互聯(lián)網(wǎng)在淘汰密碼上邁出了一大步,替代品是什么呢?
密碼是個(gè)棘手的問(wèn)題,你可能不得不時(shí)常更改密碼以免被侵入,或是重置密碼,或是記住用郵箱地址注冊(cè)的每個(gè)用戶平均多達(dá)130個(gè)賬戶的獨(dú)特密碼。 本周一,萬(wàn)維網(wǎng)聯(lián)盟(World Wide Web Consortium)和線上快速身份驗(yàn)證聯(lián)盟(FIDO Alliance)宣布WebAuthn成為官方認(rèn)可的網(wǎng)絡(luò)標(biāo)準(zhǔn),在淘汰密碼上邁出了一大步。WebAuthn是網(wǎng)絡(luò)身份驗(yàn)證(Web Authentication)的縮寫(xiě),它可以讓用戶通過(guò)生物特征技術(shù),例如指紋和面部識(shí)別,或安全密鑰,或智能手機(jī)、智能手表等設(shè)備進(jìn)行登錄,從而淘汰密碼。 萬(wàn)維網(wǎng)聯(lián)盟表示,除了不用記憶或輸入密碼的便利之外,新的登錄標(biāo)準(zhǔn)在安全上也有很大優(yōu)勢(shì)。FIDO2等登錄秘鑰對(duì)特定網(wǎng)站而言是唯一的。如果用戶選擇面部或指紋識(shí)別登錄,這一信息只會(huì)存儲(chǔ)在用戶的設(shè)備上,而不會(huì)保存在服務(wù)器端。此外,這些獨(dú)特的認(rèn)證信息也有助于阻止公司在互聯(lián)網(wǎng)上監(jiān)視用戶并追蹤他們的操作。 大部分流行的瀏覽器,包括谷歌(Google)Chrome、微軟(Microsoft)Edge、蘋(píng)果(Apple)的Safari和火狐(Firefox),都已經(jīng)兼容WebAuthn。官方的認(rèn)證為更多網(wǎng)頁(yè)將其作為標(biāo)準(zhǔn)登錄方式鋪平了道路。Dropbox和微軟去年宣布兼容WebAuthn,成為了它的早期采用者。 盡管密碼在短期內(nèi)還不會(huì)進(jìn)入科技的墳?zāi)梗局芤话l(fā)布的聲明更像是一個(gè)警告,標(biāo)志著密碼作為最可靠和保險(xiǎn)的網(wǎng)絡(luò)安全憑證的時(shí)代已經(jīng)快到盡頭了。(財(cái)富中文網(wǎng)) 譯者:嚴(yán)匡正 |
Passwords are problematic, whether it’s constantly having to change them due to a hack, resetting them, and even just remembering a unique password for the 130 accounts the average user has registered to their email address. The Worldwide Web Consortium and the FIDO Alliance took a big step toward killing the password on Monday when they announced WebAuthn, which is short for Web Authentication, is now an official web standard. The login format kills the password in favor of letting people log in using biometrics, such as fingerprints, and facial recognition, or through security keys, and devices such as smartphones, and smartwatches. Aside from the ease of not having to remember or enter a password, the new login standard also has some major security benefits, according to the Worldwide Web Consortium. Login keys, such as FIDO2, are are unique to a specific site. If a person chooses to login using their face or fingerprint, that information is only stored on their device, and never stays on a server. Additionally, those unique credentials could help prevent companies from following users around the Internet and tracking their every move. WebAuthn is already supported by most popular browsers, including Google Chrome, Microsoft Edge, Apple’s Safari, and Firefox. Its official approval paves the way for more sites to integrate it as a standard login option. Dropbox and MIcrosoft were both early adopters that announced support for WebAuthn last year. While the password isn’t going to the tech graveyard in the near future, the announcement on Monday was mostly a warning sign that its reaching the end of its time as the most trustworthy and safe Internet security credential. |
-
熱讀文章
-
熱門(mén)視頻