4 ms·
Any new constraint on password inputs will result in attackers creating a fake password input without any constraint, via CSS / JS.
by esnard 6y ago
Any new constraint on password inputs will result in attackers creating a fake password input without any constraint, via CSS / JS.
- amelius 6y agoBut an AI in the browser could detect this and warn the user.
- therein 6y agoSo we are throwing machine learning at the problem because we can't come up with the heuristics for this ourselves?
- amelius 6y agoMachine learning is being used in spam filters, so why not use it for this problem too?
- web007 6y agoYes? That's exactly what it's for: finding patterns that are too hard or too complex for humans to find. Enumerating every edge case of "enter a password" is not possible for a human, and whatever edge cases we humans miss _will_ be exploited by someone to compromise someone else. It's also a matter of volume. How many pages can you evaluate and categorize in an hour versus how many can a ML system do in the same? I once saw a demo where a firewall/virus scanner app could detect malware heuristics dynamically by comparing to a baseline system, and could do so in 10 seconds or less per item. It would take a human more than 10 seconds just to read the report to generate a rule, and humans don't scale nearly well enough. There are lots of complaints to be had about ML and privacy / fairness / ethics / effectiveness, but this shouldn't be one of them.