博客
关于我
强烈建议你试试无所不能的chatGPT,快点击我
为什么在网上分享生日很危险
阅读量:2509 次
发布时间:2019-05-11

本文共 4914 字,大约阅读时间需要 16 分钟。

Birthday Cake

A birthday isn’t something you might think of as being private information you should keep secret. Almost everyone celebrates them on social media, and quite a few people post them on their profile. That’s a horrible idea; here’s why.

生日并不是您应该保密的私人信息。 几乎每个人都在社交媒体上庆祝他们,并且相当多的人在个人资料上发布它们。 那是一个可怕的主意。 这就是为什么。

这可能是您的安全性问题之一 (It’s Probably One of Your Security Questions)

Alongside the model of your first car and your mother’s maiden name, your birthday is perhaps the most common security question asked on most websites.

除了第一辆汽车的型号和母亲的娘家姓,生日是大多数网站上最常见的安全问题。

Security questions are  They’re likely the cause of most social media “hacks” online, including the that affected many celebrities. The fault is in password recovery systems; they’re designed for you to be able to reset your password easily, but they often make it easy for hackers to do the same. Brute-forcing your password on a website isn’t really a thing anymore, and most “hacks” you may experience either rely on you being caught in massive data breaches or having terrible security questions.

安全问题 它们可能是大多数社交媒体在网上“被黑客入侵”的原因,其中包括影响许多名人的 。 故障出在密码恢复系统上。 它们旨在使您能够轻松地重置密码,但是它们通常使黑客能够轻松地执行相同的操作。 在网站上强行强行输入密码已不再是一回事了,您可能会遇到的大多数“骇客”都可能是因为您被海量数据泄露所困扰或存在可怕的安全性问题。

Like your birthday. It’s a wonder that it’s even still an option for the already insecure “security question protection,” since it’s much easier for a hacker to find out your birthday than “the street you grew up on.” Since it’s also one of the simplest and easy to remember questions, it’s probably picked very often. That’s an issue because many people leave it publicly posted on their profile, or at least leave up a list of “Happy Birthday!” posts every year. In fact, people to security questions in the form of “quizzes” shared around Facebook. Another day, another hilarious attack vector.

喜欢你的生日。 令人惊奇的是,它仍然是本来就不安全的“安全问题保护”的一种选择,因为对于黑客来说,找到您的生日比“您长大的街道”要容易得多。 由于它也是最简单易记的问题之一,因此可能经常被选择。 这是一个问题,因为许多人将其公开发布在个人资料上,或者至少留下了“生日快乐!”列表。 每年发布。 实际上,人们以在Facebook上共享的“测验”形式安全问题 。 改天,又是另一个热闹的攻击媒介。

Even if your birthday isn’t the answer to an actual security question on your account, it’s still information that a person can use when they try to obtain access to your account through other means—like calling your service provider and pretending to be you.

即使您的生日不是您帐户中实际安全问题的答案,当人们尝试通过其他方式(例如致电您的服务提供商并假装成为您)来获取对您帐户的访问权限时,仍然可以使用这些信息。

有时会用作您的密码 (It Functions as Your Password Sometimes)

When I upgraded to a new phone at a Verizon store, they asked me for two things: my phone number and my birthday. Nothing else. They then proceeded to switch my entire phone line over to a new device. That’s a problem because those two easily-accessible numbers present an obvious attack vector against two-factor authentication.

当我在Verizon商店升级到新手机时,他们问我两件事:我的电话号码和我的生日。 没有其他的。 然后,他们继续将我的整个电话线切换到新设备。 这是一个问题,因为这两个易于访问的数字是针对两因素身份验证的明显攻击媒介。

(often called 2FA) is when a service sends a code to your phone (or asks for a code generated by an app), and you must enter that code in addition to your password. It’s a great way to enhance security. It’s also used often for account recovery, as nobody should have access to a device in your pocket except you. But if someone can virtually steal your phone number just by knowing your birthday, it compromises any service that relies on it.

(通常称为2FA)是指服务将代码发送到您的手机(或要求由应用程序生成的代码),并且您必须输入密码和密码。 这是增强安全性的好方法。 它还经常用于帐户恢复,因为除了您之外,没有人可以使用您口袋中的设备。 但是,如果有人仅仅知道您的生日就可以窃取您的电话号码,那么它就会损害任何依赖该电话号码的服务。

And it’s not just your phone that could be vulnerable, this problem of “birthday-as-password” is prevalent in a lot of places. How many times have you been asked your birthday to verify something? It makes sense, as everyone has a birthday, so it’s easy for people to remember. It’s also fairly secure, as the number of days in a 30-year timespan is already more than the 10,000 possible four-digit PIN combos. But people don’t pin their PIN to the top of their Facebook profiles.

不仅仅是您的手机容易受到攻击,“生日密码”这一问题在很多地方也很普遍。 您被要求生日多少次才能验证? 每个人都有生日,这很有意义,因此人们很容易记住。 这也是相当安全的,因为30年时间跨度中的天数已经超过10,000个可能的四位数PIN组合。 但是人们不会将PIN固定在其Facebook个人资料的顶部。

它可以帮助人们猜测您的社会保险号 (It Helps People Guess Your Social Security Number)

security tip: regularly change your birthplace and mother's maiden name

安全提示:定期更改您的出生地和母亲的娘家姓

— Justin Pot (@jhpot)

—贾斯汀·波特(@jhpot)

Heck, if you were born in the USA and have a social security number, people can use your birthday and place of birth to . Social security numbers were linked to birth location up until 2011 when , so everyone born before then has a more predictable social security number.

哎呀,如果您在美国出生并且有社会保险号,人们可以使用您的生日和出生地来 。 直到2011年之前,社会保险号都与出生地点相关联,因此在此之前出生的每个人都有一个更可预测的社会保险号。

Your birthday isn’t the only dangerous thing to share; identity thieves can also make good use of details like your birthplace and mother’s maiden name. And it’s tough to avoid sharing these details online.

你的生日不是唯一要分享的危险。 身份盗贼还可以充分利用诸如您的出生地和母亲的娘家姓之类的详细信息。 避免在线共享这些详细信息非常困难。

翻译自:

转载地址:http://gvkwd.baihongyu.com/

你可能感兴趣的文章
WebServicer接口类生成方法。
查看>>
POJ 1740
查看>>
【翻译】火影忍者鸣人 疾风传 终级风暴2 制作介绍
查看>>
http和webservice
查看>>
hdu1879------------prim算法模板
查看>>
jdbc之二:DAO模式
查看>>
MySQL性能优化方法一:缓存参数优化
查看>>
如何捕获 System.loadLibrary 产生的异常?(转)
查看>>
Jmeter4.0安装
查看>>
Angular2 - 概述
查看>>
正则表达式tab表示\t
查看>>
NodeJS+Express+MongoDB 简单实现数据录入及回显展示【Study笔记】
查看>>
随心-随想 -谁是我的女主角 -《我的女主角是你》
查看>>
session使用
查看>>
公益筹模板
查看>>
android UI进阶之实现listview的分页加载
查看>>
hdu 2066 一个人的旅行 解题报告
查看>>
完美获取浏览器滚动条卷去的高度
查看>>
PID参数整定快速入门(调节器参数整定方法)
查看>>
[Effective JavaScript 笔记]第39条:不要重用父类的属性名
查看>>