行业英语 学英语,练听力,上听力课堂! 注册 登录
> 行业英语 > 金融英语 > 金融时报原文阅读 >  第256篇

你的密码有多脆弱?

所属教程:金融时报原文阅读

浏览:

2020年06月22日

手机版
扫描二维码方便学习和分享

你的密码有多脆弱?

很多人不仅会重复使用密码,而且经常选择自己的宠物加数字、或是连着的键盘字母作为密码——对我们的密码设置习惯,黑客可比我们自己要了解地更多。

测试中可能遇到的词汇和知识:

memorable显著的,难忘的['mem(ə)rəb(ə)l]

leaked漏的[li:kt]

crummy微不足道的;寒酸的['krʌmɪ]

adultery通奸行为;外遇[ə'dʌlt(ə)rɪ]

capitalisation市值(等于capitalization);资本化[,kæpɪtəlɪ'zeʃən]

Your passwords are a lot more vulnerable than you think( 659 words)

By Lisa Pollack

The puppy’s name can be whatever you want,the father in the Bizarro comic tells his son,“but make sure it is something memorable. You’ll be using it as a security question answer for the rest of your life.”

Unfortunately the name given to the dog — say,Poppy — may or may not have been encrypted when it was leaked among details of 500m Yahoo accounts,which included the answers to security questions about first pets. The dog’s name was probably also used as a password at some point as people often use pets’names — maybe with a couple of numbers at the end.

“Poppy95”is not a secure password but it is fairly typical and it illustrates an uncomfortable fact: our crummy password construction is predictable. And with large breaches of popular websites,hackers are getting to know us better than ever.

People often pick animals(“monkey”),keyboard patterns(“zxcvbn”),dad jokes(“letmein”),sports teams(“liverpool”) and angst(“whatever”). All proved popular with users of the adultery site,Ashley Madison,hacked last year. In case you are thinking only adulterers use weak passwords,many of these also showed up in a leak from the Last.fm music service which surfaced more recently.

Both breaches — estimated at about 30m-40m each — are dwarfed by the 164m LinkedIn and 360m MySpace accounts that appeared in May.

Passwords are valuable to hackers in a couple of indirect ways. First,most people — about 60 per cent by some estimates — reuse passwords. This means the login details from one site can be tried out on more valuable sites — financial accounts,for example,or people’s work. And,combined with details such as previous addresses obtained from a retailer and a date of birth from the Yahoo hack or Facebook,they may be used to obtain credit fraudulently.

Second,the data sets can be added to“dictionaries”comprising actual dictionaries,tens of thousands of books and all of Wikipedia,which can be used to crack passwords.

If you are thinking:“I may use the same base password but I change it a bit for different websites”,well,I have a research paper for you. A group from the University of Illinois at Urbana-Champaign and elsewhere looked at the often simplistic changes people make. Using passwords for the same users from different leaks,they were able to guess almost a third of the transformed passwords within 100 or fewer attempts. Popular changes involved two to three appended characters. Keyboard sequence changes,capitalisation changes and“leet speak” — changing s to $,say — were also common.

Unfortunately,password strength meters aren’t much help as they underestimate hackers’understanding of users’habits.

In an ideal world,website owners would strengthen their own security to protect users. But if their customers use weak passwords — or reuse strong ones on other,less secure sites — there’s only so much they can do.

There is some encouragement to be had,though. University researchers from Pennsylvania tested whether people could correctly identify the more secure password among pairs,where“security”is“guessability”using cracking tools. Participants did reasonably well — identifying the benefits of capitals,digits and symbols in the middle of a password,and avoiding names.

However,they also overestimated the usefulness of appending digits,incorrectly selecting“astley123”as more secure than“astleyabc”. The former is easier to crack because of the pervasiveness of the pattern of appending digits — hence the problem with the variant of Poppy’s name.

Participants also“underestimated the poor security properties of building a password around common keyboard patterns and common phrases”. They wrongly believed that“iloveyou88”is stronger than“ieatkale88”(which frankly seems like an excellent name for a dog).

The researchers concluded that such misunderstandings,and poor password choices generally,stem from an underestimation of the risk of potential attacks and a lack of knowledge about how dangerously common certain construction techniques are. Which is not surprising,they note,as we don’t often see one another’s passwords. Unfortunately,hackers do.

1.Why the son should remember the puppy’s name in the Bizarro comic?

A. the dog is with us our entire life

B. it should be taken seriously

C. it may be a security question answer

D. the name will be the password

答案(1)

2.What is the password“Poppy95”illustrating with?

A. crummy password construction is predictable

B. stolen password is fairly typical

C. crummy password is unsafe

D. people often use pets’names

答案(2)

3.How many percent of people are used to reuse passwords?

A. 30%

B. 40%

C. 60%

D. 80%

答案(3)

4.Which one of the following is not right about password?

A. “iloveyou88”is not stronger than“ieatkale88”

B. using names is more secure

C. “astley123”is easier to crack than“astleyabc”

D. customers are best not to use weak passwords

答案(4)

(1) 答案:C.it may be a security question answer

解释:“这只小狗的名字你可以随便取,”漫画Bizarro中的父亲告诉儿子,“但要确保能记住。因为你一辈子都要把它作为安全问题的答案。”

(2) 答案:A.crummy password construction is predictable

解释:“Poppy95”并非一个安全的密码,但它相当普遍,而且说明了一个令人不安的事实:我们随随便便的密码结构是可以预测的。

(3) 答案:C.60%

解释:大概60%的人会重复使用密码。这意味着,一个网站的登录细节可能会在更有价值的网站上使用:例如金融账户或人们的工作。结合从零售商获取的以前的地址以及从雅虎或Facebook获取的生日日期,这些密码可能会被用来骗贷。

(4) 答案:B.using names is more secure

解释:密码要避免使用名字但后缀数字的用处也被高估,因为后缀数字模式很普遍,同时常见的键盘模式和常见短语设置密码安全性也很差。

用户搜索

疯狂英语 英语语法 新概念英语 走遍美国 四级听力 英语音标 英语入门 发音 美语 四级 新东方 七年级 赖世雄 zero是什么意思咸阳市百合小区英语学习交流群

网站推荐

英语翻译英语应急口语8000句听歌学英语英语学习方法

  • 频道推荐
  • |
  • 全站推荐
  • 推荐下载
  • 网站推荐