...
首页> 外文期刊>First Monday >This would work perfectly if it weren’t for all the humans: Two factor authentication in late modern societies
【24h】

This would work perfectly if it weren’t for all the humans: Two factor authentication in late modern societies

机译:如果不是所有人都可以的话,这将非常有效:现代社会中的两因素验证

获取原文
   

获取外文期刊封面封底 >>

       

摘要

Late modern societies are now dependent on innumerable digitally networked technologies, yet there are intractable incongruencies between the technologies that we develop, and the corresponding technological literacies of users. This disjuncture has greatly increased the scope and scale of the risks to which globalized publics are exposed. With public cybersecurity literacies necessarily in decline as a result of the techno-social dynamism of “liquid modernity”, we now face an immense and exponentially growing matrix of cyberthreats and vulnerabilities, of which many carry potentially catastrophic consequences. Our interrogation of two-factor authentication systems, popularly implemented through short messaging services (SMSs), is demonstrative of vulnerabilities that continue to emerge as a result of widespread and entrenched disjunctures between the design of contemporary ICT systems, and the various flawed assumptions that undergird their implementation. We examined 400 authentication messages that were automatically posted to a public forum by Web sites commonly used to receive SMS authentication tokens on behalf of users. We found that 76.5 percent of those messages included the name of the application for which the message was intended: in so doing,?over three quarters?of our sample risked compromising their accounts. Occasionally, we even observed usernames and passwords posted?together. The socio-technical implications of our findings for ICT system design in today’s globalized late modern societies are discussed.
机译:晚期现代社会现在依赖于无数的数字网络技术,但是我们开发的技术与相应的用户技术素养之间存在着棘手的矛盾。这种分离极大地增加了全球化公众所面临风险的范围和规模。由于“流动性现代性”的技术社会活力,导致公共网络安全知识水平必然下降,因此,我们现在面临着庞大且呈指数级增长的网络威胁和漏洞矩阵,其中许多威胁和灾难性后果。我们对通过双向消息服务(SMS)普遍实施的两因素身份验证系统的询问表明,由于当代ICT系统的设计与根深蒂固的各种错误假设之间存在广泛而根深蒂固的脱节而导致的漏洞继续出现他们的实施。我们检查了400条身份验证消息,这些消息由通常用于代表用户接收SMS身份验证令牌的网站自动发布到公共论坛。我们发现,这些消息中有76.5%包含了该消息所针对的应用程序的名称:这样做的话,有超过四分之三的样本有可能损害他们的帐户。有时,我们甚至观察到一起张贴的用户名和密码。讨论了我们的发现对当今全球化的近代现代社会中ICT系统设计的社会技术意义。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号