课程报名咨询电话:010-51268840 51268841
英语 | 小语种 | 考研 | 在职研 | 财会 | 公务员 | 人力资源 | 出国留学 | 冬令营 | 企业管理 | 高校 | 高考 | 文体 | 0-18岁 | 网络课堂
 外语招生网
 外语报名咨询热线:010-51294614、51299614  ||  热点:环球雅思部分课程9.5折特惠 限时抢报!
 雅思·IELTS新托福·TOEFL四六级PETS商务英语职称英语小语种翻译少儿英语GREGMAT | 其他外语考试

If Your Password Is 123456, Just Make It HackMe

作者:不详   发布时间:2010-01-25 11:51:46  来源:网络
  • 文章正文
  • 调查
  • 热评
  • 论坛

Just

  Back at the dawn of the Web, the most popular account password was “12345.”
  Today, it’s one digit longer but hardly safer: “123456.”
  Despite all the reports of Internet security breaches over the years, including the recent attacks on Google’s e-mail service, many people have reacted to the break-ins with a shrug.
  According to a new analysis, one out of five Web users still decides to leave the digital equivalent of a key under the doormat: they choose a simple, easily guessed password like “abc123,” “iloveyou” or even “password” to protect their data.
  “I guess it’s just a genetic flaw in humans,” said Amichai Shulman, the chief technology officer at Imperva, which makes software for blocking hackers. “We’ve been following the same patterns since the 1990s.”
  Mr. Shulman and his company examined a list of 32 million passwords that an unknown hacker stole last month from RockYou, a company that makes software for users of social networking sites like Facebook and MySpace. The list was briefly posted on the Web, and hackers and security researchers downloaded it. (RockYou, which had already been widely criticized for lax privacy practices, has advised its customers to change their passwords, as the hacker gained information about their e-mail accounts as well.)
  The trove provided an unusually detailed window into computer users’ password habits. Typically, only government agencies like the F.B.I. or the National Security Agency have had access to such a large password list.
  “This was the mother lode,” said Matt Weir, a doctoral candidate in the e-crimes and investigation technology lab at Florida State University, where researchers are also examining the data.
  Imperva found that nearly 1 percent of the 32 million people it studied had used “123456” as a password. The second-most-popular password was “12345.” Others in the top 20 included “qwerty,” “abc123” and “princess.”
  More disturbing, said Mr. Shulman, was that about 20 percent of people on the RockYou list picked from the same, relatively small pool of 5,000 passwords.
  That suggests that hackers could easily break into many accounts just by trying the most common passwords. Because of the prevalence of fast computers and speedy networks, hackers can fire off thousands of password guesses per minute.
  “We tend to think of password guessing as a very time-consuming attack in which I take each account and try a large number of name-and-password combinations,” Mr. Shulman said. “The reality is that you can be very effective by choosing a small number of common passwords.”
  Some Web sites try to thwart the attackers by freezing an account for a certain period of time if too many incorrect passwords are typed. But experts say that the hackers simply learn to trick the system, by making guesses at an acceptable rate, for instance.
  To improve security, some Web sites are forcing users to mix letters, numbers and even symbols in their passwords. Others, like Twitter, prevent people from picking common passwords.
  Still, researchers say, social networking and entertainment Web sites often try to make life simpler for their users and are reluctant to put too many controls in place.
  Even commercial sites like eBay must weigh the consequences of freezing accounts, since a hacker could, say, try to win an auction by freezing the accounts of other bidders.
  Overusing simple passwords is not a new phenomenon. A similar survey examined computer passwords used in the mid-1990s and found that the most popular ones at that time were “12345,” “abc123” and “password.”
  Why do so many people continue to choose easy-to-guess passwords, despite so many warnings about the risks?
  Security experts suggest that we are simply overwhelmed by the sheer number of things we have to remember in this digital age.
  “Nowadays, we have to keep probably 10 times as many passwords in our head as we did 10 years ago,” said Jeff Moss, who founded a popular hacking conference and is now on the Homeland Security Advisory Council. “Voice mail passwords, A.T.M. PINs and Internet passwords — it’s so hard to keep track of.”
  In the idealized world championed by security specialists, people would have different passwords for every Web site they visit and store them in their head or, if absolutely necessary, on a piece of paper.
  But bowing to the reality of our overcrowded brains, the experts suggest that everyone choose at least two different passwords — a complex one for Web sites were security is vital, such as banks and e-mail, and a simpler one for places where the stakes are lower, such as social networking and entertainment sites.
  Mr. Moss relies on passwords at least 12 characters long, figuring that those make him a more difficult target than the millions of people who choose five- and six-character passwords.
  “It’s like the joke where the hikers run into a bear in the forest, and the hiker that survives is the one who outruns his buddy,” Mr. Moss said. “You just want to run that bit faster.”

以下网友留言只代表网友个人观点,不代表本站观点。 立即发表评论
提交评论后,请及时刷新页面!               [回复本贴]    
用户名: 密码:
验证码: 匿名发表
外语招生最新热贴:
【责任编辑:苏婧  纠错
阅读下一篇:下面没有链接了
【育路网版权与免责声明】  
    ① 凡本网注明稿件来源为"原创"的所有文字、图片和音视频稿件,版权均属本网所有。任何媒体、网站或个人转载、链接、转贴或以其他方式复制发表时必须注明"稿件来源:育路网",违者本网将依法追究责任;
    ② 本网部分稿件来源于网络,任何单位或个人认为育路网发布的内容可能涉嫌侵犯其合法权益,应该及时向育路网书面反馈,并提供身份证明、权属证明及详细侵权情况证明,育路网在收到上述法律文件后,将会尽快移除被控侵权内容。
外语报名咨询电话:010-51294614、51299614
外语课程分类
 
-- 大学英语---
专四专八英语四六级公共英语考研英语
-- 出国考试---
雅思托福GREGMAT
-- 职业英语---
BEC翻译职称英语金融英语托业
博思实用商务面试英语
-- 实用英语---
口语新概念外语沙龙口语梦工场口语
VIP翻译
-- 小语种----
日语法语德语韩语俄语阿拉伯语
西班牙语意大利语其它语种
热点专题·精品课程
 
外语课程搜索
课程关键词:
开课时间:
价格范围: 元 至
课程类别:
学员报名服务中心: 北京北三环西路32号恒润中心1803(交通位置图
咨询电话:北京- 010-51268840/41 传真:010-51418040 上海- 021-51567016/17
育路网-中国新锐教育社区: 北京站 | 上海站 | 郑州站| 天津站
本站法律顾问:邱清荣律师
北京育路互联科技有限公司版权所有1999-2010 | 京ICP备05012189号