Live data from Hacker News

Behavioral Profiling: The password you can't change

paul.reviews

41–50 of 99 posts

Re: Behavioral Profiling: The password you can't change

#41
post #17

What a huge nightmare waiting to happen. Sites already give me shit for changing my location, making me jump through additional hoops because my browser signature changed, refusing to let me purchase something because I don't access them from my home country. The last thing I need is a behavioral profiler that insists it has determined I'm not me and there is nothing I can do to prove it wrong.

One of the banks I use had a keyboard profiling feature on their login page for three or four years and discontinued it in the last year or so. The reason: customers hated it because it did not work well enough (i.e. it would reject your login 3-4 times before accepting it).

Re: Behavioral Profiling: The password you can't change

#42
How is the profiling data supposed to be used theoretically? I hope not as a full login. I'd count it as a "what you are" type of item like a fingerprint and would just only want to use it as a username. I think session expiration could actually be an interesting use case. Instead of/in addition to "session expires after X minutes" you could expire the session after the behavioral delta is big enough. But I'd assume a different login mechanism. Could be good session hijacking protection, especially for applications that require regular interaction anyway.

Love that there's countermeasures already. Well written article, too :)

Re: Behavioral Profiling: The password you can't change

#43
post #29

Earlier quoted context omitted.

By knowing in advance what the ratio is. Such a great system will do really well in the real world. ( You have a very ironic username given the circumstances. )

The original researcher knows in advance what the ratio is, yes, that's my point. I'm illustrating that the research is not very good. They couldn't even identify women to take part in the study. Given the numbers involved, it certainly isn't Facebook-ready. In general, I don't believe it is possible to distinguish male and female typing patterns. What you might be recognising is how people learned to type combined w…

Fabricating facts and using ad-hominem is not a very good way of backing up your arguments.

Quote from the paper: We use the public GREYC keystroke benchmark database for this work. It is one of the largest databases (in term of number of users and sessions) in keystroke dynamics. To out knowledge, no existing database contains more individuals. In order to reduce the bias due to this high quantity of male information, we only kept the first n male samples( where n is the number of female samples).

( Don't bother with your response, I won't be reading it. )

Re: Behavioral Profiling: The password you can't change

#44
post #42

How is the profiling data supposed to be used theoretically? I hope not as a full login. I'd count it as a "what you are" type of item like a fingerprint and would just only want to use it as a username. I think session expiration could actually be an interesting use case. Instead of/in addition to "session expires after X minutes" you could expire the session after the behavioral delta is big enough. But I'd assume…

Practically speaking, you will get advertisements, that have a measurably larger chance of you following up on them, i.e. targeted adds.

Re: Behavioral Profiling: The password you can't change

#46
post #45

Isn't Google's recaptcha already doing this? http://www.wired.com/2014/12/google-one-click-recaptcha/

Yes. It's annoying, because it taunts me with efforless click once or twice a day while it wastes my time with the annoying image matching for the rest of the day.

Re: Behavioral Profiling: The password you can't change

#47
post #46
post #45

Isn't Google's recaptcha already doing this? http://www.wired.com/2014/12/google-one-click-recaptcha/

Yes. It's annoying, because it taunts me with efforless click once or twice a day while it wastes my time with the annoying image matching for the rest of the day.

I blocked the domain. If the site presents me with a re-captcha, I don't even have to think whether to use that site.

Re: Behavioral Profiling: The password you can't change

#48
post #43

Earlier quoted context omitted.

The original researcher knows in advance what the ratio is, yes, that's my point. I'm illustrating that the research is not very good. They couldn't even identify women to take part in the study. Given the numbers involved, it certainly isn't Facebook-ready. In general, I don't believe it is possible to distinguish male and female typing patterns. What you might be recognising is how people learned to type combined w…

Fabricating facts and using ad-hominem is not a very good way of backing up your arguments. Quote from the paper: We use the public GREYC keystroke benchmark database for this work. It is one of the largest databases (in term of number of users and sessions) in keystroke dynamics. To out knowledge, no existing database contains more individuals. In order to reduce the bias due to this high quantity of male informatio…

>We use the public GREYC keystroke benchmark database

Yes. That's their own database which they're talking up, the one that they made to do this research. That's what I was talking about.

>In order to reduce the bias due to this high quantity of male information, we only kept the first n male samples( where n is the number of female samples).

It happens that I didn't read this part.

On reflection, what I understand now is far worse than what I originally understood:

- They have 35 females and 98 males, they take many handwriting samples from each.

- Since the participants provided many samples, these samples appear both in the training set data and in the test set data.

- I use the training set data to figure out if I can recognise the handwriting of the 35 female participants.

- Then I look through the test data to see if I can identify those participants again.

Basically what you've shown is you can identify the handwriting of 35 people if you've already seen it - 88% of the time.

Splitting groups into 'female' and 'male' is a red herring. This method would presumably work, even if I split them into two random groups.

If I'm right, this is not even state-of-the-art. In 2006 they could have been scoring 96%: http://abcnews.go.com/Technology/story?id=97978&page=2

Re: Behavioral Profiling: The password you can't change

#49
> Most (if not all) behavioral profiling systems check your mouse movements too. However in my experience, mouse movements do not provide sufficient metadata to accurately identify a user

I would love to know more about this. Online ad networks have access to mouse movement patterns on web pages, but users (usually) don't enter data through keyboard on such pages. And I would expect they already use this mouse movement data to catch fraud... I wonder if it can be used to identify users?

Re: Behavioral Profiling: The password you can't change

#50
post #7

If you can't change it, it's a username, not a password.

There are plenty of sites that allow you to change your username!

The observation that some usernames are changeable, doesn't contradict the claim that passwords must be changeable, nor does it contradict the claim that usernames need not be changeable.
Post reply on HN