Skip to content

【世界密碼日】這些年,大家一起用的弱密碼

您知道每個五月的第一個星期四是世界密碼日嗎?現代生活每天都過得十分繁忙,您有好好關心過您的密碼嗎?趁著世界密碼日,好好的了解一下關於密碼容易被忽視的問題。

根據 splashdata 的統計,2019 年的十大弱密碼仍是那幾個熟面孔,和 2018 年的榜單做個比較,上榜的密碼大同小異,雖然「sunshine」掉出 Top 10 榜外但也仍是第30名,新進榜的還是更弱的「123123」。並且毫無意外的,仍是「123456」奪下弱密碼冠軍寶座。


什麼是弱密碼呢?就是特別容易被猜中,或是許多人愛用的同一種邏輯所設定的密碼:例如,去年一位國外工程師曾在推特發問,為何 ji32k7au4a83 這個看似安全的密碼在 Have I been pwned 資料庫中出現上百次。然而,這個問題竟然只有台灣網友答得出來,對照注音鍵盤 ji32k7au4a83 = 我的密碼。不僅如此,網友還發現和password、iloveyou相同邏輯的 au4a83、ji394su3 密碼使用量遠超過 ji32k7au4a83。

根據最新美國標準與科技研究院(NIST)所提出的建議,高強度的密碼設定原則,最好包括15個字元以上,並由幾個不相干的名詞或數字組成:例如,VisonExamAttention2020YouLove,這樣超長的密詞可套用自己才知道的邏輯進行組合,比亂數形成的密碼方便記憶,也不容易被破解。另外,若無任何證據顯示密碼有外流的情況,頻率過高的更換密碼,為難的不是入侵者,而是密碼的使用者!

密碼的保護,除了應避免使用弱密碼外,也必須考慮外來的嘗試與破解!當系統遭遇錯誤率過高的外來的密碼嘗試時,應直接封鎖嘗試的來源,而非將該帳號封鎖,這樣才能在避免「暴力破解(Brute-force attack)」、「字典檔攻擊(Dictionary attack)」與「密碼噴灑(Password Spraying)」的時候,不至於困擾擁有正確密碼的主人。

最後,也是大家最容易疏忽的事:千萬不要在多個服務都使用同一組密碼!
一旦任一服務有密碼外洩事件發生時,使用相同密碼的其他服務也跟著一起曝險!

ASRC 研究中心的帳密安全提醒
1. 選擇使用者保護較嚴謹的系統服務,例如一定要有防密碼濫猜的機制
2. 切記,不要一套密碼走天下。不同的服務間使用相同的密碼,只要一個服務的帳密外洩,很容易牽連其他服務帳戶,尤其網路銀行登入密碼更要避免重覆使用。
3. 避免使用公開在外或社群網站可見的生日、姓名、手機等資料做為密碼
4. 雙因子驗證的搭配使用,比定期更換密碼的保護效益有用許多

驗證郵件密碼強度,SPAM SQR 密碼強度檢測模組
企業的電子郵件密碼安全,可透過中華數位科技 SPAM SQR 密碼強度檢測模組定期實施密碼稽核,確保密碼強健度,降低密碼被猜中的風險,避免員工的弱密碼成為資安破口。詳情請洽中華數位科技 02-25422526。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於中華數位科技 Softnext Technologies Corp.
創立於2000年8月。
秉持著【We Secure Your Content】的服務理念,以提供企業資訊應用管理服務及打造資訊內容安全防護為宗旨。專精於提供網路應用服務技術,根據市場需求推出多款資訊內容安全的解決方案及應用服務,能夠協助企業透過符合資安管理規範並遵循法規的方式進行資訊內容安全管理,以維護員工的生產力、提升企業經營績效。

關於 ASRC 垃圾訊息研究中心
ASRC 垃圾訊息研究中心 (Asia Spam-message Research Center),長期與中華數位科技合作,致力於全球垃圾郵件、惡意郵件、網路攻擊事件等相關研究事宜,並運用相關數據統計、調查、趨勢分析、學術研究、跨業交流、研討活動..等方式,促成產官學界共同致力於淨化網際網路之電子郵件使用環境。更多資訊請參考 www.asrc-global.com .

精品科技成立30年,用軟體無微不至的守護台日企業關鍵資產

精品的客戶說:「精品X-FORT就像實力派歌手,當你聽他的歌就知道功力的深厚,可能外型不那麼亮眼,但有著不可否認的實力。」精品科技透過紮實的研發能力與追求極致的精神,邁向未來30年,持續挑戰瞬息萬變的資訊世界。

根據統計一家新設公司的平均存活時間約為13年,精品科技成立於1989年,至今已滿30年,由一群交大的學長學弟共同創辦,從幾個人的小公司,一路成長至今,人數將近100人。於2005年拓展事業版圖至日本,獲得NTT集團採用,並由NTT DATA與子公司合作代理銷售,近年更將行銷觸角延伸到東南亞市場。精品科技30年維持獲利,秉持著開拓者的精神,堅持做與別人不一樣的產品,用軟體守護企業內部資安。

觀察精品科技的產品走向,可說是隨著電腦與網路發展,順應科技潮流的過程。從早期的電腦排版軟體,手寫辨識軟體,USB應用軟體,到因應移動式儲存裝置蓬勃發展,防止電子資料外洩日益受到重視的資安領域,研發出端點防護、文件加密、資產管理等X系列企業內部防護系統,都可看出精品眼光銳利,洞悉趨勢的能力,不斷的追求最新的市場動態。

精品科技這家專業軟體研發公司,勇於不斷挑戰高門檻,高度創新的服務內容。為此在內部導入國際級的CMMI認證、提昇自我研發實力;與ISO27001認證,藉由資安制度導入及落實,把所獲得的資安防護精髓回饋到研發設計規格。積極傾聽來自客戶的聲音,把客戶反映的切身資安需求,實現在X-FORT防護功能中。透過申請通過的130多項專利,保護客戶使用權益。

近年,保護智慧財產權蔚為普世價值,企業辛苦研發出來的智慧結晶,可謂經營存活的關鍵命脈,這些寶貴資產在資訊化時代,幾乎都是以檔案或者資料庫的形式存在,X-FORT的任務,就是聚焦於保護這些重要的智慧資產。在資安專業研發技術方面,精品投入大量資金,不斷研發前瞻技術,包含雲端平台支援、加密金鑰結合HSM,強化X-FORT各項記錄證據能力等前瞻規劃,更是2019年的一大亮點。

未來精品將成為企業防資料外洩的全球先驅品牌,以數位世界正義為己任,守護企業的關鍵資產,打造安心值得信賴的資安堡壘,確保企業能永續發展。

賀! 精品科技榮獲台灣創新技術博覽會 鉑金獎

精品科技在專業技術上不斷的創新研發,2018年在台灣創新技術博覽會中獲得最高榮譽「鉑金獎」。此次參展以虛擬磁碟防護參加競賽,虛擬碟可以應用於程式碼開發,在電腦中建立類似”沙箱的各離機制”,保護文件及程式碼,避免資料外洩與勒索軟體的威脅。

虛擬碟具有以下特點

  • 操作簡便:「透明加解密」電腦文件,「不」改變操作習慣
  • 相容性、擴充性:任何電腦文件、繪圖、程式設計…等=>無限擴充
  • 維修簡易:只須安裝軟體,不必增加硬體
  • 實用性:
    • 獨步全球對於防止美工設計、電路圖、原始程式設計外流的唯一解決方案
    • 可應用於防止駭客竊取資料及勒索軟體威脅

精品科技符合經濟部工業局技術服務機構能量登錄作業要點

精品科技於107年7月15日符合「經濟部工業局技術服務機構服務能量登錄作業要點」,登陸類別為資訊安全服務機構。

通過登陸之技術服務項目及分類為

  • 資訊安全服務、建置及產品服務項目
    • 網路傳輸防護產品
      • 虛擬私有網路防護產品
  • 資訊安全檢測服務項目
    • 網路傳輸安全檢測防護服務
      • 弱點與露管理檢測服務

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於精品科技
精品科技(FineArt Technology) 成立於1989年,由交大實驗室中,一群志同道合的學長學弟所組合而成的團隊,為一家專業的軟體研發公司。從國內第一套中文桌上排版系統開始,到投入手寫辨識領域,憑藉著程式最小、速度最快、辨識最準等優異特性,獲得許多國際大廠的合作與肯定。歷經二十個寒暑,精品科技所推出的產品,無不廣受客戶好評。

iDocCam App iOS訂閱制上線,首購免費試用一個月

智慧型手機即刻化身實物攝影機

由實物攝影機領導品牌 「IPEVO愛比科技」專業團隊推出的 IPEVO iDocCam 遠距教學App,讓手機能即時傳輸教材、文件、各種動態影像……等畫面至大螢幕上展示,或透過通訊軟體即時分享實物、操作手勢等影像,創造出與實物攝影機的相同功能。五月一日iOS版新增兩大功能,月付僅新台幣33元便能使用全功能,將手機隨時隨地變身實物攝影機 。使用步驟請參考: https://www.ipevo.com.tw/blog/posts/ipevo-idoccam-app

iOS版下載連結:https://apple.co/2WWsIXL

Android版下載連結(無訂閱制):https://bit.ly/2X0uSW8

為了更強化 iDocCam 在遠距教學及線上會議的使用便利性, iOS版新增兩項功能:

• 點對點(peer-to-peer)通訊功能
點對點通訊的新功能,讓iPhone使用者使用iDocCam App時,無需在相同網段下即可透過藍牙、與下載 Visualizer 軟體iOS/macOS系統的裝置相連,使用更簡易方便。

• 控制面板模式
在此模式下 iPhone使用者可以將iPhone變身遙控器,遠端控制投射在大螢幕上、 iDocCam所拍攝的即時影像畫面。 iDocCam 五月一日已在 App Store 及 Google Play Store 商店上架,每月僅需付新台幣33元、或年付新台幣330元,兩個方案均有一個月的免費試用期。亦可透過在App Store 及 Google Play Store 商店搜尋「iDocCam OTS」 ,直接一次性買斷使用。iDocCam OTS (iOS 版)並可透過「⼤量採購計劃」(VPP),大量購買、管理與使用。

             

2020/5/1起,價格方案如下:(單次永久性購買請在App Store搜尋iDocCam OTS)

 



About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於IPEVO
IPEVO源自於PChome Online硬體事業部門,2007年7月正式獨立。自2004年於台灣營運Skype網絡電信服務,使台灣成為Skype全球發展中最成功的市場。2005年起以IPEVO品牌推出一系列Skype專屬硬件產品,將Skype虛擬服務轉化為使用者實質經驗。IPEVO以簡單、實際且具有價值的經驗為產品目標,其簡潔俐落的產品風格呼應著IPEVO的核心思考與產品精神。目前已研發之產品包括:Skype有線USB話機、Skype無線話機、Skype會議系統、Skype視訊設備、Stand-alone免電腦Skype話機。

ESET Science Award launches its second annual edition

Bratislava – At a time when the world is relying on scientists and science to help with the coronavirus pandemic, ESET Science Award is launching its second annual recognition contest. Its aim is to recognize outstanding scientists working in Slovakia and introduce them to the public, as well as to showcase the essential role that science plays in society. The international jury will once again be chaired by a Nobel Prize winner this year.

In 2019, ESET Science Award launched its second annual edition to recognize exceptional scientists and academics working in Slovakia. Laureates of the first award include chemist Ján Tkáč, molecular biologist Ľubomíra Tóthová, and bioinformatics scientist Tomáš Vinař.

One of the objectives of the ESET Science Award is to highlight the important role of science and scientists within society. “Today more than ever we, as a society, recognize that scientific knowledge can save thousands of lives and help us make better decisions,” says Richard Marko, CEO of ESET. “Results of a survey conducted before the launch of this year’s award show that as much as 86 percent of respondents agree that Slovakia needs stronger support for science and research. We believe that by recognizing outstanding personalities in science, we will be able to increase the public’s interest in the field, thus increasing the state’s support for it.”

The jury that decides on the laureates consists of world-renowned and respected representatives of science disciplines from around the world. The jury assesses the short-listed scientists in terms of the quality of their scientific work and research and how these overlap with society, with an emphasis on international standards. A complex evaluation process includes both quantitative and qualitative criteria, taking into account the analysis of professional work and its benefits for society, communication, and scientific ethics and integrity.

This year, a top-level evaluation process is to be overseen by an international jury chairman who is a Nobel Prize winner. As the award organizer, the ESET Foundation is hopeful that, despite the current situation with the coronavirus pandemic, it will be able to secure the chairman’s participation in person. “Accepting the award from a Nobel Prize winner has been an exceptional moment in my scientific career. Despite the laureates being decided by a high-quality international scientific jury, I am pleased that this award comes not only from scientific circles but also from the wider community. It symbolizes that society is slowly starting to recognize the role of science in people’s everyday lives,” says Jan Tkáč, the 2019 laureate in the main category, Outstanding Individual Contributor to Slovak Science.

Scientists, researchers, and academics working in Slovakia have until May 28, 2020, to submit an application for the ESET Science Award via the esetscienceaward.sk website. Like last year, this year’s award is to be split into three categories – Outstanding Individual Contributor to Slovak Science, Exceptional Young Scientist in Slovakia under the Age of 35, and Outstanding Academic. The award covers four scientific areas: natural sciences, medical and pharmaceutical sciences, technical sciences, and agricultural sciences. An award ceremony to announce the laureates is planned for October 14, 2020, subject to change based on the coronavirus pandemic situation. For more information, visit www.esetscienceaward.sk.

 

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET investigates Grandoreiro, a trojan exploiting the coronavirus pandemic

BRATISLAVA, PRAGUE – As part of an ongoing series on Latin American banking trojans, ESET researchers take an in-depth look at Grandoreiro. This trojan targets users especially in Brazil, Mexico, Spain and Peru. Distributed almost exclusively through email spam, it has lately started to utilize fake websites capitalizing on the global coronavirus pandemic. Grandoreiro reveals a persistent effort from its authors to evade detection. Although ESET has seen Grandoreiro primarily distributed through spam, where the authors usually utilize a fake Java or Flash update, recently we have observed a shift to COVID19 related scams. The trojan was hiding in videos on fake websites promising information about the coronavirus. However, instead of playing, clicking the video leads to the download of a payload on visitors’ devices.Grandoreiro has been active since at least 2017 in Brazil and Peru, expanding to Mexico and Spain in 2019. As with other Latin American banking trojans in this series, Grandoreiro attacks its victims by displaying fake pop-up windows as a ploy to get them to divulge sensitive information.

The backdoor functionality of Grandoreiro includes manipulating windows; updating itself; capturing keystrokes; simulating mouse and keyboard actions; navigating browsers to chosen URLs; signing out and restarting machines; and blocking access to websites. Grandoreiro collects various information about affected machines and, in some versions, it also steals credentials stored in Google Chrome as well as data stored in Microsoft Outlook browsers.“For a Latin American banking trojan, Grandoreiro utilizes a surprisingly large number of tricks to evade detection and emulation. That includes many techniques to detect or even disable banking protection software,” says ESET researcher Robert Šuman, leading the team analyzing Grandoreiro. “They seem to be developing the banking trojan very rapidly. Almost every new version we see introduces some changes. We also suspect they are developing at least two variants simultaneously. Interestingly, from a technical point of view, they also utilize a very specific application of the binary padding technique that makes it hard to get rid of the padding while keeping a valid file,” adds Šuman.Unlike the majority of Latin American banking trojans, Grandoreiro utilizes quite small distribution chains. For different campaigns, it may choose a different type of downloader. These downloaders are often stored on well-known public online sharing services such as GitHub, Dropbox, Pastebin, 4shared or 4Sync.

For more technical details about Grandoreiro, read the blogpost “Grandoreiro: How engorged can an EXE get?” on WeLiveSecurity.com. Make sure to follow ESET research on Twitter for the latest news from ESET Research.

 

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×