密码安全指南:为什么弱密码屡禁不止,如何真正防住A Practical Guide to Password Security
每年泄露榜单上 "123456" 依然名列前茅。本文解释弱密码与密码复用的真实风险,给出强密码的三个特征,以及“生成器 + 密码管理器 + 两步验证”的落地方案。"123456" still tops breach lists every year. This article explains the real risks of weak and reused passwords, the three traits of a strong password, and a practical setup combining a generator, a password manager and two-factor authentication.
弱密码与复用:被攻破的头号原因Weak and reused passwords: the top attack vector
绝大多数账号被盗并非因为对方“黑客技术高超”,而是撞库:攻击者拿着某次泄露的账号密码组合,批量尝试登录其他网站。只要你复用了密码,任何一个小众论坛的泄露都可能殃及你的邮箱与网银。Most account takeovers are not sophisticated hacks but credential stuffing: attackers try username/password pairs leaked from one breach against many other sites. If you reuse passwords, a breach at some obscure forum can compromise your email and banking.
弱密码则更直接:生日、手机号、键盘序列(qwerty)都在攻击字典里,暴力破解一个 6 位纯数字密码只需几秒钟。Weak passwords are even easier: birthdays, phone numbers and keyboard walks like qwerty are all in attack dictionaries, and a 6-digit numeric password falls to brute force in seconds.
强密码的三个特征Three traits of a strong password
第一是长度优先:12 位以上的随机字符,比“8 位复杂密码”难破解成千上万倍。第二是真正随机:人脑想出来的“随机”充满规律(如 P@ssw0rd),应交给密码学安全的生成器。第三是站点唯一:每个网站一个独立密码,把单次泄露的爆炸半径限制在一个站点内。First, length wins: 12+ random characters beats an "8-character complex" password by orders of magnitude. Second, true randomness: human-made "random" is full of patterns (P@ssw0rd), so delegate to a cryptographically secure generator. Third, uniqueness per site: one password per service limits the blast radius of any single breach.
这三条同时满足,密码本身就不再是安全链条上的短板。Satisfy all three, and the password itself stops being the weak link.
落地方案:生成器 + 管理器 + 两步验证The practical setup: generator + manager + 2FA
记住几十个随机密码不现实,正确分工是:生成器负责“造”,密码管理器负责“记”,你只需要记住一个主密码。再为邮箱、网银等核心账号开启两步验证(2FA),即使密码泄露,攻击者也过不了第二道门。Memorising dozens of random passwords is unrealistic, so divide the labour: a generator creates, a password manager remembers, and you memorise a single master password. Add two-factor authentication (2FA) to core accounts like email and banking — even a leaked password then stops at the second door.
另外提醒:不要在聊天工具里明文传输密码;“安全问题”的答案可以当作第二密码随机填写并记入管理器,因为生日、母校这类答案同样能被社工获取。Two more tips: never send passwords in plain text via chat apps, and treat "security questions" as second passwords — random answers stored in your manager, since birthdays and school names are socially engineerable.