为不同网站和设备设置不同密码并记住要消耗太多脑细胞,不少人干脆设置个简单密码或者图省事设置成同一个,但这也增加了被黑的风险。新式的在线身份认证将使用户用其他身份认证方法登录到网络和设备,这些方法包括硬件安全密钥、指纹、面部识别、虹膜扫描及其他生物特征识别解决方案。以后再也不用担心把密码搞忘了!
A new web standard is expected to kill passwords, meaning users will no longer have to remember difficult logins for each and every website or service they use.
一种新的网络标准或将终结密码的使用,用户不再需要记住登录每个网站和个人设备的账号信息。
The Web Authentication (WebAuthn) standard is designed to replace the password with biometrics and devices that users already own, such as a security key, a smartphone, a fingerprint scanner or webcam.
这种“网络认证”标准旨在使用生物识别和用户已有的设备替代密码,比如安全密钥、智能手机、指纹扫描仪和网络摄像头。
Instead of having to remember an increasingly long string of characters, users can authenticate their login with their body or something they have in their possession, communicating directly with the website via Bluetooth, USB or NFC.
用户无需再记忆越来越冗长的密码,而可以使用身体特征或者已有设备认证其登录信息,通过蓝牙、USB接口或近场通信技术直接完成在线身份认证。
“WebAuthn will change the way that people access the Web,” said Jeff Jaffe, chief executive of the World Wide Web Consortium (W3C), the body that controls web standards.
网络标准机构万维网联盟的董事长杰夫-贾福尔说:“网络认证能改变人们的上网方式。”
One example of how WebAuthn will work is that when a user visits a site they want to log into, they input a user name and then get an alert on their smartphone. Tapping on the alert on their phone then logs them into the website without the need for a password.
举个例子,如果一名用户想用电脑登录访问一家网站,他们可以输入用户名,之后就会在智能手机上收到提示。点击手机上的提示信息就可以顺利登录网站,无需输入密码。
WebAuthn promises to protect users against phishing attacks and the use of stolen credentials as there will be nothing to steal, the authentication token is generated and used once by their specific device each time the user logs in.
“网络认证”标准将使用户无需担心受到网络钓鱼攻击,也不用担心认证信息被盗用,因为本身就没什么可偷的。每次用户登录网站,都会生成特定设备才可使用的一次性身份认证指令。
“After years of increasingly severe data breaches and password credential theft, now is the time for service providers to end their dependency on vulnerable passwords and one-time-passcodes and adopt phishing-resistant FIDO Authentication for all websites and applications,” said Brett McDowell, executive director of the FIDO Alliance, one of the bodies pushing the new standard.
推动新标准实行的机构之一FIDO联盟(线上快速身份认证联盟)的执行董事布雷特-麦克道尔说:“这些年来数据泄露和密码信息被盗的情况越来越严重,现在服务提供商是时候结束他们对易受攻击的密码和一次性密码的依赖,并在所有网站和应用中使用可防止网络钓鱼的线上快速身份认证了。”
WebAuthn should also help people use unique login details for each and every service they use, instead of using the same login and password for every site, which many people still do leaving them vulnerable to further attacks if one site is hacked.
“网络认证”标准还帮助人们为每个设备使用独一无二的登录信息,而不是针对每个网站都使用相同的登录名和密码。如果其中一个网站被黑,很多用户的登录名和密码都可能遭到进一步攻击。
The W3C has moved WebAuthn to what’s called the “candidate recommendation” stage – the penultimate step before it becomes an approved web standard – inviting sites and services to begin implementing it. The web standards body announced that Google, Microsoft and Mozilla had committed to supporting WebAuthn, meaning that all major web browsers short of Apple’s Safari will implement the new standard.
万维网联盟已将“网络认证”标准列入“候选推荐”阶段,这是互联网标准最终获得认可、邀请网站和设备开始应用之前的倒数第二个阶段。万维网联盟宣布,谷歌、微软和摩斯拉(火狐)已决心致力于支持这一标准,这意味着除了苹果公司的Safari浏览器外,所有的主流浏览器都将实施这一新标准。
“While there are many web security problems and we can’t fix them all, relying on passwords is one of the weakest links. With WebAuthn’s multi-factor solutions we are eliminating this weak link,” said Jaffe.
贾福尔说:“尽管互联网安全存在诸多问题,我们也无法全部解决,但依赖密码是其中最薄弱的环节。通过网络认证标准的多因素解决方案,我们将消除这一薄弱环节。”
Several sites and services already use similar methods to log in, including Google and Facebook, which can both be logged into using a USB security key. But a single cross-platform, cross-service standard ratified by the W3C will mean that many more sites and services will be able to kill the password as the defacto login method.
已有数家网站和多种设备使用类似的登录方式,谷歌和脸书等网站用户可以选择使用USB安全密钥登录。但互联网联盟批准的单一跨平台、跨设备标准意味着将有越来越多的网站和设备取消密码这种实际登录办法。
WebAuthn is the culmination of many years of work and the change will not happen overnight. But as it increasingly seems inevitable that our email or other online services will get hacked into, removing the password is an important step in improving online security and making using sites and services easier.
“网络认证”标准是数年成就积累的顶峰,这种改变并非一蹴而就。但随着电子邮件和其他网络服务被黑客入侵越发不可避免,消除密码是提升网络安全、让网站和设备使用更加便捷的重要一步。
体坛英语资讯:China overpowers S. Korea for mens team title at Asian Table Tennis
体坛英语资讯:Kenyas Bett eyes wild cards for Commonwealth Games
娱乐英语资讯:Concert marks 70th anniversary of China-Russia diplomatic ties
国内英语资讯:Five detained following east China road accident
女子误把芥末当成牛油果吃掉,心脏衰竭进医院!
国内英语资讯:Rain adds to troubles of stranded passengers in Hainan
论文交"白卷"却获最高分?
体坛英语资讯:Suarez and Alba help Barca pass Eiba test
2019年12月六级作文范文:明星当教授
《雷神3:诸神黄昏》电影精讲(视频)
国内英语资讯:CPC leaders stress high-quality construction of Xiongan New Area
国际英语资讯:Spotlight: U.S. ambassador testifies Trump directed diplomats to work with his lawyer on Ukr
国内英语资讯:China launches campaign to strengthen food safety
“妈妈给装的后备箱”成热门话题
体坛英语资讯:Urawa eliminate Shanghai SIPG to make ACL semis
国内英语资讯:Top political advisor stresses winning fight against poverty
“海陆空”回家难 海口上演真实版“人在囧途”
国际英语资讯:Spotlight: EU, Britain reach new Brexit deal but uncertainties still remain
体坛英语资讯:Interview: WADA President gives all thumbs up to Chinas anti-doping efforts
这些明星竟然都破过吉尼斯世界纪录!
国际英语资讯:Spotlight: Peace far away as showdown approaches Syrias Eastern Ghouta
体坛英语资讯:Bayern win, Hamburg lose in German Bundesliga
体坛英语资讯:Belgium tops Slovakia, remains undefeated at European Volleyball Championship
体坛英语资讯:Slovakia easy prey for Germany at European Volleyball Championship
国内英语资讯:Xi sends congratulatory letter to Zhongguancun Forum
国内英语资讯:Heavy fog strands over 100,000 tourists in Hainan
The Best Gift 最好的礼物
国际英语资讯:Spotlight: Trump pushes ban on bump stocks as debate on gun rights continues
国际英语资讯:Greece speeds up electronic auctions of foreclosed properties
体坛英语资讯:Kenyas Mungara targets marathon win at Cwealth Games