Live data from Hacker News

Behavioral Profiling: The password you can't change

paul.reviews

21–30 of 99 posts

Re: Behavioral Profiling: The password you can't change

#21

If this doesn't get implemented into browsers as a default option or usage of extension doesn't get popular people using this are going to be easy to identify. It's like someone using just normal http and suddenly using https and Tor. You are going to stick out.

I wonder how popular are NoScript/AdBlock percentage wise these days?

Re: Behavioral Profiling: The password you can't change

#23
I might not get everything right, but aren't they proposing "kind of" a keylogger as a security solution? Even the idea of using a technology for which others build products to fight against seems a bit strange.

Now, admitting that everyone will use it in good faith, I'd like the fact that, by itself, it does not add another thing you need to do as a user to authenticate. But, as Paul said in his article, I only see it used as a trigger for other security measures.

Re: Behavioral Profiling: The password you can't change

#25
post #17

What a huge nightmare waiting to happen. Sites already give me shit for changing my location, making me jump through additional hoops because my browser signature changed, refusing to let me purchase something because I don't access them from my home country. The last thing I need is a behavioral profiler that insists it has determined I'm not me and there is nothing I can do to prove it wrong.

True - I was thinking "what happens if I burn my finger while cooking?" It does seem like a solution looking for a problem.

Re: Behavioral Profiling: The password you can't change

#26
post #5
post #3

It sounds great and much more protective than passwords. You can't copy/imitate behaviors. However, I am wondering if the system still works if you are tired or sick. Your behavior might change in this case and therefore the system would not recognise you.

I think you misunderstood the intention of this feature. The goal is to identify and/or profile users that themselves use just a regular log-in. This can be then used to improve targeted marketing, selling that information to third-parties for example. Note how the article mentions that the gender can be determined after a few keystrokes, even though the user never entered that specific information. This is certainly…

> Note how the article mentions that the gender can be determined after a few keystrokes, even though the user never entered that specific information.

Research got median 88% accuracy testing subsets of 98 males and 35 females.

Note that I got 74% accuracy on that data set by guessing male, male, male, male, male...

Re: Behavioral Profiling: The password you can't change

#27

Earlier quoted context omitted.

That would be... disturbing. Fortunately it's not true, as you can see for yourself with the chrome developer tools.

It was true at one stage, according to official acknowledgement form Facebook. There's a discussion somewhere here on Hacker News. Can't find the link right now.

Not quite. Here's a blog post from someone who read the study, and quotes from it:

http://www.dailykos.com/story/2013/12/16/1263165/--Facebook-...

Re: Behavioral Profiling: The password you can't change

#28
post #17

What a huge nightmare waiting to happen. Sites already give me shit for changing my location, making me jump through additional hoops because my browser signature changed, refusing to let me purchase something because I don't access them from my home country. The last thing I need is a behavioral profiler that insists it has determined I'm not me and there is nothing I can do to prove it wrong.

Presumably, such a system would escalate to a more heavy weight authentication. We're already seeing something similar with sites trying to figure out if you're a bot or not. For example, if you make edits on stackoverflow, the site might decide to challenge you with a captcha from time to time.

Re: Behavioral Profiling: The password you can't change

#29
post #5

Earlier quoted context omitted.

I think you misunderstood the intention of this feature. The goal is to identify and/or profile users that themselves use just a regular log-in. This can be then used to improve targeted marketing, selling that information to third-parties for example. Note how the article mentions that the gender can be determined after a few keystrokes, even though the user never entered that specific information. This is certainly…

> Note how the article mentions that the gender can be determined after a few keystrokes, even though the user never entered that specific information. Research got median 88% accuracy testing subsets of 98 males and 35 females. Note that I got 74% accuracy on that data set by guessing male, male, male, male, male...

By knowing in advance what the ratio is. Such a great system will do really well in the real world.

( You have a very ironic username given the circumstances. )

Re: Behavioral Profiling: The password you can't change

#30
post #25
post #17

What a huge nightmare waiting to happen. Sites already give me shit for changing my location, making me jump through additional hoops because my browser signature changed, refusing to let me purchase something because I don't access them from my home country. The last thing I need is a behavioral profiler that insists it has determined I'm not me and there is nothing I can do to prove it wrong.

True - I was thinking "what happens if I burn my finger while cooking?" It does seem like a solution looking for a problem.

Or, what if I've had a few beers and my typing is getting sloppier.
Post reply on HN