慣性聚合 高效追讀感興趣之博客、新聞、科技資訊
閱原文 以慣性聚合開啟

推薦訂閱源

Y
Y Combinator Blog
D
Docker
Stack Overflow Blog
Stack Overflow Blog
IT之家
IT之家
Google DeepMind News
Google DeepMind News
阮一峰的网络日志
阮一峰的网络日志
爱范儿
爱范儿
J
Java Code Geeks
博客园 - 司徒正美
S
SegmentFault 最新的问题
Jina AI
Jina AI
小众软件
小众软件
A
About on SuperTechFans
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
V
Visual Studio Blog
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Martin Fowler
Martin Fowler
V
V2EX

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python)
慎哉!自拍照或泄指纹。
Rishu · 2026-06-15 · via DEV Community
夫汝自拍照中出平手示意,而上传之。然此照片或已暴露不可更改之事——汝指纹。 何以可能乎? 指纹沟壑乃实体结构,在佳光线下,高分辨率相机及手指近镜头时,沟壑投射微小阴影显于照片之中。人工智能图像增强工具可放大此细节,提取沟壑模式,并绘出生物识别系统用于匹配之独特标识点。 自此以后,有心之人可用果冻或硅胶制造物理假指,并将其置于真实指纹扫描器前。此即所谓展示攻击也。 此事已发生矣: 2013年——Apple TouchID于48小时内被攻破 混沌计算机俱乐部自iPhone玻璃表面提取指纹,增强图像后,用之制造果冻假指而解锁手机。 2014年——默克尔总理指纹从新闻照片中重建 研究者Jan Krissler(“Starbug”)仅使用公开获取的高分辨率照片重建了德国总理的手指指纹——无需物理接触。 2017年——平手自拍照被列为风险 日本国立信息学研究所警告称,在现代相机3米内拍摄的平手手势足以暴露足够指尖细节以进行指纹重建。 2019年——AI生成“MasterPrints”欺骗扫描器 纽约大学研究者生成合成指纹,匹配大量真实指纹,揭示了部分指纹传感器之脆弱性。 当密码泄露时,汝可更改之。然汝十指终不可改也。被窃取之指纹永不可复原——无重置之道。 风险显著增加若: 照片高分辨率且手指靠近相机 光线自然或侧光(产生沟壑阴影) 照片在线上公开可见 使用如平手或点赞等手势近镜头 对于大多数随意自拍照而言,当前风险较低。但AI工具发展迅速,今日上传的照片将在未来更强大的工具面前存在。 汝应做之事: 勿将指纹视为密码。此乃非秘密之物——汝触碰一切皆留有其迹。用以便利而非唯一安全门径。 为银行及敏感应用启用PIN或密码与生物识别并行 注意高分辨率照片中近镜头手势 若开发生物识别,务必实施多重认证——勿单独使用指纹 总而言之: 指纹永久存在。自拍照永存。AI每年进步。 此威胁真实、记录且增长。解决之道不是停止拍照——而是停止过度信任指纹验证如同其为汝独知之秘密一般。 发现有用乎?分享之——此刻大多数用指纹解锁手机之人对此风险一无所知。