Replacing Passwords With The Subconscious Mind

It sounds like something out of a spy novel. Someone tries to coerce you into revealing your computer password. You might be tempted to give in — but it is impossible for you to reveal your credentials, because you do not actually know them. They are buried in your subconscious.
A team of researchers from Stanford and Northwestern universities and SRI International presented a system based on this idea at the 2012 USENIX Security Symposium. Their paper — "Neuroscience Meets Cryptography: Designing Crypto Primitives Secure Against Rubber Hose Attacks," led by Stanford's Hristo Bojinov — targets the weakest link in any security system: the human user.
The trick is a concept from neuroscience called implicit learning: the process by which you absorb new information without being aware that you have learned anything — like learning to ride a bike. The researchers built a simple computer game, something like Guitar Hero, in which players tap keys as dots descend on a screen. Hidden within the game was a sequence of 30 successive positions that repeated more than 100 times during a 30-to-45-minute session.
The players' brains unconsciously learned the pattern. Their error rates dropped as they played — and they still remembered it two weeks later. Yet when asked, none of them could consciously identify the sequence.
Authentication works the same way in reverse. To log in, the user plays a round of the game in which their trained sequence is interspersed with random ones. To pass, they must reliably perform better on their own sequence. Since they cannot recite what they know, no amount of coercion — what cryptographers grimly call a "rubber hose attack" — can extract it.
The researchers envision applications where the stakes justify the hassle: high-security government installations, nuclear facilities, military access. They are upfront about the limits — hundreds of players were tested in initial experiments, and nobody is proposing this for your email login tomorrow.
But the underlying insight is striking. For decades, authentication has been about who you are (biometrics), what you know (passwords), or what you have (tokens). This proposes a fourth category: what you know without knowing you know it. The human memory system turns out to be both more fragile and more capable than the security models built on top of it.
Related Stories
Archive: Mark Rober's 2014 Demo of How Your ATM PIN Can Be Stolen
In August 2014, YouTuber Mark Rober showed how a phone thermal camera can read your ATM PIN from keypad heat — and the simple trick that defeats it.

How Important Is a Good Night's Sleep?
Chronic sleep deprivation raises the risk of heart disease, diabetes, and dementia. Sleep is not downtime; it is maintenance.

Text Messages Direct to Your Contact Lens
Belgian researchers built a curved LCD display that fits inside a contact lens, promising text messages and directions projected straight onto the eye.