31 karma · joined May 19, 2015
The paper I linked to actually does a good job motivating specific classes of typos by looking at real typos from Dropbox users.
Here's one idea: Let's say the user's password is P. The user enters some password P' with a typo. The authentication check is "does H(T_k(P')) == H(P)" for some set of transformations {T_1, T_2, ..., T_n}. Each transformation T_i hypothesizes that the user made a specific mistake. (e.g., T_1 is the caps lock is on so we need to flip the case of all the characters)
However, there's recent work [0] from Cornell that explores the security-usability tradeoff when correcting password typos. It turns out that accepting specific classes of typos (e.g., caps lock on: if password is "Password" then allow "pASSWORD") can increase usability with minimal security impact.
marionette [2] enables control over what protocol it looks like you're using and duration of connections generated, amount of data sent per connection, etc.
[1] https://fteproxy.org/ [2] https://github.com/marionette-tg/marionette