µÚÒ»Õ£ºµÚÈý·½¹¤¾ßΪºÎ³ÉÎªÍÆÌØÇå¾²ÖØÔÖÇø
ÍÆÌØÆ½Ì¨ÈÕ¾ù»îÔ¾Óû§´ï2.3ÒÚ£¬ÆäÖÐ31%µÄÕ˺ÅÇå¾²ÊÂÎñÓë²»·¨µÚÈý·½¹¤¾ßÏà¹Ø¡£ÒÔ91Ãâ·Ñ°æÎª´ú±íµÄÒ»¼üÖÎÀí¹¤¾ß³£Î±×°Ð§¹ûÂÊÖúÊÖ£¬ÊµÔòͨ¹ý×¢Èë¾ç±¾£¨script injection£©»ñÈ¡Óû§Ãô¸ÐÊý¾Ý¡£Ñо¿ÏÔʾ£¬Ä³°æ±¾91¹¤¾ß×°ÖðüÄÚǶµÄÒþ²ØÊ½´úÂ루covert code£©¿Éʵʱ¼à¿ØÓû§Ë½ÐÅ¡¢×·×ÙµØÀíλÖò¢ÍøÂçÁªÏµÈËÐÅÏ¢¡£
µÚ¶þÕ£º91Ãâ·Ñ°æÔËÐлúÖÆµÄÊÖÒÕÆÊ½â
ÄæÏò¹¤³Ì£¨reverse engineering£©ÆÊÎöÅú×¢£¬¸Ã¹¤¾ß½ÓÄÉÆæÒìµÄȨÏÞÀ¦°óÕ½ÂÔ¡£×°ÖÃÀú³ÌÖлáÇ¿ÖÆÒªÇó¿ªÆô11ÏîϵͳȨÏÞ£¬°üÀ¨¶ÁȡͨѶ¼¡¢»á¼ûÉãÏñÍ·µÈ½¹µãÒþ˽¹¦Ð§¡£¸üΣÏÕµÄÊÇÆäʹÓõĶ¯Ì¬Ö¤Êé¸üУ¨Dynamically Updating Certificate£©ÊÖÒÕ£¬¿ÉÈÆ¹ýGoogle PlayÊÐËÁµÄÇå¾²¼ì²â¡£µ±Óû§Ö´ÐÐÍÆÌØ·¢Ìû²Ù×÷ʱ£¬¿Í»§¶Ë»á½«ÐÅϢͬʱ´«Ê䵽δ֪IPµØµã¡£
µÚÈýÕ£º¸ßΣȨÏÞ±³ºóµÄÊý¾ÝºÚ²úÁ´Ìõ
ÍøÂçÇ徲ר¼Òͨ¹ýÁ÷Á¿¼à¿Ø·¢Ã÷£¬Ê¹ÓÃ91Ãâ·Ñ°æµÄÕË»§Ã¿24Сʱ¾Í»á±¬·¢Ô¼340KBµÄÒì³£Êý¾Ý´«Êä¡£ÕâЩÊý¾Ý¾ÓÉAES-256¼ÓÃܺóÁ÷Ïò¾³ÍâЧÀÍÆ÷£¬½âÂëºó°üÀ¨ÍêÕûµÄÓû§»ÏñÊý¾Ý¡£Æ¾Ö¤ÍøÂç·¸·¨Ñо¿ÖÐÐĵı¨¸æ£¬ÕâЩÐÅÏ¢ÔÚºÚÊпÉÂôµ½Ã¿Ìõ0.3-1.5ÃÀÔª£¬Ö÷Òª±»ÓÃÓÚ¾«×¼¹ã¸æÍ¶·ÅºÍ´¹ÂÚ¹¥»÷£¨phishing attacks£©¡£
µÚËÄÕ£º¹Ù·½APIÓë²»·¨¹¤¾ßµÄȨÏÞ±ÈÕÕ
ÍÆÌØ¹Ù·½ÌṩµÄ±ê×¼API£¨Application Programming Interface£©½ö¿ª·Å38Ïî»ù´¡¹¦Ð§£¬ÑÏ¿á×ñÕÕOAuth 2.0ÊÚȨÐÒé¡£Ïà±È֮ϣ¬²»·¨¹¤¾ßͨ¹ýÄæÏò¹¤³ÌÊֶλñÈ¡µÄ˽ÓÐAPI½Ó¿ÚµÖ´ï79ÏÆäÖаüÀ¨ÅÌÎÊÓû§Òþ˽״̬µÄÄÚ²¿½Ó¿Ú¡£Êý¾ÝÏÔʾ£¬Ê¹Óò»·¨¹¤¾ßµÄÕË»§±»ºÚ¿ÍÈëÇֵĸÅÂÊÊÇͨË×ÕË»§µÄ7.3±¶¡£
µÚÎåÕ£º×¨Òµ¼¶ÍÆÌØÇå¾²·À»¤¼Æ»®
½¨ÒéÓû§½ÓÄÉÁãÐÅÈΣ¨Zero Trust£©Ç徲ģ×Ó¾ÙÐзÀ»¤¡£ÆôÓÃÓ²¼þÇå¾²ÃÜÔ¿£¨ÈçYubiKey£©¾ÙÐÐË«ÒòËØÈÏÖ¤£¬Æä·À´¹ÂÚÀÖ³ÉÂʿɴï99.9%¡£Ê¹Óùٷ½Ðû²¼µÄTwitter Advanced Protection³ÌÐò£¬¸Ã³ÌÐòʵʱ¼à¿ØAPIŲÓ㬿ÉÒÉÇëÇó×èµ²ÏìӦʱ¼ä½öΪ0.08Ãë¡£Õë¶ÔÒÆ¶¯¶ËÓû§£¬½¨Òé×°ÖÃGoogle Play ProtectʵʱɨÃèDZÔÚÍþв¡£
µÚÁùÕ£ºÕ˺ÅÒì³£µÄÌØÕ÷ʶ±ðÓë´¦Öóͷ£
µ±ÕË»§·ºÆðÒÔÏÂ3¸öÕ÷Õ×ʱӦÁ¬Ã¦ÅŲ飺1£©¹Ø×¢ÁÐ±í·ºÆðδ¹Ø×¢Õ˺ţ»2£©Ë½ÐżÍ¼Öб£´æÎ´·¢ËÍÐÅÏ¢£»3£©µÇ¼ËùÔÚÏÔʾºÜÊÇÓÃÇøÓò¡£×¨ÒµÈ¡Ö¤¹¤¾ßÏÔʾ£¬±»Ö²Èë¶ñÒâ´úÂëµÄÕË»§»áÔÚÿ120Ãë·¢ËÍÐÄÌø°ü£¨heartbeat packet£©ÖÁC&CЧÀÍÆ÷¡£·ºÆðÒ쳣ʱ¿ÉʹÓÃTwitter Safety DashboardÌìÉúÍêÕûµÄÇå¾²É󼯱¨¸æ¡£
ͨ¹ý±¾ÎĵÄÊÖÒÕÆÊÎö¿ÉÒÔ¿´µ½£¬ÍÆÌظßΣΣº¦91Ãâ·Ñ°æ×°ÖðüʵÔòÊÇÈ«ÐÄÉè¼ÆµÄÊý×ÖÏÝÚå¡£Çå¾²Ñо¿Êý¾ÝÅú×¢£¬×èֹʹÓò»·¨µÚÈý·½¹¤¾ß¿É½«ÕË»§Ç徲Ʒ¼¶ÌáÉý89%¡£½¨ÒéÓû§°´ÆÚ¼ì²éÒÑÊÚȨµÄÓ¦ÓóÌÐò£¬½«OAuthÁîÅÆÓÐÓÃÆÚÉèÖÃΪ×î´óÖµ£¨¼´12¸öÔ£©£¬²¢¿ªÆôµÇ¼ÑéÖ¤ÂëË«ÖØ±£»¤¹¦Ð§¡£¼Çס£ºÕæÕýµÄÇå¾²À´×ÔÓÚ¶ÔϵͳȨÏÞµÄÑÏ¿á¹Ü¿ØºÍ¶Ô¹Ù·½¹¤¾ßµÄºÏÀíʹÓᣵÚÒ»Õ£ºµÚÈý·½¹¤¾ßΪºÎ³ÉÎªÍÆÌØÇå¾²ÖØÔÖÇø
ÍÆÌØÆ½Ì¨ÈÕ¾ù»îÔ¾Óû§´ï2.3ÒÚ£¬ÆäÖÐ31%µÄÕ˺ÅÇå¾²ÊÂÎñÓë²»·¨µÚÈý·½¹¤¾ßÏà¹Ø¡£ÒÔ91Ãâ·Ñ°æÎª´ú±íµÄÒ»¼üÖÎÀí¹¤¾ß³£Î±×°Ð§¹ûÂÊÖúÊÖ£¬ÊµÔòͨ¹ý×¢Èë¾ç±¾£¨script injection£©»ñÈ¡Óû§Ãô¸ÐÊý¾Ý¡£Ñо¿ÏÔʾ£¬Ä³°æ±¾91¹¤¾ß×°ÖðüÄÚǶµÄÒþ²ØÊ½´úÂ루covert code£©¿Éʵʱ¼à¿ØÓû§Ë½ÐÅ¡¢×·×ÙµØÀíλÖò¢ÍøÂçÁªÏµÈËÐÅÏ¢¡£
µÚ¶þÕ£º91Ãâ·Ñ°æÔËÐлúÖÆµÄÊÖÒÕÆÊ½â
ÄæÏò¹¤³Ì£¨reverse engineering£©ÆÊÎöÅú×¢£¬¸Ã¹¤¾ß½ÓÄÉÆæÒìµÄȨÏÞÀ¦°óÕ½ÂÔ¡£×°ÖÃÀú³ÌÖлáÇ¿ÖÆÒªÇó¿ªÆô11ÏîϵͳȨÏÞ£¬°üÀ¨¶ÁȡͨѶ¼¡¢»á¼ûÉãÏñÍ·µÈ½¹µãÒþ˽¹¦Ð§¡£¸üΣÏÕµÄÊÇÆäʹÓõĶ¯Ì¬Ö¤Êé¸üУ¨Dynamically Updating Certificate£©ÊÖÒÕ£¬¿ÉÈÆ¹ýGoogle PlayÊÐËÁµÄÇå¾²¼ì²â¡£µ±Óû§Ö´ÐÐÍÆÌØ·¢Ìû²Ù×÷ʱ£¬¿Í»§¶Ë»á½«ÐÅϢͬʱ´«Ê䵽δ֪IPµØµã¡£
µÚÈýÕ£º¸ßΣȨÏÞ±³ºóµÄÊý¾ÝºÚ²úÁ´Ìõ
ÍøÂçÇ徲ר¼Òͨ¹ýÁ÷Á¿¼à¿Ø·¢Ã÷£¬Ê¹ÓÃ91Ãâ·Ñ°æµÄÕË»§Ã¿24Сʱ¾Í»á±¬·¢Ô¼340KBµÄÒì³£Êý¾Ý´«Êä¡£ÕâЩÊý¾Ý¾ÓÉAES-256¼ÓÃܺóÁ÷Ïò¾³ÍâЧÀÍÆ÷£¬½âÂëºó°üÀ¨ÍêÕûµÄÓû§»ÏñÊý¾Ý¡£Æ¾Ö¤ÍøÂç·¸·¨Ñо¿ÖÐÐĵı¨¸æ£¬ÕâЩÐÅÏ¢ÔÚºÚÊпÉÂôµ½Ã¿Ìõ0.3-1.5ÃÀÔª£¬Ö÷Òª±»ÓÃÓÚ¾«×¼¹ã¸æÍ¶·ÅºÍ´¹ÂÚ¹¥»÷£¨phishing attacks£©¡£
µÚËÄÕ£º¹Ù·½APIÓë²»·¨¹¤¾ßµÄȨÏÞ±ÈÕÕ
ÍÆÌØ¹Ù·½ÌṩµÄ±ê×¼API£¨Application Programming Interface£©½ö¿ª·Å38Ïî»ù´¡¹¦Ð§£¬ÑÏ¿á×ñÕÕOAuth 2.0ÊÚȨÐÒé¡£Ïà±È֮ϣ¬²»·¨¹¤¾ßͨ¹ýÄæÏò¹¤³ÌÊֶλñÈ¡µÄ˽ÓÐAPI½Ó¿ÚµÖ´ï79ÏÆäÖаüÀ¨ÅÌÎÊÓû§Òþ˽״̬µÄÄÚ²¿½Ó¿Ú¡£Êý¾ÝÏÔʾ£¬Ê¹Óò»·¨¹¤¾ßµÄÕË»§±»ºÚ¿ÍÈëÇֵĸÅÂÊÊÇͨË×ÕË»§µÄ7.3±¶¡£
µÚÎåÕ£º×¨Òµ¼¶ÍÆÌØÇå¾²·À»¤¼Æ»®
½¨ÒéÓû§½ÓÄÉÁãÐÅÈΣ¨Zero Trust£©Ç徲ģ×Ó¾ÙÐзÀ»¤¡£ÆôÓÃÓ²¼þÇå¾²ÃÜÔ¿£¨ÈçYubiKey£©¾ÙÐÐË«ÒòËØÈÏÖ¤£¬Æä·À´¹ÂÚÀÖ³ÉÂʿɴï99.9%¡£Ê¹Óùٷ½Ðû²¼µÄTwitter Advanced Protection³ÌÐò£¬¸Ã³ÌÐòʵʱ¼à¿ØAPIŲÓ㬿ÉÒÉÇëÇó×èµ²ÏìӦʱ¼ä½öΪ0.08Ãë¡£Õë¶ÔÒÆ¶¯¶ËÓû§£¬½¨Òé×°ÖÃGoogle Play ProtectʵʱɨÃèDZÔÚÍþв¡£
µÚÁùÕ£ºÕ˺ÅÒì³£µÄÌØÕ÷ʶ±ðÓë´¦Öóͷ£
µ±ÕË»§·ºÆðÒÔÏÂ3¸öÕ÷Õ×ʱӦÁ¬Ã¦ÅŲ飺1£©¹Ø×¢ÁÐ±í·ºÆðδ¹Ø×¢Õ˺ţ»2£©Ë½ÐżÍ¼Öб£´æÎ´·¢ËÍÐÅÏ¢£»3£©µÇ¼ËùÔÚÏÔʾºÜÊÇÓÃÇøÓò¡£×¨ÒµÈ¡Ö¤¹¤¾ßÏÔʾ£¬±»Ö²Èë¶ñÒâ´úÂëµÄÕË»§»áÔÚÿ120Ãë·¢ËÍÐÄÌø°ü£¨heartbeat packet£©ÖÁC&CЧÀÍÆ÷¡£·ºÆðÒ쳣ʱ¿ÉʹÓÃTwitter Safety DashboardÌìÉúÍêÕûµÄÇå¾²É󼯱¨¸æ¡£
ͨ¹ý±¾ÎĵÄÊÖÒÕÆÊÎö¿ÉÒÔ¿´µ½£¬ÍÆÌظßΣΣº¦91Ãâ·Ñ°æ×°ÖðüʵÔòÊÇÈ«ÐÄÉè¼ÆµÄÊý×ÖÏÝÚå¡£Çå¾²Ñо¿Êý¾ÝÅú×¢£¬×èֹʹÓò»·¨µÚÈý·½¹¤¾ß¿É½«ÕË»§Ç徲Ʒ¼¶ÌáÉý89%¡£½¨ÒéÓû§°´ÆÚ¼ì²éÒÑÊÚȨµÄÓ¦ÓóÌÐò£¬½«OAuthÁîÅÆÓÐÓÃÆÚÉèÖÃΪ×î´óÖµ£¨¼´12¸öÔ£©£¬²¢¿ªÆôµÇ¼ÑéÖ¤ÂëË«ÖØ±£»¤¹¦Ð§¡£¼Çס£ºÕæÕýµÄÇå¾²À´×ÔÓÚ¶ÔϵͳȨÏÞµÄÑÏ¿á¹Ü¿ØºÍ¶Ô¹Ù·½¹¤¾ßµÄºÏÀíʹÓá£