Can a person be identified by just the way they type?
blog.wolfram.com
blog.wolfram.com
Gun manufacturers hate it because it has scary gun control implications. But if/when it does become available New Jersey police will all use it.
Keystrokes should be way more distinctive than a trigger pull.
EDIT: Michael Recce is his name, http://www.njit.edu/news/2003/2003-125.php
I would also be fascinated to learn more.
It's not keyed to a specific weapon, but it seems like it would help prevent the most common dangers of either a kid finding and using it accidentally, or in an actual combat situation, being disarmed and having it used against you.
The only major benefit to per-device keying would be (marginal) additional security, and increased auditability
James Bond is chasing a villain. Draws his gun to aim for a long range shot. (Gun has a little green LED on the side) Out of the side lunges a henchman who engages Bond in hand to hand combat. The gun goes skidding away. Henchman wins combat over Bond and runs to the gun. It appears Bond is done for. Henchman draws gun. The LED is red, but the henchman doesn't notice.
<CLICK>
Henchman thinks the gun is out of bullets and flings it at Bond as a projectile and runs at him to reengage hand-to-hand combat. Bond deftly catches the gun. He draws it. The LED is green.
Cue gunbarrel sequence.
I wonder what other 2000AD technologies might start cropping up soon. We already have riot foam, however from what I read it didn't work very well when first used. http://discovermagazine.com/1999/apr/warwithoutdeath1610
Does it also detect the changes under duress?
Really fascinating stuff.
While somewhat of a black box demo, we were able to play with the technology. We tried a ton of stuff to fool the system (physical only, we didn't use keystroke macros or anything like that) and it would correctly identify us every time. It was showing us the probabilities as they'd change and it was uncanny how it would immediately know that I started typing instead of a coworker.
So, it's not only probable/possible/exists, it's only drawback is the lack of necessity. Outside of the the highly paranoid using it to prevent outside intrusions (government mostly), not many systems need it due to lower-end attacks that are much easier to do and typically successful enough.
>it's only drawback is the lack of necessity
No, that's not the only drawback. Be very careful when talking about cryptography and security never to assume that you are aware of all of the weaknesses unless you've got a formal proof.
One very big drawback I can think of off the top of my head is that it would essentially be like having the same password everywhere, and being completely unable to change that password. If someone records your typing style once, they will be able to get to absolutely everything that identifies you based on typing style. At least with retina scans and fingerprints, there are mechanical obstacles to producing a facsimile.
You're right, it's not the only drawback. I just meant that there are many vectors of attack when it comes to network security and so many fail at those that this might be less gain than one might assume at first thought.
The problem is that we have 'server' machines and a system which requires 'root' access to do certain things. We'd love to know who on the operations staff did something on the server (a workaround is to set an environment variable but which works in the 'normal' case but fails if someone is being a bad actor). So you train it up across the org, and then when ever you have a session where the signal from the type sig doesn't match the logged in UID, you alert it (or log it). SO instead of 'root just changed the date to last year' you get 'Chuck just changed the date to last year'. That would be a very very very useful tool to have in one's toolbox.
http://aplawrence.com/Basics/sudo.html
EDIT: noticed the 'root', making a new assumption this is a windows server box.
Without going into operational specifics, the answer is that this doesn't scale.
I'd think it could be more robust than the 'remember to set env X=y before doing stuff' especially for real-time oh shit fix everything moments, as a sort of passive identification, but couldn't hope to stand against a determined adversary.
Erh.. no thank you.
Yeah, no thanks.
Surprisingly enough, that company's userbase absolutely hated carrying tokens and they wanted to bend over backwards to accommodate them. The entire point was to provide an alternative way of doing 2-factor authentication.
The bottom line is that it mostly did work as advertised. The place where it struggled were poor typers of the hunt and peck variety. They just didn't have a good enough pattern and the failure rate was fairly high.
Another weak point would be any type of hand injury or even being under the influence would throw it off completely.
I liked the approach a lot, but ultimately, when it does fail, its extremely frustrating to the end user, since they don't really understand what they did wrong.
Checking long posts on news sites or blogs just to make sure it is the writer would be interesting, but boring and not worth it.
http://www.cs.berkeley.edu/~tygar/keyboard.htm
"We examine the problem of keyboard acoustic emanations.
We present a novel attack taking as input a 10-minute sound recording of a user
typing English text using a keyboard, and then recover- ing up to 96% of typed
characters. There is no need for a labeled training recording. Moreover the
recognizer bootstrapped this way can even recognize random text such as
passwords: In our experi- ments, 90% of 5-character random passwords using only
letters can be generated in fewer than 20 attempts by an adversary; 80% of 10-
character passwords can be generated in fewer than 75 attempts.Now, visit it from a different browser or computer and make another comment - it would log you in as you again, somehow.
Errors would likely make it unpractical, but it'd be an amusing demo for the unaware.
If you got through the problem of people's keystroke speed varying with local factors, you'd wind-up with a situation where not only is your "password" the same on every site, even sites you visited without logging into could "sniff" your "password".
0-factor "identification"!
I.e. THIS POST TO BE DOWNVOTED?
Vs SHOULD THIS POST BE DOWNVOTED?
So the ability of this method to identify you based
on your typing style would require a certain amount
of consistency in the way you type.
Well done, you found the answer. A lot of people can't be positively identified, and the whole thing is error prone.Wish I could remember where I read that; it was some book about hackers in general.
It also have downside - your patter will change overtime and if this is sole authentication measure - it will fail eventually. I would use it as fuzzy monitoring to detect stolen credentials instead.
In either case everybody will have to have a fallback password in case their stride is off one day. If the system works well, then that password will be rarely used. A rarely used password is harder to remember than a regularly used one, so people will choose weak passwords for the fallback.
So the only way that this system has any chance of working without grossly compromising everyone's security, is if it barely ever positively identifies anyone.
Of course, even if it did work perfectly, it would be the equivalent of having the same password everywhere. In that case, why not just memorize one strong password?
Likewise, by making ideas like this, along with an early investigation, perhaps someone can build on it, or throw out another idea, and perhaps people can work together to find a good solution to the mess that is current user identification.
Or would you rather people beavered away in secret, never sharing ideas, never sharing their results, and never working together?
I experimented with this a couple of years ago when I saw that video, by implementing an ajaxy authentication system that timed keystrokes. Ignoring the fact that you could probably keylog the heck out of it, I found that a single user's typing patterns varied substantially, depending on typing skill, input device, and so on. Oh, well.
1. You ask a user to type in a couple of words. 2. Create a profile for them.
so that when you sign up for something you:
3. verify they are who they say they are as they fill out the form. 4. can skip captcha? (i.e. the form filling is the captcha)
?
I'm going with "no" ;-)