Published: February 5, 2007 New York Times1. Internet se" />
Study Finds Web Antifraud Measure Ineffective 1. Internet security experts have long known that simple passwords do not fully defend online bank accounts from determined fraud artists. Now a study suggests that a popular secondary security measure provides little additional protection. 2.The study, produced jointly by researchers at Harvard and the Massachusetts Institute of Technology, looked at a technology called site-authentication images. In the system, currently used by financial institutions like Bank of America, ING Direct and Vanguard, online banking customers are asked to select an image, like a dog or chess piece, that they will see every time they log in to their account. 3.The idea is that if customers do not see their image, they could be at a fraudulent Web site, dummied up to look like their bank’s, and should not enter their passwords. 4.The Harvard and M.I.T. researchers tested that hypothesis. In October, they brought 67 Bank of America customers in the Boston area into a controlled environment and asked them to conduct routine online banking activities, like looking up account balances. But the researchers had secretly withdrawn the images. 5.Of 60 participants who got that far into the study and whose results could be verified, 58 entered passwords anyway. Only two chose not to log on, citing security concerns. 6.“The premise is that site-authentication images increase security because customers will not enter their passwords if they do not see the correct image,” said Stuart Schechter, a computer scientist at the M.I.T. Lincoln Laboratory. “From the study we learned that the premise is right less than 10 percent of the time.” 7.He added: “If a bank were to ask me if they should deploy it, I would say no, wait for something better,” he said. 8.The system has some high-power supporters in the financial services world, many trying to comply with new online banking regulations. In 2005, the Federal Financial Institutions Examination Council, an interagency body of federal banking regulators, determined that passwords alone did not effectively thwart intruders like identity thieves. 9.It issued new guidelines, asking financial Web sites to find better ways for banks and customers to identify each other online. January 2007 was set as the compliance date, though the council has yet to begin enforcing the mandate. 10.Banks immediately knew what they did not want to do: ask customers to download new security software, or carry around hardware devices that feed them PIN codes they can use to authenticate their identities. Both solutions would add an extra layer of security but, the banks believed, detract from the convenience of online banking. 11.The image system, introduced in 2004 by a Silicon Valley firm called PassMark Security, offered banks a pain-free addition to their security arsenals. Bank of America was among the first to adopt it, in June 2005, under the brand name SiteKey, asking its 21 million Web site users to select an image from thousands of possible choices and to choose a unique phrase they would see every time they logged in. 12.SiteKey “gives our customers a fairly easy way of authenticating the Bank of America Web site,” said Sanjay Gupta, an e-commerce executive at the bank. “It was very well received.” 13.The Harvard and M.I.T. researchers, however, found that most online banking customers did not notice when the SiteKey images were absent. When respondents logged in during the study, they saw a site maintenance message on the screen where their image and phrases should have been pictured. The error message also had a conspicuous spelling mistake, further suggesting something fishy. 14.Mr. Gupta of Bank of America said he was not troubled by the results of the survey, and stressed that SiteKey had made the bank’s Web site more secure. He also said that the system was only a single part of a larger security blanket. “It’s not like we’re betting the bank on SiteKey,” he said. 15.Most financial institutions, like Bank of America, have other ways to tell if a customer is legitimate. The banks often drop a small software program, called a cookie, onto a user’s PC to associate the computer with the customer. If the customer logs in from another machine, he may be asked personal questions, like his mother’s maiden name. 16.Rachna Dhamija, the Harvard researcher who conducted the study, points out that swindlers can use their dummy Web sites to ask customers those personal questions. She said that the study demonstrated that site-authentication images are fundamentally flawed and, worse, might actually detract from security by giving users a false sense of confidence. 17.RSA Security, the company that bought PassMark last year, “has a lot of great data on how SiteKey instills trust and confidence and good feelings in their customers,” Ms. Dhamija said. “Ultimately that might be why they adopted it. Sometimes the appearance of security is more important than security itself.” Do the following statements agree with the information given in the passage? Please write TRUE if the statement agrees with the writer FALSE if the statement does not agree with the writer NOT GIVEN if there is no information about this in the passage 1.According to internet security experts, secondary security measures provide little additional protection against fraud. 2.In the Harvard and MIT study, two subjects didn’t log on without seeing the correct pictures. 3.According to Schechter, more than 90% of online banking customers studied logged on without seeing the right pictures. 4.The image system is the only security measure that the banks mentioned in the passage have currently. 5.Bank of America is the first bank that adopted the image system. Questions 6-13 Answer the following questions or complete the following sentences by choosing NO MORE THAN THREE WORDS for each answer. 6.What is ING Direct and Vanguard? 7.What might online banking customers be cheated to give at a fraudulent Web site? 8.What may stop online banking customers from using new verification methods? 9.The key to online banking security is to verify the ______ of customers. 10.Where is PassMark Security located? 11.What is the reason why SiteKey is popular among online banking customers? 12.What was used instead of images in the Harvard and M.I.T. study? 13.How many security methods are mentioned in this passage? Answer keys 1. 第一段“Now a study suggests that a popular secondary security measure provides little additional protection.”似與問題文字很接近,但是原文中a popular secondary security measure是指特定的一個措施,而非泛指所有secondary security measure。原文沒有其它secondary security measure安全有效性的內容。故應選擇NG。 2. 見第4、5段內容。第四段 “But the researchers had secretly withdrawn the images.”即研究人員撤下了圖形,第五段“Only two chose not to log on, citing security concerns.”,有兩個人因為安全考慮未進入。 3. T 見第6段。 4. F 見第11、14段。 5. F 見第11段“Bank of America was among the first to adopt it”,可見首批采用圖形識別軟件的銀行并非Bank of America一家。 6. A financial institution 見第二段。 7. (their) passwords 見第三段。 8. less convenience 見第十段。 9. identity 見第八、十段。 10. Silicon Valley 見第十一段。 11. easy to use 見第十二段。 12. site maintenance message 見第十三段“When respondents logged in during the study, they saw a site maintenance message on the screen where their image and phrases should have been pictured.” 13. 4 分別見第十段的“download new security software”和“hardware devices that feed them PIN codes”,第十五段的“a small software program, called a cookie”,以及本文提到的site-authentication images |
| 雅思考試論壇熱貼: |
【責任編輯:蘇婧 糾錯】 |
|
閱讀上一篇:2009雅思閱讀實戰訓練(十五) |
|
閱讀下一篇:2009雅思閱讀實戰訓練(十) |
|
|
| 【育路網版權與免責聲明】 | |
| ① 凡本網注明稿件來源為"原創"的所有文字、圖片和音視頻稿件,版權均屬本網所有。任何媒體、網站或個人轉載、鏈接、轉貼或以其他方式復制發表時必須注明"稿件來源:育路網",違者本網將依法追究責任; | |
| ② 本網部分稿件來源于網絡,任何單位或個人認為育路網發布的內容可能涉嫌侵犯其合法權益,應該及時向育路網書面反饋,并提供身份證明、權屬證明及詳細侵權情況證明,育路網在收到上述法律文件后,將會盡快移除被控侵權內容。 | |
視頻課程 |
| ·2010年雅思有48個考試日 比今年新增2個 |
| ·獲廣泛認可 中國雅思考生數量破歷史紀錄 |
| ·美領館解答最新留學簽證政策 |
| ·2010年雅思考試時間表及開考城市 |
| ·英國大使館:中國雅思成績逐年提高 |
| ·河北省首個雅思考點“落戶”石家莊 |
| ·權威盤點:出國語言考試之五大最 |
| ·最新資訊:雅思將暫不在中國推行機考 |
| ·外地考生來渝“搶”雅思托福考位 |
| ·中國學生雅思考試:應用能力成軟肋 |
| ·北京新航道學校寒假課程最新優惠 |
| ·引領考雅熱潮,開啟雅思新紀元 |
| ·明年雅思增兩考試日 全年設48個考試日期 |
| · 北京環球雅思學校雅思培訓 |
| ·雅思報名過程中重要問題的最新提示 |
| ·澳大利亞四大名校提高入學門檻 |
| ·新航道5周年真情大回饋! |
| ·南昌:IELTS考點成立并開放網上報名的通知 |
| ·美國:09年20所頂級名校錄取率盤點 |
| ·7月初ETS官方答疑解答公布 |
| ·雅思聽力考試的最大障礙:詞匯聽不懂 |
| ·從劍橋聽力看出題難點 |
| ·堅持不懈訓練雅思聽力方法 |
| ·雅思聽力備考關鍵:最后一堂課的“份量” |
| ·名師解析雅思聽力兩大誤區 |
| ·聽力考試中的數字考點 |
| ·10月24日雅思聽力考題回顧 |
| ·烤鴨必備 走近雅思聽力 |
| ·為什么聽力總是第二遍才能聽懂 |
| ·烤鴨,帶你走近雅思聽力! |
| ·雅思口語:如何克服中文思維 |
| ·應對雅思口語之各種食物的英文說法 |
| ·口語考試:小心你的肢體語言 |
| ·雅思口語Part 1中最難的10道題 |
| ·雅思口語Part 2中最難的10道題 |
| ·雅思口語Part 3中最難的10道題 |
| ·雅思口語素材:The Oriental Pearl TV Tower |
| ·雅思口語考試:不可忽略的細節 |
| ·名師教您如何從“聽”中提高雅思口語 |
| ·雅思口語中用于過渡的萬能猶豫句 |
| ·雅思閱讀考試圖形題目中必須掌握的英語單詞 |
| ·雅思閱讀考試:高中生需掌握四大技能 |
| ·突破雅思閱讀8分的捷徑 |
| ·雅思閱讀中的Matching分類和應對策略 |
| ·雅思常考閱讀文章背景知識:攝影術與藝術 |
| ·如何突破雅思閱讀高分“瓶頸” |
| ·雅思閱讀:需要會“找”會“挑” |
| ·雅思閱讀段落標題題的新趨勢及應對策略 |
| ·10月24日雅思閱讀考題回顧 |
| ·有關雅思閱讀Heading題的做題方法 |
| ·雅思寫作高分必讀:小作文句子模版總結 |
| ·寫作-考場上的"興奮劑"事件 |
| ·雅思寫作:中國學生常見問題 |
| ·雅思寫作TASK2三步走常見誤區 |
| ·雅思作文:多練才是王道 |
| ·雅思:專業運動員是否可以比其他職業賺得多 |
| ·10月24日雅思寫作(A類)考題回顧 |
| ·10月24日雅思寫作(G類)考題回顧 |
| ·2009年10月24日雅思寫作真題點評 |
| ·雅思寫作步驟指導:如何審題和列大綱 |