成人小说亚洲一区二区三区,亚洲国产精品一区二区三区,国产精品成人精品久久久,久久综合一区二区三区,精品无码av一区二区,国产一级a毛一级a看免费视频,欧洲uv免费在线区一二区,亚洲国产欧美中日韩成人综合视频,国产熟女一区二区三区五月婷小说,亚洲一区波多野结衣在线

立即打開
蘋果推出新登錄功能,用戶可能面臨更大風(fēng)險(xiǎn)

蘋果推出新登錄功能,用戶可能面臨更大風(fēng)險(xiǎn)

Alyssa Newcomb 2019年07月04日
專家認(rèn)為,OpenID加大了人們對(duì)潛在安全風(fēng)險(xiǎn)的顧慮。

行業(yè)團(tuán)體OpenID基金會(huì)稱,允許人們用一個(gè)蘋果賬號(hào)登錄各個(gè)網(wǎng)站和app的新登錄功能,存在重大隱私和安全漏洞,必須予以修復(fù)。

該基金會(huì)為非營利組織,成員包括谷歌、PayPal和微軟等。它管理的OpenID Connect是一項(xiàng)行業(yè)標(biāo)準(zhǔn),作用是對(duì)同一ID在多個(gè)網(wǎng)站上授權(quán),而且無需設(shè)置不同的密碼。

OpenID基金會(huì)指出,“Sign in with Apple”功能和Open ID Connect有一些類似之處,但它并不完全符合該行業(yè)標(biāo)準(zhǔn)。該組織寫給蘋果公司工程高級(jí)副總裁克雷格·費(fèi)德里吉的信指出,該問題有可能讓人們面臨“更大的安全和隱私風(fēng)險(xiǎn)”。

OpenID基金會(huì)的主席奈特·崎村在信中寫道:“OpenID Connect和Sign in with Apple目前的不同之處讓人們可以使用Sign in with Apple的地方變少了,而且讓他們面臨更大的安全和隱私風(fēng)險(xiǎn)?!?/p>

崎村說蘋果尚未推出的這項(xiàng)單一ID登錄功能還給開發(fā)者帶來了“不必要的負(fù)擔(dān)”,因?yàn)樗麄儽仨毷褂肙penID Connect標(biāo)準(zhǔn)并對(duì)蘋果此項(xiàng)功能的不同之處進(jìn)行處理。

OpenID基金會(huì)要求蘋果加入該組織并遵循OpenID Connect標(biāo)準(zhǔn)。一份追蹤該標(biāo)準(zhǔn)和蘋果產(chǎn)品差別的文件已經(jīng)詳細(xì)列出了“彌合差異”所需要調(diào)整的代碼。

網(wǎng)絡(luò)安全公司Mimecast的威脅情報(bào)部門主管弗朗西斯·加夫尼表示,OpenID使得人們加大了對(duì)潛在安全風(fēng)險(xiǎn)的顧慮。

加夫尼認(rèn)為:“考慮到威脅行動(dòng)體越發(fā)仔細(xì)地搜尋潛在漏洞,他們發(fā)現(xiàn)并利用某個(gè)‘差異’可能只是時(shí)間問題?!?/p>

蘋果沒有立即對(duì)詢問做出回應(yīng)。該公司一直宣稱,Sign in with Apple可以幫助重視隱私的人登錄他們喜歡的網(wǎng)站。蘋果表示它不會(huì)和app開發(fā)者共享不必要的數(shù)據(jù)。

Sign in with Apple尚未發(fā)布,但iPhone用戶應(yīng)該會(huì)在自己喜歡的app中看到這個(gè)選項(xiàng),原因是蘋果已經(jīng)要求提供其他單一ID登錄方案(比如通過Facebook或谷歌賬號(hào)登錄)的開發(fā)者同樣向用戶推薦Sign in with Apple。(財(cái)富中文網(wǎng))

譯者:Charlie

審校:夏林

Apple’s new sign in feature, which allows people to use an Apple ID to sign into websites and apps, has critical privacy and security gaps that must be fixed, according to an industry group.

The OpenID Foundation, a nonprofit with members including Google, PayPal, and Microsoft, runs OpenID Connect, an industry standard for authenticating a person’s identity across multiple websites, without requiring them to use different passwords.

Sign in with Apple has some similarities with Open ID Connect, according to the group, but it’s not entirely in line with the industry standard. That’s a problem that could expose people to “greater security and privacy risks,” according to a letter the OpenID Foundation sent to Craig Federighi, Apple’s senior vice president of engineering.

“The current set of differences between OpenID Connect and Sign in with Apple reduces the places where users can use Sign in with Apple, and exposes them to greater security and privacy risks,” Nat Sakimura, chairman of the OpenID Foundation, wrote in the letter.

Sakimura says the single sign-in feature, which has yet to be rolled out, also puts an “unnecessary burden” on developers, who must work with the OpenID Connect standard and navigate the differences in Apple’s sign in feature.

The OpenID Foundation asks that Apple join the group, and to become compliant with the industry protocol. A document tracking differences between those protocols and Apple’s product details a list of necessary coding changes to “address the gaps.”

Francis Gaffney, director of threat intelligence at cybersecurity company Mimecast, says OpenID raises valid concerns about potential security risks.

“Given the increased scrutiny by threat actors on potential vulnerabilities, it would only be a matter of time before one of these ‘differences’ is discovered and exploited,” Gaffney says.

Apple did not immediately respond to a request for comment. The company is touting Sign in with Apple as a way for privacy-minded people to log into their favorite websites. Apple says it won’t share unnecessary data with app developers.

Sign in with Apple hasn’t been publicly released, however anyone with an iPhone should expect to see it as an option in their favorite apps, since Apple requires developers who offer other single sign on options, such as through a Facebook or Google account, to also promote Apple’s sign-in as an option.

掃碼打開財(cái)富Plus App
欧美性色欧美a在线播放| 无遮挡粉嫩小泬久久久久久久| 一区二区天堂资源中文最新版在线一区| 精品国产91久久久久久久久| 日韩性爱视屏一区二区免费网| 国产欧美日韩综合亚洲| 少妇性饥渴无码A区免费| 中文字幕午夜乱码在线视频| 99久久精品国产波多野结衣| 永久免费精品精品永久夜色| 亚洲成a人片在线观看无码专区| 无码人妻精品一区二区三区久久| 亚洲日韩中文字幕日韩在线| 黄色国产网站小视频免费观看| 国产自产视频在线观看香蕉| 性色欲网站人妻丰满中文久久不卡| 亚洲乱码中文字幕综合| 樱花官网官方进入入口| 狠狠综合久久久久尤物| 一卡二卡亚洲乱码一卡二卡| 亚洲国产另类无码日韩| 欲妇荡岳丰满少妇a片| 自拍亚洲欧美在线成电影| 国产在线国偷精品免费看| 少妇性饥渴无码A区免费| 亚洲一区二区三区自拍公司| 欧美猛少妇色XXXXX猛叫| 红杏亚洲影院一区二区三区| 国产午夜成人久久无码一区二区| 蜜桃成人无码区免费视频网站| 国产精品偷伦无码视频| 日产无人区一线二线三线最新版| 亚洲中文有码字幕日本第一页| 99久热RE在线精品99 6热视频| 国产精品高清一区二区三区不卡| 国产一卡一卡三卡乱码| 久久夜噜噜噜亚洲AV蜜臀| 婷婷丁香综合五月久久综合| 精品国产成人亚洲午夜福利| 天天日天天射伊人色综合久久| 无码人妻一区二区三区免费视频|