Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chap0x02实验报告2提交 #2

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open

chap0x02实验报告2提交 #2

wants to merge 1 commit into from

Conversation

Stephaniesuu
Copy link
Collaborator

No description provided.

@huangyifei226 huangyifei226 self-requested a review November 22, 2021 08:50
Copy link

@huangyifei226 huangyifei226 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Accepted

Pros

  • 作业总体完成的不错

Cons

  • 用户使用用户名/口令+图片验证码方式录系统的流程图中,尝试次数是否达到上限的判断框后应标注出"N/Y",如果达到上限就锁定账户稍后再试,未到达上限则输入验证码。

Recommends

  • 业界对生物特征用于身份认证场景的安全性排序共识是:「刷脸」>「指纹」>「声纹」
  • BLP 是机密性保护模型,Biba 是完整性保护模型。所以,涉及到「读」操作的访问控制,都属于 BLP 模型应用范围。「写」操作限制可以使用 Biba 模型。
  • 由于老化或重量波动而导致形状变化,则可能无法识别,对于人脸认证,真正的挑战是 岁月 这把杀猪刀和真正的杀猪刀,不过对于 岁月 的雕刻可以通过经常性使用「刷脸」功能,刷脸系统也是可以累积、更新你的脸指纹数据的。至于真正的杀猪刀造成的突然性伤害,确实没办法,所以生物特征身份认证永远只是辅助性认证因素,不会作为单一认证方式的。最终都可以 fallback 到「口令认证」;

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants