Live data from Hacker News

Behavioral Profiling: The password you can't change

paul.reviews

51–60 of 99 posts

Re: Behavioral Profiling: The password you can't change

#51
I hope these services have an opt-out. I know, I know, this will get infinitely more accurate at an arbitrary point in the future, and that I won't have complaints then.

But I get screwed constantly while travelling to other countries, getting repeatedly locked out of Gmail. Again, most users won't face these issues. But I don't want to live in a world where if you're not a nominal case, you're screwed.

The people who think passwords are hard will keep getting older and will be washed away. The generation coming in thinks paper is a broken iPad. So exactly, why do we need to solve the problem of passwords, when even slightly savvy users can handle it. Is it so hard to figure out that not too long in future, you can expect all your users to be comfortably savvy?

Also, passwords are deterministic and are a better UI. The Android Lollipop's on-body smart lock, for example, is pure non-deterministic headache. Haven't we gone through this with automatic sliding doors already?

Re: Behavioral Profiling: The password you can't change

#52
post #17

What a huge nightmare waiting to happen. Sites already give me shit for changing my location, making me jump through additional hoops because my browser signature changed, refusing to let me purchase something because I don't access them from my home country. The last thing I need is a behavioral profiler that insists it has determined I'm not me and there is nothing I can do to prove it wrong.

One of the banks I use had a keyboard profiling feature on their login page for three or four years and discontinued it in the last year or so. The reason: customers hated it because it did not work well enough (i.e. it would reject your login 3-4 times before accepting it).

[deleted]

Re: Behavioral Profiling: The password you can't change

#53
post #47
post #46

Earlier quoted context omitted.

Yes. It's annoying, because it taunts me with efforless click once or twice a day while it wastes my time with the annoying image matching for the rest of the day.

I blocked the domain. If the site presents me with a re-captcha, I don't even have to think whether to use that site.

That's a pretty dismissive attitude. We recently added reCAPTCHA to our sign up flow at Codecademy and it helped combat spam a lot. The site was harder to manage and moderate before we took that little step.

Assuming all websites using reCAPTCHA are not worth using seems ridiculous to me.

Re: Behavioral Profiling: The password you can't change

#54
post #32

Earlier quoted context omitted.

The article doesn't make it sound like this would be a first line of defense, in fact the author seems quite adamant about its infallibility, but even if such algorithms would be used conservatively it would still be a huge hassle. Imagine every major website nudging you with a popup every once in a while: " we don't like the way you're typing, please use our code generator mobile app to prove it's still you ". I all…

Google started doing this to me; I've had a similar message pop up three times in the last week.

They do it if you are on a shared network (like in an office) and someone on the network did something Google doesn't like. Such as scraping them.

Re: Behavioral Profiling: The password you can't change

#55
post #47

Earlier quoted context omitted.

I blocked the domain. If the site presents me with a re-captcha, I don't even have to think whether to use that site.

That's a pretty dismissive attitude. We recently added reCAPTCHA to our sign up flow at Codecademy and it helped combat spam a lot. The site was harder to manage and moderate before we took that little step. Assuming all websites using reCAPTCHA are not worth using seems ridiculous to me.

Captchas are dismissive towards users.

You throw humans and robots in the same basket and tell all of them to solve a puzzle or you won't talk to them.

Re: Behavioral Profiling: The password you can't change

#56
post #47
post #46

Earlier quoted context omitted.

Yes. It's annoying, because it taunts me with efforless click once or twice a day while it wastes my time with the annoying image matching for the rest of the day.

I blocked the domain. If the site presents me with a re-captcha, I don't even have to think whether to use that site.

I guess that can be healthy since that plug-in is undoubtedly used for Google's own profiling to somehow sell more ads, heh.

Re: Behavioral Profiling: The password you can't change

#57
post #56
post #47

Earlier quoted context omitted.

I blocked the domain. If the site presents me with a re-captcha, I don't even have to think whether to use that site.

I guess that can be healthy since that plug-in is undoubtedly used for Google's own profiling to somehow sell more ads, heh.

Don't worry, there are additional blocked domains just for that. :-)

Re: Behavioral Profiling: The password you can't change

#59
post #17

What a huge nightmare waiting to happen. Sites already give me shit for changing my location, making me jump through additional hoops because my browser signature changed, refusing to let me purchase something because I don't access them from my home country. The last thing I need is a behavioral profiler that insists it has determined I'm not me and there is nothing I can do to prove it wrong.

Get your own personal assistant robot, Intel Jimmy-style, switch into a personality profile of your choice (I am in an Amazon mood today, next I want to shop on eBay etc.) and voilà! Pas de problème!

Re: Behavioral Profiling: The password you can't change

#60
post #55

Earlier quoted context omitted.

That's a pretty dismissive attitude. We recently added reCAPTCHA to our sign up flow at Codecademy and it helped combat spam a lot. The site was harder to manage and moderate before we took that little step. Assuming all websites using reCAPTCHA are not worth using seems ridiculous to me.

Captchas are dismissive towards users. You throw humans and robots in the same basket and tell all of them to solve a puzzle or you won't talk to them.

I understand your point, but do you have a better suggestion to solve the spam problem? It's a really hard problem, and CAPTCHAs do a reasonable job of solving it at low cost to the end user.
Post reply on HN