Security posture

このサイトの守り方。

このサイトはユーザーのデータを一切持ちません。Cookieもデータベースもアカウントもゼロです。存在しないものは奪えません。そのうえで、実際に効く防御をHTTP層から多層に適用しています。

脅威モデル(要約)

PII_COLLECTED
0 bytes
COOKIES_SET
0
DB_QUERIES
0
TRACKING_PIXELS
0
THIRD_PARTY_SCRIPTS
0
USER_ACCOUNTS
0
SESSION_TOKENS
0
DATA_STORES
0
HEADERS_SERVED
28

存在しないデータは、盗めません。

多層防御(断面図)

  1. L1EDGE (VERCEL OR CADDY)requests are first judged here
  2. L2HTTP HEADERS28 declared, applied per route
  3. L3CSPenforced on every response
  4. L4HONEYPOT418 + cookie wipe + incident log
  5. L5STATIC FILESno server-side code executes
  6. L6DATAno user data exists to steal

静的ファイルと最小限のサーバサイド処理だけの構成が、攻撃面を最小化します。

HTTP防御ヘッダー(実物)

以下は vercel.json に定義されたヘッダーを実物どおりに掲載したものです。同じマニフェストがセルフホスト構成でもCaddyとアプリ内ミドルウェアによって適用されます。

/(.*)

Strict-Transport-Security
max-age=63072000; includeSubDomains; preload
X-Content-Type-Options
nosniff
X-Frame-Options
DENY
Referrer-Policy
no-referrer
Cross-Origin-Opener-Policy
same-origin
Cross-Origin-Resource-Policy
same-origin
Cross-Origin-Embedder-Policy
credentialless
Origin-Agent-Cluster
?1
X-Permitted-Cross-Domain-Policies
none
X-XSS-Protection
0
X-DNS-Prefetch-Control
off
Permissions-Policy
accelerometer=(), ambient-light-sensor=(), aria-notify=(), autoplay=(), battery=(), bluetooth=(), browsing-topics=(), camera=(), captured-surface-control=(), compute-pressure=(), cross-origin-isolated=(), deferred-fetch=(), deferred-fetch-minimal=(), display-capture=(), document-domain=(), encrypted-media=(), fullscreen=(), gamepad=(), geolocation=(), gyroscope=(), hid=(), identity-credentials-get=(), idle-detection=(), interest-cohort=(), join-ad-interest-group=(), keyboard-map=(), local-fonts=(), magnetometer=(), microphone=(), midi=(), otp-credentials=(), payment=(), picture-in-picture=(), publickey-credentials-create=(), publickey-credentials-get=(), run-ad-auction=(), screen-wake-lock=(), serial=(), shared-storage=(), speaker-selection=(), storage-access=(), synced-reading=(), usb=(), unload=(), web-share=(), window-management=(), xr-spatial-tracking=()
Reporting-Endpoints
default="https://harukakaya.dev/api/security-report"
NEL
{"report_to":"default","max_age":604800,"include_subdomains":true,"success_fraction":0,"failure_fraction":1}
X-Security-Contact
https://harukakaya.dev/.well-known/security.txt

/((?!keystatic|api/keystatic).*)

Content-Security-Policy
default-src 'self'; script-src 'self'; style-src 'self' https://fonts.googleapis.com; style-src-attr 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com; img-src 'self' data:; connect-src 'self'; media-src 'self'; worker-src 'self'; manifest-src 'self'; frame-src 'none'; child-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self'; object-src 'none'; block-all-mixed-content; upgrade-insecure-requests; report-uri /api/security-report; report-to default

/keystatic/:path*

X-Robots-Tag
noindex, nofollow
Cache-Control
no-store
Content-Security-Policy
default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://avatars.githubusercontent.com https://raw.githubusercontent.com; font-src 'self' data:; connect-src 'self' https://api.github.com https://raw.githubusercontent.com; worker-src 'self' blob:; frame-ancestors 'none'; base-uri 'self'; form-action 'self' https://github.com; object-src 'none'; upgrade-insecure-requests

/api/keystatic/:path*

X-Robots-Tag
noindex, nofollow
Cache-Control
no-store
Content-Security-Policy
default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'self' https://github.com

/api/security-report

Cache-Control
no-store
Access-Control-Allow-Origin
*
Access-Control-Allow-Methods
POST, OPTIONS
Access-Control-Allow-Headers
Content-Type

/.well-known/security.txt

Content-Type
text/plain; charset=utf-8
Cache-Control
public, max-age=86400

ハニーポット

スキャナが標的にするパス(/.env、/wp-admin、.php 系など)はすべて HTTP 418 を返し、Clear-Site-Data でブラウザのサイトデータ消去を要求します。各プローブには決定論的な事件番号が発行され、サーバーログに記録されます。User-Agent で攻撃ツールを名乗るクライアントは全パスで拒否します。

確認方法:

$ curl -sI https://harukakaya.dev/.env
HTTP/2 418
x-incident-id: KY-24A62BB9
clear-site-data: "cookies", "storage"

脆弱性を発見した方へ

このサイトで脆弱性を発見した場合は security.txt の連絡先へご報告ください。静的サイトに見つかった問題は多くの場合ホスティング基盤かAstro本体のものですが、ご連絡いただければ確認します。

殿堂入り

このサイトで脆弱性を見つけ、ここに名を刻んだ研究者の一覧:

(意図的に空白)