Behavioral Profiling: The password you can't change
paul.reviews
paul.reviews
We worked in biometrics like 4 years ago or so. It is trivial to defeat this "security mechanism".
We had snake oil people trying to convince us to invest in this(we are a software company), so we made a bet: If we could defeat their marvelous thing on a test they will pay all of our tester team a dinner(and go away and don't bother us again).
It was as easy as creating a prototype trainer. You record a person typing with a webcam. You make some statistics and then in 10 minutes you could train ANYBODY to copy the same behavior signature.
It took us like 2 hours to create the prototype trainer. After testing it we realized the webcam WAS NOT EVEN NEEDED, the microphone is enough.
So we used a single hidden microphone to record the people chosen by the snake oil team and ALL OF US(10 people) were able to defeat the system. Really fun for us, extremely humiliating for the snake oil people.
BTW: This man is proposing a complete keylogger of all your actions in the computer, what could go wrong?
But given I am not an expert in this field I would like to turn around and perhaps ask you, what is the bigger vision?
Surely biometrics in all sorts of shapes and forms comes with it's own issues and shortcomings.
Isn't the idea to make it good enough not necessarily 100% airtight (although I do understand that the scaleability of technology makes it the requirements many times higher than between people)?
If you can assemble an AI copy of someone, you have an almost unbeatable weapon against him. You can make him do things that he thinks are his own ideas, just by adjusting the input parameters.
If you want someone to walk on one side of the street, and you know he avoids panhandlers, you put a fake panhandler on the other side. If you want him to slow down or stop at a certain point on that side of the street, and you know he likes motorcycles, you park a custom chopper there. And while he's gawking, you pick his pocket, or bag his head and shove him into a van, or stab him with a drugged needle, or whatever other spy movie crap you might have in mind.
If you have a detailed enough model to authenticate someone, you may also have a good enough model to impersonate them, or to influence their behavior for your own ends.
I know this is probably naive sci-fi but I have heard crazier things. I guess at the end of the day it requires that the interfacing is not just digital but also somehow biological/genetic.
Indeed. A behavioral biometric like this is probably most similar to gait recognition (identifying someone by they way they walk). It's slightly better than a 'soft biometric' like skin color and gender, but not good enough for any type of large scale deployment. Usually when researchers show this stuff it's more or less for novelty. With that in mind, there really shouldn't be a 'bigger vision' because recognition rates are usually not good enough to merit anything other than an occasional paper.
Changing your natural, habitual behavior is hard.
The sad part is, this probably would be pretty effective at catching bots due to the fact they likely are largely repetitive and/or skip the mouse move to simply click a location.
I allege that this would have a huge number of false positives for no discernible reason to begin with, but on top of that: I might be on a different keyboard, using a different mouse, using a track pad, might be in bed lazily trying to log in with my laptop, might be injured, might be distracted, I might be in another country using an unfamiliar keyboard layout, a different screen size, the list goes on...
But I get screwed constantly while travelling to other countries, getting repeatedly locked out of Gmail. Again, most users won't face these issues. But I don't want to live in a world where if you're not a nominal case, you're screwed.
The people who think passwords are hard will keep getting older and will be washed away. The generation coming in thinks paper is a broken iPad. So exactly, why do we need to solve the problem of passwords, when even slightly savvy users can handle it. Is it so hard to figure out that not too long in future, you can expect all your users to be comfortably savvy?
Also, passwords are deterministic and are a better UI. The Android Lollipop's on-body smart lock, for example, is pure non-deterministic headache. Haven't we gone through this with automatic sliding doors already?
I wonder if younger generations use more secure passwords. I'd guess that the typical user does not.
I am on the glass half empty side of if user passwords will improve on a scale required. Even if you get to 90% of users using a good enough password, that still seems too low. For an average user, it is difficult to use a different password AND remember it, and that barrier probably will not change much. Many users still aren't going to start using a password safe.
The article mentions but dismisses multi-factor as degrading the user experience. But I think with the dominance of mobile devices, that providing a simple multi-factor token has become easier than carrying an RSA dongle. I find Google's use of the SMS token to be quite convenient.
Moreover, in the mobile dominant world, use of public computers is very less. So typically an authenticated session would last months or years, rather than a few hours. So it is less of an annoyance.
This sort of thing is useful as a signal when deciding if a user is who they say they are, but it's not sufficient on it's own.
It would be another thing an intruder would have to bypass, and it could be constructed loosely enough to not interfere with a normal work day. Essentially just a flag, rather than a lock-out if it detects a failure.
I imagine a suite of behavior heuristics would be something of interest to a big enterprise company.
Assuming all websites using reCAPTCHA are not worth using seems ridiculous to me.
You throw humans and robots in the same basket and tell all of them to solve a puzzle or you won't talk to them.
To suggest it's a "dismissive attitude" to not want to be hassled due to some other bad actor implies looking at it from the business perspective, and not necessarily from the perspective of the effect it has on users.
Note that certain adware/spyware domains, like google-analytics( look at the tags <maybe-spy> and <maybe-ads> ), are commented out, so edit the file as per your needs.
Google's re-capthas are coming from google.com, to block them add:
127.0.0.1 google.com
127.0.0.1 www.google.com
This may be a tough choice to make, depending on how integrated has Google become with your life ( note how I phrased this relationship ).
The only thing that wouldn't transfer would be your valuable internet points.
What are you talking about? The comment I replied to didn't make any such claims!
> passwords must be changeable
Not necessarily. What about fingerprints?
> usernames need not be changeable
Not necessarily. What about National Insurance / Social Security numbers?
What's the point of a password you can't change? Once it leaks, you're screwed forever.
In the autenticaion realm, there's three main things used: a) who you are ("username") b) what you know ("password") and c) what you have (smartcard, various kinds of dongles). Biometrics of any kind only fit in the first category. The other two must be changeable, or there's no point to them, since they become aliases for the username. Any authentication system needs to assume the password or the what-you-have thingy leaks or is stolen. If they can't be changed, it becomes rather difficult to lock out an attacker while still allowing the legitimate user access.
This doesn't make sense. You cannot "use a username as a password".
Fingerprints, retina scans, DNA samples, etc are biometric passwords. They are unique identifiers to your identification, and cannot be changed for obvious reasons.
The entire concept of "biometric passwords" is flawed, because as you see, they "cannot be changed for obvious reasons". One of the most important things about passwords (and passphrases!) is that they may be changed at any time. Every time there is an unauthorized data dump, we get lists of thousands of passwords or hashes thereof. Therefore, anyone who protects important assets with passwords should change them regularly. Anyone whose biometric data is stored in a database will eventually have that dumped as well.
The day is quickly approaching when none of these biometric measures will be private anyway. With that in mind, they could perhaps be used as public identifiers, "usernames" if you will. In that sense they might be similar to the SSN, another datum that is clearly unsuitable as a password, even though hundreds of stupid organizations have used it as such.
The problem is that behavioral profiling will get better. How long you stay on a page, which links you prefer, and potentially a lot of the metrics that companies routinely use to A/B test their page would also reveal your behavioral profile.
It's a similar problem to rhetorical analysis. It's difficult to publish a paper anonymously if you have other publications because the rhetoric is likely to have your fingerprint plastered all over it.
Privacy is rapidly eroding and it's not clear the trend can be reversed.
By the way, it's funny how often the discussions turn into "we need to stop technology X because evil advertisers will use it to do their evil things". It's not technology X that is the problem, it's evil advertisers that are assholes, and we need to find the way to get rid of the latter, not the former.
At this point we have to drag out the heavy philosophical tools and ask: what do we mean by progress? The "Whig view of history" is one of incremental improvement towards better states, but it's reasonable to ask what we mean by "better" and how the progress itself affects our view on what is better.
We also need to bear in mind that it's not just future governments but present governments in various parts of the world that will weaponise technology for control purposes. Behavioural analysis as part of the Great Firewall of China?
And as a society I think we're going to need coping strategies. Trying to protect privacy is only going to delay the eventual meltdown of privacy in our lives.
I think we are making good strides already though. There is less stigma around porn, around homosexuality, around fetishes. Religious tolerance also seems to be increasing. There are still problem points, but I think the trends are in the right direction. I'm happy to be proven wrong on this point though.
Log in from your laptop vs desktop and you're (presumably) going to have to have 1 profile for each.
[1] - http://features.jsomers.net/how-i-reverse-engineered-google-...
http://www.dailykos.com/story/2013/12/16/1263165/--Facebook-...
And then there's Rowhammer (http://googleprojectzero.blogspot.com/2015/03/exploiting-dra...).
I would love to know more about this. Online ad networks have access to mouse movement patterns on web pages, but users (usually) don't enter data through keyboard on such pages. And I would expect they already use this mouse movement data to catch fraud... I wonder if it can be used to identify users?
Now, admitting that everyone will use it in good faith, I'd like the fact that, by itself, it does not add another thing you need to do as a user to authenticate. But, as Paul said in his article, I only see it used as a trigger for other security measures.
My problem with all of this prfiling/bio-metrics is an extension of the problem with retinal scanning. It isn't a question of if it works or not, but of what information other than identity does it leak.
How would mobile work with this? Sometimes I use both fingers, sometimes just my thumb on one hand. Would it just create multiple behavior profiles for me that are accepted?
In combination of the right password and the behavior match, it seems like this would actually be pretty strong. I'm looking forward to trying to break it tomorrow with a friend.
Note how the article mentions that the gender can be determined after a few keystrokes, even though the user never entered that specific information. This is certainly not the only metric that can be identified. The point of the article is to develop a solution to prevent leakage of private/personal information.
Research got median 88% accuracy testing subsets of 98 males and 35 females.
Note that I got 74% accuracy on that data set by guessing male, male, male, male, male...
( You have a very ironic username given the circumstances. )
In general, I don't believe it is possible to distinguish male and female typing patterns.
What you might be recognising is how people learned to type combined with the size of their hands - that might partly but not exactly break along gender lines. Bucketing people on that basis is just a recipe for awkwardness.
Quote from the paper: We use the public GREYC keystroke benchmark database for this work. It is one of the largest databases (in term of number of users and sessions) in keystroke dynamics. To out knowledge, no existing database contains more individuals. In order to reduce the bias due to this high quantity of male information, we only kept the first n male samples( where n is the number of female samples).
( Don't bother with your response, I won't be reading it. )
Yes. That's their own database which they're talking up, the one that they made to do this research. That's what I was talking about.
>In order to reduce the bias due to this high quantity of male information, we only kept the first n male samples( where n is the number of female samples).
It happens that I didn't read this part.
On reflection, what I understand now is far worse than what I originally understood:
- They have 35 females and 98 males, they take many handwriting samples from each.
- Since the participants provided many samples, these samples appear both in the training set data and in the test set data.
- I use the training set data to figure out if I can recognise the handwriting of the 35 female participants.
- Then I look through the test data to see if I can identify those participants again.
Basically what you've shown is you can identify the handwriting of 35 people if you've already seen it - 88% of the time.
Splitting groups into 'female' and 'male' is a red herring. This method would presumably work, even if I split them into two random groups.
If I'm right, this is not even state-of-the-art. In 2006 they could have been scoring 96%: http://abcnews.go.com/Technology/story?id=97978&page=2
You could use it as an indicator and trigger a warning email.
Love that there's countermeasures already. Well written article, too :)
There are a lot of approaches around (big data, profiling, machine learning, ...) based on the assumption that people usually behave in the same way. And they really do.
This thing is quite the contrary.