雅思阅读实战:StudyFindsWebAntifraudMeasureIneffective1
文章来源: 文章作者: 发布时间:2007-10-09 07:19 字体: [ ]  进入论坛
(单词翻译:双击或拖选)

Study Finds Web Antifraud Measure Ineffective

Published: February 5, 2007 New York Times

1. Internet security experts have long known that simple passwords do not fully1 defend online bank accounts from determined2 fraud artists. Now a study suggests that a popular secondary security measure provides little additional protection.

2.The study, produced jointly3 by researchers at Harvard and the Massachusetts Institute of Technology, looked at a technology called site-authentication images. In the system, currently used by financial institutions like Bank of America, ING Direct and Vanguard, online banking4 customers are asked to select an image, like a dog or chess piece, that they will see every time they log in to their account.

3.The idea is that if customers do not see their image, they could be at a fraudulent Web site, dummied up to look like their bank's, and should not enter their passwords.

4.The Harvard and M.I.T. researchers tested that hypothesis. In October, they brought 67 Bank of America customers in the Boston area into a controlled environment and asked them to conduct routine online banking activities, like looking up account balances. But the researchers had secretly withdrawn5 the images.

5.Of 60 participants who got that far into the study and whose results could be verified, 58 entered passwords anyway. Only two chose not to log on, citing security concerns.

6.“The premise6 is that site-authentication images increase security because customers will not enter their passwords if they do not see the correct image,” said Stuart Schechter, a computer scientist at the M.I.T. Lincoln Laboratory. “From the study we learned that the premise is right less than 10 percent of the time.”

7.He added: “If a bank were to ask me if they should deploy7 it, I would say no, wait for something better,” he said.

8.The system has some high-power supporters in the financial services world, many trying to comply with new online banking regulations. In 2005, the Federal Financial Institutions Examination Council, an interagency body of federal banking regulators, determined that passwords alone did not effectively thwart8 intruders like identity thieves.

9.It issued new guidelines, asking financial Web sites to find better ways for banks and customers to identify each other online. January 2007 was set as the compliance9 date, though the council has yet to begin enforcing the mandate10.

10.Banks immediately knew what they did not want to do: ask customers to download new security software, or carry around hardware devices that feed them PIN codes they can use to authenticate11 their identities. Both solutions would add an extra layer of security but, the banks believed, detract from the convenience of online banking.

11.The image system, introduced in 2004 by a Silicon12 Valley firm called PassMark Security, offered banks a pain-free addition to their security arsenals13. Bank of America was among the first to adopt it, in June 2005, under the brand name SiteKey, asking its 21 million Web site users to select an image from thousands of possible choices and to choose a unique phrase they would see every time they logged in.

12.SiteKey “gives our customers a fairly easy way of authenticating14 the Bank of America Web site,” said Sanjay Gupta, an e-commerce executive at the bank. “It was very well received.”

13.The Harvard and M.I.T. researchers, however, found that most online banking customers did not notice when the SiteKey images were absent. When respondents logged in during the study, they saw a site maintenance message on the screen where their image and phrases should have been pictured. The error message also had a conspicuous15 spelling mistake, further suggesting something fishy16.

14.Mr. Gupta of Bank of America said he was not troubled by the results of the survey, and stressed that SiteKey had made the bank's Web site more secure. He also said that the system was only a single part of a larger security blanket. “It's not like we're betting the bank on SiteKey,” he said.

15.Most financial institutions, like Bank of America, have other ways to tell if a customer is legitimate17. The banks often drop a small software program, called a cookie, onto a user's PC to associate the computer with the customer. If the customer logs in from another machine, he may be asked personal questions, like his mother's maiden18 name.

16.Rachna Dhamija, the Harvard researcher who conducted the study, points out that swindlers can use their dummy19 Web sites to ask customers those personal questions. She said that the study demonstrated that site-authentication images are fundamentally flawed and, worse, might actually detract from security by giving users a false sense of confidence.

17.RSA Security, the company that bought PassMark last year, “has a lot of great data on how SiteKey instills trust and confidence and good feelings in their customers,” Ms. Dhamija said. “Ultimately that might be why they adopted it. Sometimes the appearance of security is more important than security itself.”



点击收听单词发音收听单词发音  

1 fully Gfuzd     
adv.完全地,全部地,彻底地;充分地
参考例句:
  • The doctor asked me to breathe in,then to breathe out fully.医生让我先吸气,然后全部呼出。
  • They soon became fully integrated into the local community.他们很快就完全融入了当地人的圈子。
2 determined duszmP     
adj.坚定的;有决心的
参考例句:
  • I have determined on going to Tibet after graduation.我已决定毕业后去西藏。
  • He determined to view the rooms behind the office.他决定查看一下办公室后面的房间。
3 jointly jp9zvS     
ad.联合地,共同地
参考例句:
  • Tenants are jointly and severally liable for payment of the rent. 租金由承租人共同且分别承担。
  • She owns the house jointly with her husband. 她和丈夫共同拥有这所房子。
4 banking aySz20     
n.银行业,银行学,金融业
参考例句:
  • John is launching his son on a career in banking.约翰打算让儿子在银行界谋一个新职位。
  • He possesses an extensive knowledge of banking.他具有广博的银行业务知识。
5 withdrawn eeczDJ     
vt.收回;使退出;vi.撤退,退出
参考例句:
  • Our force has been withdrawn from the danger area.我们的军队已从危险地区撤出。
  • All foreign troops should be withdrawn to their own countries.一切外国军队都应撤回本国去。
6 premise JtYyy     
n.前提;v.提论,预述
参考例句:
  • Let me premise my argument with a bit of history.让我引述一些史实作为我立论的前提。
  • We can deduce a conclusion from the premise.我们可以从这个前提推出结论。
7 deploy Yw8x7     
v.(军)散开成战斗队形,布置,展开
参考例句:
  • The infantry began to deploy at dawn.步兵黎明时开始进入战斗位置。
  • The president said he had no intention of deploying ground troops.总统称并不打算部署地面部队。
8 thwart wIRzZ     
v.阻挠,妨碍,反对;adj.横(断的)
参考例句:
  • We must thwart his malevolent schemes.我们决不能让他的恶毒阴谋得逞。
  • I don't think that will thwart our purposes.我认为那不会使我们的目的受到挫折。
9 compliance ZXyzX     
n.顺从;服从;附和;屈从
参考例句:
  • I was surprised by his compliance with these terms.我对他竟然依从了这些条件而感到吃惊。
  • She gave up the idea in compliance with his desire.她顺从他的愿望而放弃自己的主意。
10 mandate sj9yz     
n.托管地;命令,指示
参考例句:
  • The President had a clear mandate to end the war.总统得到明确的授权结束那场战争。
  • The General Election gave him no such mandate.大选并未授予他这种权力。
11 authenticate 0u4zr     
vt.证明…为真,鉴定
参考例句:
  • We would have to authenticate your relationship with the boy.我们必须证实一下您和那个孩子的关系。
  • An expert was needed to authenticate the original Van Gogh painting from his imitation.这幅画是凡·高的真迹还是赝品,需由专家来鉴定。
12 silicon dykwJ     
n.硅(旧名矽)
参考例句:
  • This company pioneered the use of silicon chip.这家公司开创了使用硅片的方法。
  • A chip is a piece of silicon about the size of a postage stamp.芯片就是一枚邮票大小的硅片。
13 arsenals 8089144f6cfbc1853e8d2b8b9043553d     
n.兵工厂,军火库( arsenal的名词复数 );任何事物的集成
参考例句:
  • We possess-each of us-nuclear arsenals capable of annihilating humanity. 我们两国都拥有能够毁灭全人类的核武库。 来自辞典例句
  • Arsenals are factories that produce weapons. 军工厂是生产武器的工厂。 来自互联网
14 authenticating 3d5d0f5c7a6b281da0b22f8c128fb20e     
v.证明是真实的、可靠的或有效的( authenticate的现在分词 );鉴定,使生效
参考例句:
  • Specifies the password used for authenticating to a remote server. 指定用于对远程服务器身份验证的密码。 来自互联网
  • Property indicating which hash algorithm to use when authenticating the message. 表示验证消息时要使用的散列算法的属性。 来自互联网
15 conspicuous spszE     
adj.明眼的,惹人注目的;炫耀的,摆阔气的
参考例句:
  • It is conspicuous that smoking is harmful to health.很明显,抽烟对健康有害。
  • Its colouring makes it highly conspicuous.它的色彩使它非常惹人注目。
16 fishy ysgzzF     
adj. 值得怀疑的
参考例句:
  • It all sounds very fishy to me.所有这些在我听起来都很可疑。
  • There was definitely something fishy going on.肯定当时有可疑的事情在进行中。
17 legitimate L9ZzJ     
adj.合法的,合理的,合乎逻辑的;v.使合法
参考例句:
  • Sickness is a legitimate reason for asking for leave.生病是请假的一个正当的理由。
  • That's a perfectly legitimate fear.怀有这种恐惧完全在情理之中。
18 maiden yRpz7     
n.少女,处女;adj.未婚的,纯洁的,无经验的
参考例句:
  • The prince fell in love with a fair young maiden.王子爱上了一位年轻美丽的少女。
  • The aircraft makes its maiden flight tomorrow.这架飞机明天首航。
19 dummy Jrgx7     
n.假的东西;(哄婴儿的)橡皮奶头
参考例句:
  • The police suspect that the device is not a real bomb but a dummy.警方怀疑那个装置不是真炸弹,只是一个假货。
  • The boys played soldier with dummy swords made of wood.男孩们用木头做的假木剑玩打仗游戏。
TAG标签:
发表评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
验证码:点击我更换图片