Passwords and authentication · 密码与身份验证
Proving who you are
- Authentication means proving you are who you claim to be. There are three classic ways:
- Something you know (a password), something you have (a phone), something you are (a fingerprint).
证明你是你
- **身份验证(authentication)**就是证明你确实是你所声称的那个人。经典的方式有三种:
- 你知道的东西(密码)、你拥有的东西(手机)、你本身的特征(指纹)。
Stronger logins
- Biometrics — fingerprints or face scans; hard to steal, but not perfect.
- Two-step verification (2FA) — a password plus a one-time code sent to your phone.
- Even if an attacker steals your password, 2FA stops them logging in.
更强的登录
- 生物识别(biometrics) —— 指纹或人脸扫描;难以盗取,但并非完美。
- 两步验证(2FA) —— 密码加上一个发到你手机的一次性验证码。
- 即使攻击者偷到了你的密码,2FA 也能阻止他们登录。
What makes a password strong?
- Length beats everything. Each extra character multiplies the guesses an attacker needs.
- A mix of letters, digits, and symbols helps — but a long passphrase like
correct horse battery stapleis both strong and memorable.
什么样的密码才算强?
- 长度胜过一切。 每多一个字符,都会把攻击者所需的猜测次数成倍放大。
- 字母、数字和符号混用会有帮助 —— 但像
correct horse battery staple这样的长口令,既强又好记。
Build a checker
- Below, write a tiny rule: a password is "strong" only if it is long enough and has a digit.
- Real checkers also reject common passwords like
123456andpassword.
Covers: IGCSE 5.3 (authentication), A-Level 6.1, AP CSP Big Idea 5.
写一个检查器
- 下面,写一条小规则:只有当密码足够长并且含有数字时,才算 “strong”。
- 真实的检查器还会拒绝像
123456和password这样的常见密码。
涵盖:IGCSE 5.3(身份验证)、A-Level 6.1、AP CSP Big Idea 5。
Common mistakes
- Long and unique beats short, complex, but reused.
- Two-factor authentication adds a second, different check.
常见错误
- 又长又独特胜过又短又复杂却重复使用。
- 双因素认证增加了第二种不同的验证。
Write a simple strength checker. A password is strong if it is at least 8 characters AND contains a digit; otherwise weak. Print the right word for the given password. · 写一个简单的强度检查器。如果密码至少 8 个字符****且包含一个数字,就是 strong,否则是 weak。为给定的密码打印出正确的词。
Click Run to see the output here. · 点击“运行”查看此处输出。
Real checkers also reject common passwords. Improve the rule: if the password is in the common list it is weak no matter what; otherwise apply the old rule (length ≥ 8 AND a digit). Print the verdict. · 真正的检查器还会拒绝常见密码。改进规则:密码只要在 common 列表里就一律是 weak;否则套用旧规则(长度 ≥ 8 且含数字)。打印判定结果。
Click Run to see the output here. · 点击“运行”查看此处输出。