Suspicious Website Logins · 可疑网站登录
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| password attack/ˈpæswɜːd əˈtæk/ | 密码攻击 | mì mǎ gōng jī |
| dictionary/ˈdɪkʃənəri/ | 字典 | zì diǎn |
| authentication/ɔːˌθentɪˈkeɪʃn/ | 身份验证 | shēn fèn yàn zhèng |
| password manager/ˈpæswɜːd ˈmænɪdʒə/ | 密码管理器 | mì mǎ guǎn lǐ qì |
| multifactor authentication/ˌmʌltɪˈfæktə ɔːˌθentɪˈkeɪʃn/ | 多因素身份验证 | duō yīn sù shēn fèn yàn zhèng |
What a password attack is
- A password attack 密码攻击 tries to log in with guessed or stolen passwords.
- An online attack tries them against a real login page.
- Automated tools can try thousands of passwords fast.
什么是密码攻击
- 密码攻击(password attack)尝试用猜测或偷来的密码登录。
- 在线(online)攻击针对真实的登录页面尝试。
- 自动化工具能快速尝试数千个密码。
Signs in the log
- Many failed logins in a short time.
- Login attempts at unusual hours.
- Logins from unknown devices.
日志中的迹象
- 短时间内许多失败登录(failed logins)。
- 在异常时间(unusual hours)尝试登录。
- 来自未知设备(unknown devices)的登录。
Strong password or weak password? · 强密码还是弱密码?
Strong passwords are long, random, and unique; weak ones follow common patterns or use personal info. · 强密码长、随机且唯一;弱密码遵循常见模式或使用个人信息。
Which is a sign of an online password attack in the logs? · 日志中哪项是在线密码攻击的迹象?
A burst of failed logins signals guessing. · 大量失败登录表明猜测尝试。
An adversary's list of likely passwords built from your personal info is a . · 攻击者基于你的个人信息构建的可能密码列表称为。
A dictionary of guesses is fed to an automated tool. · 一个猜测字典被输入到自动化工具中。
Why weak passwords fail
- People use predictable patterns like
Summer24!. - They reuse names of pets or family.
- An adversary builds a dictionary 字典 of likely guesses.
为什么弱密码会失守
- 人们使用可预测的模式,如
Summer24!。 - 他们重复使用宠物或家人的名字。
- 对手建立一个可能猜测的字典(dictionary)。
Never reuse one password across sites. If one site is breached, adversaries try that same password everywhere else — a trick called credential reuse.
切勿在多个网站重复使用同一个密码。如果一个网站被攻破,对手会在其他所有地方尝试同一个密码——这种伎俩叫作凭据重用。
Which password is strongest? · 哪个密码最强?
Long, random, unique beats any pattern. · 长、随机、唯一胜过任何模式。
Multifactor authentication (MFA) adds security beyond just a password. · 多因素认证 (MFA) 增加了超越密码本身的安全性。
MFA asks for extra proof, like a texted code. · MFA 要求额外证明,例如短信验证码。
Order these from WEAKEST to STRONGEST password. · 按从最弱到最强的顺序排列这些密码。
Length and randomness increase strength. · 长度和随机性增加强度。
Which make authentication stronger? (Choose all) · 哪些能增强身份验证?(多选)
Reusing a password — even a strong one — is risky. · 重复使用密码——即使是强密码——也有风险。
Making authentication stronger
- Use long, random, unique passwords — a password manager 密码管理器 helps.
- Avoid names, dates, and meaningful words.
- Turn on multifactor authentication (MFA) 多因素身份验证.
让身份验证更强
- 使用长、随机、唯一的密码——密码管理器(password manager)能帮忙。
- 避免名字、日期和有意义的词。
- 开启多因素身份验证(multifactor authentication)。
P@ssw0rd2024 feels clever but follows the exact common pattern (word + number + symbol) an adversary's dictionary expects. A random 16-character string from a password manager is far safer.
P@ssw0rd2024 看似聪明,却完全符合对手字典所预期的常见模式(单词+数字+符号)。来自密码管理器的16位随机字符串安全得多。
An online password attack guesses against a live login and shows up as many failed attempts. People lose because they pick weak, patterned passwords. Fix it with long unique passwords and MFA.
在线密码攻击针对实时登录进行猜测,表现为许多失败尝试。人们失守是因为选择了弱的、有规律的密码。用长而唯一的密码和多因素身份验证来解决。