你的密码真的安全吗?!——格瓦拉账号被盗的教训 Is your password safe enough?!——Lessons from an account lost case
昨天公司的微信群里有同事发现自己的格瓦拉余额被盗,个别人还收到格瓦拉发来的提醒账号安全短信,我赶紧查看自己的账号,发现里面的几百块钱余额全部被盗取,在全国各地不同影院使用不同的手机号码购买了电影票。于是发了个朋友圈提醒,之后就陆续收到好多留言,表示自己也中招了。几乎可以肯定这是格瓦拉保存的账户密码信息大量泄露,迅速在市场上被转卖牟利,至于是内部人士作案还是黑客入侵就不得而知。
Yesterday ,some of my colleages found that their money in Gewara(a movie ticket booking app) is lost,I checked my own one instantly to find several hundred yuan in the wallet are stolen, to buy tickets in different cities all around China, using different cellphone. After that, more and more friends told me they are facing the same problem.We believed that the account and passwords of clients in Gewara's server were leaking out for illegal trade, whatever it is hacked or stolen by insiders.
之前我一直以为格瓦拉账号是和手机号绑定的,每次购票会发送取票密码到我的手机上,但发现了被盗之后我再仔细看,原来接收取票码的手机号每次都可以手动更改的,这意味着我的账号就只有一重密码保护了,只要密码被盗,钱财就完全暴露了。我回忆起之前玩一款游戏的时候也发生过被盗取虚拟物品的事,当我找客服投诉时,对方很冷淡地跟我说,你居然不使用密码令牌(类似于谷歌验证器的动态密码验证),只靠一个账户登陆密码就觉得安全吗?看来业内人士心里也很清楚,账号密码被盗是很正常的事。
The Gewara app uses only the login password to protect the account, and this is proved to be useless. Earlier I have lost some virtual items in an online game, and the coustomer service just told me that ,it is normal for password leak in the whole industry.
这次账号被盗的事情让我再次反思密码安全的问题。我们目前使用的基本都是中心化的应用,密码自己保存一份,还在运营商的服务器上保存一份。一旦服务器被攻破或者内部人士监守自盗,我们的机密信息和财产就毫无保障。而且,我们还无法证明这就是对方的责任,因为我们手上也有一份密码。更可怕的是,我们在不同的网站和应用上可能都使用相同的账号和密码,不法分子可能利用这一点,盗取我们更多的财产和信息。以下这个网站可以查询下你常用的账号名是否有被黑客盗取的危险:haveibeenpwned.com/
We have to rethink about the security of our own passwords. We are now using centralised apps in common, passwords are saved both by ourself, and the server of the service provider. Once the same case of Gerawa happens, our property is no longer safe. Also , we have no way to prove that the SP is responsible for this ,because ourself also keep the password. What's worse, we often use the same account and password on different websites of apps, that may cause huge lost of our properties and information. You can use the website below to check if your frequentely-use account is hacked on some websites.haveibeenpwned.com/
那么,如何提高密码的安全性?在中心化应用上,你可以选择双重认证,在登陆密码之外,再增加一把只属于的钥匙,例如手机短信验证、谷歌验证器等等。尽量避免使用只有单一登陆密码的网站或应用。
So how to enhance our password security? In centralized apps, you can choose to use double authentication to add one more key to your doors, such as cellphone message or google authenticator. Avoid using websites of apps that using single login password.
但要彻底解决密码安全问题,还有赖于去中心化应用的发展。像比特币这样的去中心化应用,个人数字资产的私钥是不会保存在任何的服务器上,你是唯一掌控自己密码的人。这才是密码安全的最佳解决方案。
But I think the development of decentralized application is the only way to completely solve the problem. The private key will never saved in any public servers in decentralized apps, like bitcoin. YOU are the ONLY one who have your keys——that's why they are safer than before.