注册并分享邀请链接,可获得视频播放与邀请奖励。

与「yubi」相关的搜索结果

yubi 贴吧
一个关键词就是一个贴吧,路径全站唯一。
创建贴吧
用户
未找到
包含 yubi 的内容
Gate170万被盗事件深度分析:高级账户如何被黑客接管 “Gate被盗170万”,官方和创始人Dr. Han已明确回应:这不是系统性黑客入侵或平台漏洞,全站资产安全。这是**单个用户账户被接管(Account Takeover)**的个案,所有操作都有完整日志可追溯。 事件时间线:7月4日新设备通过活体人脸+多重验证重置手机邮箱;7月5日再次人脸验证并提交2019年历史交易记录解绑手机号;7月6日改谷歌2FA、登录及资金密码;7月7日从历史设备多次验证后完成5笔提现(约49.96 ETH + 746k HSK + 156万USDT);7月8日用户才报案。 这不是“一键盗号”,而是4天渐进式精准攻击。攻击者很可能通过设备长期渗透(RAT木马)+社交工程,或结合AI deepfake绕过活体检测,逐步控制受害者数字生态(邮箱、旧记录、设备)。多设备切换 + 需要历史证明材料,说明攻击者有备而来且非常谨慎(避开风控)。 暴露的核心问题: •账户恢复流程(历史记录+人脸)在用户端信息已泄露时容易被利用。 •活体人脸识别在2026年AI环境下已非绝对安全,设备被控或高质量deepfake可绕过。 •平台依赖“用户授权操作”日志来定责,但高端攻击者能制造“合法”流程。 这不是Gate独有问题,而是整个行业面临的用户侧安全新挑战。Gate反应透明是加分项,但也提醒我们:即使有生物识别+多因素,最终防线仍在用户端。 实用防护升级建议(立即执行): 1提现白名单 + 硬件安全密钥(YubiKey/Passkey)作为主力2FA,优先替代App验证。 2大额资产自托管(硬件钱包+多签),交易所只留日常交易资金。 3专用干净设备操作 + 定期清理登录设备 + 开启异常通知。 4邮箱最高安全级别(硬件2FA),旧交易记录/截图加密或删除。 5高价值用户考虑行为监控更严的平台或机构托管。 核心 takeaway:加密世界“被盗”90%以上是用户生态被控,而非平台崩盘。生物识别是辅助,设备 hygiene + 硬件密钥 + 分散自托管才是对抗专业攻击者的有效组合。理性看待传闻,重视自己这道防线。 安全无小事,建议所有用户今天就检查一次自己的提现设置和登录设备。
显示更多
Gate 这件事,其实带出了一个币圈未来非常重要的问题。 当 AI 已经可以模仿任何人的声音、视频,甚至未来能够突破或欺骗扫脸验证之后,我们到底还能依靠什么来保证交易所账户的安全? 现在很多交易所把「人脸识别」当作最终安全手段,但 AI 的发展正在让生物特征越来越容易被伪造。未来真正值得思考的问题不是 AI 能不能骗过扫脸,而是账户的最终信任锚(Root of Trust)应该建立在哪里。 我的理解是,这件事情其实暴露了一个行业趋势: 人脸识别越来越适合作为身份认证(Identity),却越来越不适合作为资产授权(Authorization)。 原因很简单: 人脸、声音、视频都可以被 AI 复制; 手机可能被盗; SIM 卡可能被劫持; 邮箱可能被入侵。 这些都属于可以被复制的信息。 真正无法被 AI 复制的,只有你实际持有的东西(Something you have)。 例如: FIDO2 / Passkey 硬件认证 硬件安全密钥(如 YubiKey) 多重签名(Multisig) MPC(多方安全计算) 冷钱包确认大额转账 独立设备二次授权 未来交易所很可能会逐渐变成: AI 可以帮你证明“你是谁”,但真正决定“钱能不能转走”的,将不再是扫脸,而是加密学。 我甚至觉得,未来交易所应该重新设计安全体系: 登录:可以用 AI + 人脸 + Passkey,尽可能方便。 查看资产:几乎没有限制。 提币:必须依赖硬件密钥、MPC、多签等不可伪造的授权方式,而不是单纯扫脸。 换句话说: AI 正在让「身份」越来越容易伪造,也正在倒逼整个行业从“相信人脸”,回归到“相信密码学”。 我认为,这可能会成为未来几年交易所安全体系最大的升级方向。
显示更多
0
24
73
5
转发到社区
AI 制作的《楚门的世界》续集 作者:Yubinnnn (视频号) seedance 2.0
0
70
1.2K
150
转发到社区
▶︎▷🗯#NMB48# NEWS🗯◁◀︎ #NMB48# が 『手紙文化振興アンバサダー』に就任しました📮✨ 『手紙を書く、読む』という文化や習慣を次世代に伝え、手紙の価値を未来に伝えていきます💭 就任を記念して、11月8日に開催される #NMB4815thAnniversaryLIVE# の会場では、記念イベントも開催します💌 (※詳細は後日改めてお知らせします) @posukuma_yubin
显示更多
0
2
841
178
转发到社区
10月30日「原宿ファッション部Collection vol.5」開催! 「ハロウィン」をテーマにファッションショー&ライブを魅せる🎃 ✝️記事はこちら 🎫チケットはこちら 🎤出演者 ポジティブモンスター @moricircle みらくる★)ふぉーぜ-ZERO- @miracleforz 唯美人形 @yubiningyou77 凛々しくも臨界に咲くARTERIA @idol_lilia antares @antares_info Ellememe @Ellememe_info 蒼斗ゆりあ @aoto_yuria 青木りほ(Fenomeno)@dad_riho 東京みじんこガールズ 原宿ファッション部 👸ファッションショー参加者 美月瑠奈(ポジティブモンスター) @runa_circle 星乃愛璃咲(ポジティブモンスター) @arisa25_circle 恋空夢苺(みらくる★)ふぉーぜ-ZERO-) @KOIZORA_yume 星月陽葵(みらくる★)ふぉーぜ-ZERO-) @meruhesoo 紫月なな(唯美人形) @nana_yubi 蒼井メリッサ美華(唯美人形) @mika_yubi 水城琉衣(唯美人形)@louis_yubi 凛瞳れむ(凛々しくも臨界に咲くARTERIA) @Osashimi_wasabi 鳴声すず(凛々しくも臨界に咲くARTERIA) @suz_zz7 夢乃みゆ(antares) @0lmiu_ 美月菜那(antares) @n_ana0700 あおい凛(antares) @aoilin06 涼賀あかり(Ellememe) @Ryoga_Akari 葉月蒼依(Ellememe/原宿ファッション部) @dad_aoi 蒼斗ゆりあ(原宿ファッション部)@aoto_yuria 青木りほ(Fenomeno)@dad_riho 入瀬ひなた(東京みじんこガールズ) @dad_hinata_ 竹崎明日歩(東京みじんこガールズ/原宿ファッション部) @asuho1228 👗ファッションショー参加ブランド BACKSTAGE PASS @ShibuyaZy DustDevil @dustdevil_offi Honey Tiara @HoneyTiara_ ililil @ililil_jp LISTEN FLAVOR @ListenFlavor NieR Clothing @NieR_tokyo REFLEM @_REFLEM TRAVAS TOKYO @travas_tokyo モリグチカ @moriguchika
显示更多
0
0
41
29
转发到社区
【MUSICA9月号は8/19発売】 さらに ●Creepy Nuts ●SKY-HI ●あいみょん ●Paledusk ●シンガーズハイ ●w.o.d. ●Rol3ert ●ジ・エンプティ ●健やかなる子ら ●yubiori ●京都大作戦2025 ●TETORA presents KAKUSHIN CLUB ●KESEN ROCK FESTIVAL 2025 など盛り沢山!詳細は画像を!お楽しみに!
显示更多
0
2
164
57
转发到社区
I wrote a quick new post on "Digital Hygiene". Basically there are some no-brainer decisions you can make in your life to dramatically improve the privacy and security of your computing and this post goes over some of them. Blog post link in the reply, but copy pasting below too. Every now and then I get reminded about the vast fraud apparatus of the internet, re-invigorating my pursuit of basic digital hygiene around privacy/security of day to day computing. The sketchiness starts with major tech companies who are incentivized to build comprehensive profiles of you, to monetize it directly for advertising, or sell it off to professional data broker companies who further enrich, de-anonymize, cross-reference and resell it further. Inevitable and regular data breaches eventually runoff and collect your information into dark web archives, feeding into a whole underground spammer / scammer industry of hacks, phishing, ransomware, credit card fraud, identity theft, etc. This guide is a collection of the most basic digital hygiene tips, starting with the most basic to a bit more niche. Password manager. Your passwords are your "first factor", i.e. "something you know". Do not be a noob and mint new, unique, hard passwords for every website or service that you sign up with. Combine this with a browser extension to create and Autofill them super fast. For example, I use and like 1Password. This prevents your passwords from 1) being easy to guess or crack, and 2) leaking one single time, and opening doors to many other services. In return, we now have a central location for all your 1st factors (passwords), so we must make sure to secure it thoroughly, which brings us to... Hardware security key. The most critical services in your life (e.g. Google, or 1Password) must be additionally secured with a "2nd factor", i.e. "something you have". An attacker would have to be in possession of both factors to gain access to these services. The most common 2nd factor implemented by many services is a phone number, the idea being that you get a text message with a pin code to enter in addition to your password. Clearly, this is much better than having no 2nd factor at all, but the use of a phone number is known to be extremely insecure due to the SIM swap attack. Basically, it turns out to be surprisingly easy for an attacker to call your phone company, pretend they are you, and get them to switch your phone number over to a new phone that they control. I know this sounds totally crazy but it is true, and I have many friends who are victims of this attack. Therefore, purchase and set up hardware security keys - the industrial strength protection standard. In particular, I like and use YubiKey. These devices generate and store a private key on the device secure element itself, so the private key is never materialized on a suspiciously general purpose computing device like your laptop. Once you set these up, an attacker will not only need to know your password, but have physical possession of your security key to log in to a service. Your risk of getting pwned has just decreased by about 1000X. Purchase and set up 2-3 keys and store them in different physical locations to prevent lockout should you physically lose one of the keys. The security keys support a few authentication methods. Look for "U2F" in the 2nd factor settings of your service as the strongest protection. E.g. Google and 1Password support it. Fallback on "TOTP" if you have to, and note that your YubiKeys can store TOTP private keys, so you can use the YubiKey Authenticator app to access them easily through NFC by touching your key to the phone to get your pin when logging in. This is significantly better than storing TOTP private keys on other (software) authenticator apps, because again you should not trust general purpose computing devices. It is beyond the scope of this post to go into full detail, but basically I strongly recommend the use of 2-3 YubiKeys to dramatically strengthen your digital security. Biometrics. Biometrics are the third common authentication factor ("something you are"). E.g. if you're on iOS I recommend setting up FaceID basically everywhere, e.g. to access the 1Password app and such. Security questions. Dinosaur businesses are obsessed with the idea of security questions like "what is your mother's maidan name?", and force you to set them up from time to time. Clearly, these are in the category of "something you know" so they are basically passwords, but conveniently for scammers, they are easy to research out on the open internet and you should refuse any prompts to participate in this ridiculous "security" exercise. Instead, treat security questions like passwords, generate random answers to random questions, and store them in your 1Password along with your passwords. Disk encryption. Always ensure that your computers use disk encryption. For example, on Macs this total no-brainer feature is called "File Vault". This feature ensures that if your computer gets stolen, an attacker won't be able to get the hard disk and go to town on all your data. Internet of Things. More like @internetofshit. Whenever possible, avoid "smart" devices, which are essentially incredibly insecure, internet-connected computers that gather tons of data, get hacked all the time, and that people willingly place into their homes. These things have microphones, and they routinely send data back to the mothership for analytics and to "improve customer experience" lol ok. As an example, in my younger and naive years I once purchased a CO2 monitor from China that demanded to know everything about me and my precise physical location before it would tell me the amount of CO2 in my room. These devices are a huge and very common attack surface on your privacy and security and should be avoided. Messaging. I recommend Signal instead of text messages because it end-to-end encrypts all your communications. In addition, it does not store metadata like many other apps do (e.g. iMessage, WhatsApp). Turn on disappearing messages (e.g. 90 days default is good). In my experience they are an information vulnerability with no significant upside. Browser. I recommend Brave browser, which is a privacy-first browser based on Chromium. That means that basically all Chrome extensions work out of the box and the browser feels like Chrome, but without Google having front row seats to your entire digital life. Search engine. I recommend Brave search, which you can set up as your default in the browser settings. Brave Search is a privacy-first search engine with its own index, unlike e.g. Duck Duck Go which basically a nice skin for Bing, and is forced into weird partnerships with Microsoft that compromise user privacy. As with all services on this list, I pay $3/mo for Brave Premium because I prefer to be the customer, not the product in my digital life. I find that empirically, about 95% of my search engine queries are super simple website lookups, with the search engine basically acting as a tiny DNS. And if you're not finding what you're looking for, fallback to Google by just prepending "!g" to your search query, which will redirect it to Google. Credit cards. Mint new, unique credit cards per merchant. There is no need to use one credit card on many services. This allows them to "link up" your purchasing across different services, and additionally it opens you up to credit card fraud because the services might leak your credit card number. I like and use privacy dot com to mint new credit cards for every single transaction or merchant. You get a nice interface for all your spending and notifications for each swipe. You can also set limits on each credit card (e.g. $50/month etc.), which dramatically decreases the risk of being charged more than you expect. Additionally, with a privacy dot com card you get to enter totally random information for your name and address when filling out billing information. This is huge, because there is simply no need and totally crazy that random internet merchants should be given your physical address. Which brings me to... Address. There is no need to give out your physical address to the majority of random services and merchants on the internet. Use a virtual mail service. I currently use Earth Class Mail but tbh I'm a bit embarrassed by that and I'm looking to switch to Virtual Post Mail due to its much strong commitments to privacy, security, and its ownership structure and reputation. In any case, you get an address you can give out, they receive your mail, they scan it and digitize it, they have an app for you to quickly see it, and you can decide what to do with it (e.g. shred, forward, etc.). Not only do you gain security and privacy but also quite a bit of convenience. Email. I still use gmail just due to sheer convenience, but I've started to partially use Proton Mail as well. And while we're on email, a few more thoughts. Never click on any link inside any email you receive. Email addresses are extremely easy to spoof and you can never be guaranteed that the email you got is a phishing email from a scammer. Instead, I manually navigate to any service of interest and log in from there. In addition, disable image loading by default in your email's settings. If you get an email that requires you to see images, you can click on "show images" to see them and it's not a big deal at all. This is important because many services use embedded images to track you - they hide information inside the image URL you get, so when your email client loads the image, they can see that you opened the email. There's just no need for that. Additionally, confusing images are one way scammers hide information to avoid being filtered by email servers as scam / spam. VPN. If you wish to hide your IP/location to services, you can do so via VPN indirection. I recommend Mullvad VPN. I keep VPN off by default, but enable it selectively when I'm dealing with services I trust less and want more protection from. DNS-based blocker. You can block ads by blocking entire domains at the DNS level. I like and use NextDNS, which blocks all kinds of ads and trackers. For more advanced users who like to tinker, pi-hole is the physical alternative. Network monitor. I like and use The Little Snitch, which I have installed and running on my MacBook. This lets you see which apps are communicating, how much data and when, so you can keep track of what apps on your computer "call home" and how often. Any app that communicates too much is sus, and should potentially be uninstalled if you don't expect the traffic. I just want to live a secure digital life and establish harmonious relationships with products and services that leak only the necessary information. And I wish to pay for the software I use so that incentives are aligned and so that I am the customer. This is not trivial, but it is possible to approach with some determination and discipline. Finally, what's not on the list. I mostly still use Gmail + Gsuite because it's just too convenient and pervasive. I also use 𝕏 instead of something exotic (e.g. Mastodon), trading off sovereignty for convenience. I don't use a VoIP burner phone service (e.g. MySudo) but I am interested in it. I don't really mint new/unique email addresses but I want to. The journey continues. Let me know if there are other digital hygiene tips and tricks that should be on this list. Link to blog post version in the reply, on my brand new Bear ʕ•ᴥ•ʔ blog cute 👇
显示更多
0
697
26.5K
3.5K
转发到社区