Authentication · 身份验证
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| hash/hæʃ/ | 散列值 | sàn liè zhí |
| cryptographic hash function/ˌkrɪptəˈɡræfɪk hæʃ ˈfʌŋkʃn/ | 密码散列函数 | mì mǎ sàn liè hán shù |
| salt/sɒlt/ | 盐值 | yán zhí |
| password spraying/ˈpæswɜːd ˈspreɪɪŋ/ | 密码喷洒 | mì mǎ pēn sǎ |
| credential stuffing/krɪˈdenʃl ˈstʌfɪŋ/ | 撞库 | zhuàng kù |
| biometric/ˌbaɪəʊˈmetrɪk/ | 生物特征 | shēng wù tè zhēng |
Hashing passwords
- A cryptographic hash function 密码散列函数 turns any input into a fixed-length hash 散列值.
- It is one-way: you cannot work backwards to the input.
- The same input always gives the same hash (repeatable).
散列密码
- 密码散列函数(cryptographic hash function)把任何输入变成固定长度的散列值(hash)。
- 它是单向的:你无法反推回输入。
- 相同的输入总是给出相同的散列值(可重复)。
Salt and storage
- A service stores the hash, never the plaintext password.
- Salt 盐值 (random bits) is added so identical passwords hash differently.
- At login, the system hashes what you typed and compares.
盐值与存储
- 服务存储散列值,绝不存明文密码。
- 盐值(salt)(随机位)被加入,使相同密码散列不同。
- 登录时,系统散列你输入的内容并比较。
Which authentication factor? · 哪种身份验证因素?
Factors are: something you know, something you have, something you are (biometric), somewhere you are. · 因素包括:您知道的东西、您拥有的东西、您本身(生物特征)、您所在的位置。
A cryptographic hash output is... · 密码哈希输出是……
A hash is fixed-length and one-way. · 哈希是固定长度且单向的。
Trying one common password against many accounts is... · 尝试一个常用密码来测试许多账户是……
Password spraying = one password, many users. · 密码喷溅 = 一个密码,许多用户。
Password attacks & factors
- Password spraying 密码喷洒: one common password against many accounts.
- Credential stuffing 撞库: stolen or default credentials.
- Factors: something you know / have / are (biometric 生物特征) / where — combine for MFA.
密码攻击与因素
- 密码喷洒(password spraying):一个常见密码对许多账户。
- 撞库(credential stuffing):偷来或默认的凭据。
- 因素:你知道的/拥有的/本身的(生物特征biometric)/所在的——组合成MFA。
A service should never store your plaintext password. If it emails you your actual password when you forget it, it is storing passwords unsafely — a serious red flag. Safe services store only the salted hash.
服务绝不应存储你的明文密码。如果你忘记密码时它把你的实际密码发邮件给你,那它在不安全地存储密码——一个严重的警示。安全的服务只存加盐散列值。
Salt makes two identical passwords produce different stored hashes. · 加盐使两个相同的密码生成不同的存储哈希值。
Unique salt per user changes each hash. · 每个用户的唯一盐值改变每次哈希结果。
Using two or more authentication factors is called . · 使用两个或更多身份验证因素称为。
MFA combines factors for stronger security. · MFA 结合多种因素以增强安全性。
Match each proof to its factor type. · 将每个证明与其因素类型匹配。
Know / have / are are the classic factor types. · Know / have / are 是经典的因素类型。
Two users both pick the password sunshine. Without salt, both stored hashes are identical, so cracking one cracks both. With a unique salt each, the two hashes look completely different — the attacker must crack each one separately.
两个用户都选了密码 sunshine。没有盐值,两个存储的散列值相同,所以破解一个就破解两个。各加一个唯一的盐值后,两个散列值看起来完全不同——攻击者必须分别破解每一个。
Passwords are stored as a one-way, fixed-length hash, with salt so identical passwords differ. Attacks include spraying (one password, many accounts) and stuffing (stolen/default credentials). Authentication factors — know / have / are / where — combine into MFA.
密码以单向、固定长度的散列值存储,加盐值使相同密码不同。攻击包括喷洒(一个密码,许多账户)和撞库(偷来/默认凭据)。身份验证因素——知道/拥有/本身/所在——组合成MFA。