您的位置: 首页 >> 新闻中心 >> 英语 >> 雅思 >> 雅思阅读
雅思阅读实战:StudyFindsWebAntifraudMeasureIneffective
■ 最新课程推荐更多课程>>
学校培训课程开课时间上课地点精英价报名
启德雅思 雅思3个月保6分封闭课程2008-10-13中关村¥10476
启德雅思 大学起点6分保过课程2008-10-13中关村¥6673
环球雅思 雅思V5保6-6.5分海淀班电话预约海淀总校¥8624
启德雅思 雅思6.5全能高分课程2008-10-20中关村¥2890
启德雅思 雅思7个月保6分封闭课程2008-11-10中关村¥23086

Study Finds Web Antifraud Measure Ineffective

Published: February 5, 2007 New York Times

1. Internet security experts have long known that simple passwords do not fully defend online bank accounts from determined fraud artists. Now a study suggests that a popular secondary security measure provides little additional protection.

2.The study, produced jointly by researchers at Harvard and the Massachusetts Institute of Technology, looked at a technology called site-authentication images. In the system, currently used by financial institutions like Bank of America, ING Direct and Vanguard, online banking customers are asked to select an image, like a dog or chess piece, that they will see every time they log in to their account.

3.The idea is that if customers do not see their image, they could be at a fraudulent Web site, dummied up to look like their bank's, and should not enter their passwords.

4.The Harvard and M.I.T. researchers tested that hypothesis. In October, they brought 67 Bank of America customers in the Boston area into a controlled environment and asked them to conduct routine online banking activities, like looking up account balances. But the researchers had secretly withdrawn the images.

5.Of 60 participants who got that far into the study and whose results could be verified, 58 entered passwords anyway. Only two chose not to log on, citing security concerns.

6.“The premise is that site-authentication images increase security because customers will not enter their passwords if they do not see the correct image,” said Stuart Schechter, a computer scientist at the M.I.T. Lincoln Laboratory. “From the study we learned that the premise is right less than 10 percent of the time.”

7.He added: “If a bank were to ask me if they should deploy it, I would say no, wait for something better,” he said.

8.The system has some high-power supporters in the financial services world, many trying to comply with new online banking regulations. In 2005, the Federal Financial Institutions Examination Council, an interagency body of federal banking regulators, determined that passwords alone did not effectively thwart intruders like identity thieves.

9.It issued new guidelines, asking financial Web sites to find better ways for banks and customers to identify each other online. January 2007 was set as the compliance date, though the council has yet to begin enforcing the mandate.

10.Banks immediately knew what they did not want to do: ask customers to download new security software, or carry around hardware devices that feed them PIN codes they can use to authenticate their identities. Both solutions would add an extra layer of security but, the banks believed, detract from the convenience of online banking.

11.The image system, introduced in 2004 by a Silicon Valley firm called PassMark Security, offered banks a pain-free addition to their security arsenals. Bank of America was among the first to adopt it, in June 2005, under the brand name SiteKey, asking its 21 million Web site users to select an image from thousands of possible choices and to choose a unique phrase they would see every time they logged in.

12.SiteKey “gives our customers a fairly easy way of authenticating the Bank of America Web site,” said Sanjay Gupta, an e-commerce executive at the bank. “It was very well received.”

13.The Harvard and M.I.T. researchers, however, found that most online banking customers did not notice when the SiteKey images were absent. When respondents logged in during the study, they saw a site maintenance message on the screen where their image and phrases should have been pictured. The error message also had a conspicuous spelling mistake, further suggesting something fishy.

14.Mr. Gupta of Bank of America said he was not troubled by the results of the survey, and stressed that SiteKey had made the bank's Web site more secure. He also said that the system was only a single part of a larger security blanket. “It's not like we're betting the bank on SiteKey,” he said.

15.Most financial institutions, like Bank of America, have other ways to tell if a customer is legitimate. The banks often drop a small software program, called a cookie, onto a user's PC to associate the computer with the customer. If the customer logs in from another machine, he may be asked personal questions, like his mother's maiden name.

16.Rachna Dhamija, the Harvard researcher who conducted the study, points out that swindlers can use their dummy Web sites to ask customers those personal questions. She said that the study demonstrated that site-authentication images are fundamentally flawed and, worse, might actually detract from security by giving users a false sense of confidence.

17.RSA Security, the company that bought PassMark last year, “has a lot of great data on how SiteKey instills trust and confidence and good feelings in their customers,” Ms. Dhamija said. “Ultimately that might be why they adopted it. Sometimes the appearance of security is more important than security itself.”

本新闻共2页,当前在第1页  1  2

  影视动画培训   北大BEC培训官方报名网站   2008美国夏令营启航官方指定报名网站   2008留学第一站!  
  北师大 火星时代
共举影视动画培训之鼎
  北大BEC培训官方报名网站
现在报名独享95折!
  2008年国家职业资格考试
一次过关完全备考手册
  2008留学第一站
留学资讯尽在精英留学站!
 
上一篇:雅思阅读实战:Hackerstargetthehomefront
下一篇:雅思阅读实战:Seekinganenergyholytrinity
 相关新闻
·雅思阅读理解难句之定语从句分析·英语阅读难句分析之分割结构
·英语阅读难句分析之定语从句·2006年全年雅思阅读考试文章总纲
·影响雅思阅读题型考试的十个词·阅读综合辅导:IELTS阅读类型与应对策略
·综合辅导:IELTS新东方精华之学术类阅读·雅思阅读步骤与技巧
·雅思学术阅读贯穿始终的黄金法则及解题攻略·影响雅思阅读的十个字
·雅思阅读技巧---判断与猜测词义·雅思阅读考试辅导:阅读前要先看问题
·雅思阅读实战:Timetocoolit·雅思阅读实战:NextYearMarks
·雅思阅读实战:Sleepmedicationlinkedtobizarrebehaviour·雅思阅读实战:Seekinganenergyholytrinity
 
◇ 重点栏目导航
◇ 精英服务承诺
教育顾问:010-51660910
QQ交流:138660910
相关资料
·IELS试卷结构及做题步骤与方法
·中国地区雅思考试考生须知
·全方位对照:雅思和新托福哪个更好考
·正确认识雅思考试
·雅思考试成绩与澳洲名校入学要求
·中国地区雅思考试考生须知
·新手必看:雅思考试全过程
·雅思考试面面观
·IELTS考前应看的雅思图书推荐
·2007年雅思考试各省市增加场次信息
相关试题
·雅思考试历年真题口语题目汇总
·2006年3月11日雅思考试真题全接触
·2005年12月雅思考试真题全接触
·2005年11月雅思考试真题全接触
·2005年10月雅思考试真题全接触
·2005年9月雅思考试真题全接触
·2005年8月雅思考试真题全接触
·2005年7月雅思考试真题全接触
·2005年6月雅思考试真题全接触
·2005年5月雅思考试真题全接触
相关热贴
·雅思学术阅读贯穿始终的黄金法则及解题攻
·雅思高分写作62个精选句型特别推荐
·奥运期间只安排一场雅思考试
·雅思知识全方位[菜鸟必读]
·新手入门:雅思考试题型流程及测试要点
·2007年6-7月深圳广州各增加一场IELTS考试
·新东方名师乐静谈雅思学习的四重境界
·教育部关于雅思(IELTS)考试报名的重要声
·雅思考察实际运用能力 阅读考试怎样拿满
·雅思阅读段落配对题答疑 需要词汇量做保