I hope these services have an opt-out. I know, I know, this will get infinitely more accurate at an arbitrary point in the future, and that I won't have complaints then. But I get screwed constantly while travelling to other countries, getting repeatedly locked out of Gmail. Again, most users won't face these issues. But I don't want to live in a world where if you're not a nominal case, you're screwed. The people wh…
> The people who think passwords are hard will keep getting older and will be washed away. I wonder if younger generations use more secure passwords. I'd guess that the typical user does not.
Behavioral Profiling: The password you can't change
71–80 of 99 posts
Re: Behavioral Profiling: The password you can't change
#72I hope these services have an opt-out. I know, I know, this will get infinitely more accurate at an arbitrary point in the future, and that I won't have complaints then. But I get screwed constantly while travelling to other countries, getting repeatedly locked out of Gmail. Again, most users won't face these issues. But I don't want to live in a world where if you're not a nominal case, you're screwed. The people wh…
A temporary way to opt-out of some of these things might be a good thing. I am on the glass half empty side of if user passwords will improve on a scale required. Even if you get to 90% of users using a good enough password, that still seems too low. For an average user, it is difficult to use a different password AND remember it, and that barrier probably will not change much. Many users still aren't going to start…
Moreover, in the mobile dominant world, use of public computers is very less. So typically an authenticated session would last months or years, rather than a few hours. So it is less of an annoyance.
Re: Behavioral Profiling: The password you can't change
#73Re: Behavioral Profiling: The password you can't change
#74Earlier quoted context omitted.
True - I was thinking "what happens if I burn my finger while cooking?" It does seem like a solution looking for a problem.
Or, what if I've had a few beers and my typing is getting sloppier.
Re: Behavioral Profiling: The password you can't change
#75Re: Behavioral Profiling: The password you can't change
#76Well, yes you can change your behavior, and no, this is not a good idea. We worked in biometrics like 4 years ago or so. It is trivial to defeat this "security mechanism". We had snake oil people trying to convince us to invest in this(we are a software company), so we made a bet: If we could defeat their marvelous thing on a test they will pay all of our tester team a dinner(and go away and don't bother us again). I…
Changing your natural, habitual behavior is hard.
The sad part is, this probably would be pretty effective at catching bots due to the fact they likely are largely repetitive and/or skip the mouse move to simply click a location.
Re: Behavioral Profiling: The password you can't change
#77Well, yes you can change your behavior, and no, this is not a good idea. We worked in biometrics like 4 years ago or so. It is trivial to defeat this "security mechanism". We had snake oil people trying to convince us to invest in this(we are a software company), so we made a bet: If we could defeat their marvelous thing on a test they will pay all of our tester team a dinner(and go away and don't bother us again). I…
Although you are of course right there is something underlying interesting about what could be done to track us in order to build a unique "ghost" of us that can can be used for many purposes beyond logging in. But given I am not an expert in this field I would like to turn around and perhaps ask you, what is the bigger vision? Surely biometrics in all sorts of shapes and forms comes with it's own issues and shortcom…
If you can assemble an AI copy of someone, you have an almost unbeatable weapon against him. You can make him do things that he thinks are his own ideas, just by adjusting the input parameters.
If you want someone to walk on one side of the street, and you know he avoids panhandlers, you put a fake panhandler on the other side. If you want him to slow down or stop at a certain point on that side of the street, and you know he likes motorcycles, you park a custom chopper there. And while he's gawking, you pick his pocket, or bag his head and shove him into a van, or stab him with a drugged needle, or whatever other spy movie crap you might have in mind.
If you have a detailed enough model to authenticate someone, you may also have a good enough model to impersonate them, or to influence their behavior for your own ends.
Re: Behavioral Profiling: The password you can't change
#78Earlier quoted context omitted.
The observation that some usernames are changeable, doesn't contradict the claim that passwords must be changeable, nor does it contradict the claim that usernames need not be changeable.
> the claim that [...] What are you talking about? The comment I replied to didn't make any such claims! > passwords must be changeable Not necessarily. What about fingerprints? > usernames need not be changeable Not necessarily. What about National Insurance / Social Security numbers?
What's the point of a password you can't change? Once it leaks, you're screwed forever.
In the autenticaion realm, there's three main things used: a) who you are ("username") b) what you know ("password") and c) what you have (smartcard, various kinds of dongles). Biometrics of any kind only fit in the first category. The other two must be changeable, or there's no point to them, since they become aliases for the username. Any authentication system needs to assume the password or the what-you-have thingy leaks or is stolen. If they can't be changed, it becomes rather difficult to lock out an attacker while still allowing the legitimate user access.
Re: Behavioral Profiling: The password you can't change
#79If this doesn't get implemented into browsers as a default option or usage of extension doesn't get popular people using this are going to be easy to identify. It's like someone using just normal http and suddenly using https and Tor. You are going to stick out.
I wonder how popular are NoScript/AdBlock percentage wise these days?
Re: Behavioral Profiling: The password you can't change
#80Earlier quoted context omitted.
I wonder how popular are NoScript/AdBlock percentage wise these days?
I tried NoScript for a bit. Obviously most social networks stopped working, but I liked how NYT became free again (since they track you by a cookie) and obviously HN remained solid. Essentially NoScript just means no online socializing, which I think I might grow to become ok with.