4 ms·
Additionally, I believe they functioned as a hive mind. It would be like an individual trying to keep their password secret from another part of their body. Th
by deftnerd 10y ago
Additionally, I believe they functioned as a hive mind. It would be like an individual trying to keep their password secret from another part of their body.
That brings up an interesting hypothetical... Is it possible to have a password that you don't even know? Sure biometrics is one method, but are there any password schemes that work on things like word associations or unconscious behaviors found during the typing process, like statistical analysis of the time between key presses?
I remember doing an online course and they had me type several paragraphs in order to determine my typing "signature" but it seems doubtful to me that it would be precise enough to be used for authentication.
- comex 10y agoYep, it's possible, at least to some extent. https://www.technologyreview.com/s/515726/a-password-so-secret-you-dont-consciously-know-it/ https://www.technologyreview.com/s/515726/a-password-so-secr...
- pimlottc 10y ago> Is it possible to have a password that you don't even know? Certainly, that's why the "forget password" link is so common ;)
- ucho 10y ago> It would be like an individual trying to keep their password secret from another part of their body. Trying to recall a password that I commited only to muscle memory is damn near impossible without some kind of keyboard in front of me.
- pavel_lishin 10y agoI'm not convinced that they were a hive mind, but that's a discussion for another forum :P (edit: in fact, I went ahead and posted the question: https://www.reddit.com/r/AskScienceFiction/comments/4x7yin/independence_day_the_aliens_were_clearly/ https://www.reddit.com/r/AskScienceFiction/comments/4x7yin/i...)
- yuubi 10y ago> Is it possible to have a password that you don't even know? Seemingly, yes, according to https://www.usenix.org/conference/usenixsecurity12/technical-sessions/presentation/bojinov https://www.usenix.org/conference/usenixsecurity12/technical... , which has a paper I read a while ago and a video I never got around to watching. Abstract: Cryptographic systems often rely on the secrecy of cryptographic keys given to users. Many schemes, however, cannot resist coercion attacks where the user is forcibly asked by an attacker to reveal the key. These attacks, known as rubber hose cryptanalysis, are often the easiest way to defeat cryptography. We present a defense against coercion attacks using the concept of implicit learning from cognitive psychology. Implicit learning refers to learning of patterns without any conscious knowledge of the learned pattern. We use a carefully crafted computer game to plant a secret password in the participant’s brain without the participant having any conscious knowledge of the trained password. While the planted secret can be used for authentication, the participant cannot be coerced into revealing it since he or she has no conscious knowledge of it. We performed a number of user studies using Amazon’s Mechanical Turk to verify that participants can successfully re-authenticate over time and that they are unable to reconstruct or even recognize short fragments of the planted secret.