Live data from Hacker News

Behavioral Profiling: The password you can't change

paul.reviews

1–10 of 99 posts

Re: Behavioral Profiling: The password you can't change

#4
post #3

It sounds great and much more protective than passwords. You can't copy/imitate behaviors. However, I am wondering if the system still works if you are tired or sick. Your behavior might change in this case and therefore the system would not recognise you.

That's the first thing I thought of, tired or sick. Or how many times I've used one hand to type in my password because I had a drink or food in my other.

How would mobile work with this? Sometimes I use both fingers, sometimes just my thumb on one hand. Would it just create multiple behavior profiles for me that are accepted?

In combination of the right password and the behavior match, it seems like this would actually be pretty strong. I'm looking forward to trying to break it tomorrow with a friend.

Re: Behavioral Profiling: The password you can't change

#5
post #3

It sounds great and much more protective than passwords. You can't copy/imitate behaviors. However, I am wondering if the system still works if you are tired or sick. Your behavior might change in this case and therefore the system would not recognise you.

I think you misunderstood the intention of this feature. The goal is to identify and/or profile users that themselves use just a regular log-in. This can be then used to improve targeted marketing, selling that information to third-parties for example.

Note how the article mentions that the gender can be determined after a few keystrokes, even though the user never entered that specific information. This is certainly not the only metric that can be identified. The point of the article is to develop a solution to prevent leakage of private/personal information.

Re: Behavioral Profiling: The password you can't change

#6
Would that work if the user changed keyboards? I used Apple keyboards of various types for the last five years, and recently bought myself a new gaming pc with a gaming keyboard — and while WASD feel is great, typing is a nightmare, and I feel that my WPM count is three times smaller than on keyboards I'm used to.

Re: Behavioral Profiling: The password you can't change

#8
I wonder if it makes sense to disable some of that information in JavaScript. You couldn't disable it for js videogames, but I see no reason for most websites to be able to track your behavioral profile.

The problem is that behavioral profiling will get better. How long you stay on a page, which links you prefer, and potentially a lot of the metrics that companies routinely use to A/B test their page would also reveal your behavioral profile.

It's a similar problem to rhetorical analysis. It's difficult to publish a paper anonymously if you have other publications because the rhetoric is likely to have your fingerprint plastered all over it.

Privacy is rapidly eroding and it's not clear the trend can be reversed.

Re: Behavioral Profiling: The password you can't change

#10
We already know that places like Facebook monitor our every keystroke and store them for posterity. Yes, they hang on, also to the text you regretted, backspaced, and never published. It would seem utterly unprofessional, and potentially detrimental to shareholder interest, for them to not also keep track of timings and typing rhythms. Which makes me wonder how much mood analysis, lie detection, and other psychometrics they really have collected on us all over the years, given the right kinds of algorithms to run the lot through.
Post reply on HN