ |
| åããŠããçšé | èªèšŒ | UIèšå®ã»äžæä¿å |
èªèšŒã¯ CookieïŒHttpOnlyïŒäžæïŒ
9. ð ãŸãšã
ð HTTP ã¯ã¹ããŒãã¬ã¹
ðª Cookie ã¯ã¯ãããŒã®ãããïŒå°ããªã¡ã¢ïŒ
ðŠ äžèº«ã¯ããŒãšå€ïŒå±æ§
ðŸ ä¿åå Žæã¯ãã©ãŠã¶
ð ã»ãã¥ãªãã£ã§ã¯ HttpOnlyã»Secureã»SameSite ãå¿ é
Cookie ã¯ãã°ã€ã³ã»ã»ãã·ã§ã³ç®¡çã®è¶
åºç€ã§ãã
ãããæŒãããŠãããš Web ã®çè§£ãäžæ°ã«é²ã¿ãŸãïŒ
10. ããŸã
ð ãµãŒãããŒã㣠CookieïŒThird-Party CookieïŒãšã¯ïŒ
ãããŸã§èª¬æãã Cookie ã¯ãåºæ¬ç㫠蚪åãã ãµã€ãèªèº«ãçºè¡ãããã® ïŒãã¡ãŒã¹ãããŒã㣠CookieïŒ ã§ãã
äžæ¹ã§ãä»ãŸã§ Web ã§ãã䜿ãããŠããã®ãããµãŒãããŒã㣠CookieïŒThird-Party CookieïŒ ã§ãã
ãµãŒãããŒã㣠Cookieãšã¯ããä»ã¢ã¯ã»ã¹ããŠãããµã€ããšã¯ å¥ã®ãã¡ã€ã³ãçºè¡ ãã Cookieã ã®ããšã§ãã
äŸïŒ
ããªãã news-site.com ãèŠãŠãããšãã«ã
åºåã® ad-tracker.com ã Cookie ãçºè¡ãããããªã±ãŒã¹ã§ãã
ð å³è§£ïŒãµãŒãããŒã㣠Cookie ã®ã€ã¡ãŒãž
ãŠãŒã¶ãŒã¯ news-site.com ãèŠãŠããã®ã«ãåºåãµãŒãã¹ã®ãµã€ãïŒ ïŒç¬¬äžè ïŒã Cookie ãä»äžããŠããŸããã ãããµãŒãããŒãã£ãŒãšããããšã«ãªããŸãã
ð¯ äœã«äœ¿ãããŠããïŒ
-
è€æ°ã®ãµã€ãã«ãŸããã è¡åãã©ããã³ã°
-
èå³ã«åããã åºåã®æé©åïŒãªã¿ãŒã²ãã£ã³ã°åºåïŒ
-
ã¢ããªãã£ã¯ã¹ã®é«åºŠãªèšæž¬
åºåæ¥çã®æšæºæè¡ãšããŠé·ã䜿ãããŠããŸããã
ð« ãµãŒãããŒã㣠Cookie ã¯ä»åŸã»ãŒæ¶æ»
â åãã©ãŠã¶ã廿¢æ¹åãžåããŠããããã§ã
-
SafariïŒæ¢ã«ãããã¯
-
FirefoxïŒæ¢ã«ããã©ã«ãã§ãããã¯
-
ChromeïŒ2024ã2025 ã«æ®µéç廿¢ïŒé²è¡äžïŒ
-
EdgeïŒ2024ããæ®µéçã«å»æ¢
ð å³è§£ïŒãµãŒãããŒã㣠Cookie ã®çµãã
ð ãªã廿¢ãããã®ïŒ
â ãã©ããã³ã°ãé床ã«è¡ãããŠãã
â ãŠãŒã¶ãŒã®ãã©ã€ãã·ãŒãå®ããã
â GDPR ãªã©ååœã®æ³åŸãšã®æŽåæ§ã®ãã
ãã®ããããµãŒãããŒã㣠Cookie ã¯ä»åŸ ã»ãŒäœ¿ããªããªã ãšèã㊠OK ã§ãã
ð ä»åŸã¯ã©ããªãã®ïŒ
Google ã¯ãPrivacy Sandboxããªã©ã®ä»£æ¿æè¡ãææ¡ããŠããŸãããåºæ¬çã« Web éçºè ãšããŠã¯
-
ãµãŒãããŒã㣠Cookie ãåæã«ããå®è£ ã¯ããªã
-
ãµãŒãããŒã㣠Cookie ãªãã®ãã°ã€ã³ã»åææ¹æ³ãæ¡çš
ãšããæ¹åã«ã·ããããŠããå¿ èŠããããŸãã
12. ð ãããã«
æåŸãŸã§ã芧ããã ãããããšãããããŸãããããããããããããªåå¿è
åãã®èšäºãäœæããŠãããŸãã§ã®ããããããé¡ãããŸãã
ããã£ããä»ã®èšäºãã芧ããã ãããšå¬ããã§ããä»åŸããããããé¡ãããããŸãã