Interesting

Replacing Passwords With The Subconscious Mind

Replacing Passwords With The Subconscious Mind

It sounds like something out of a spy novel. Someone tries to coerce you into revealing your computer password. You might be tempted to give in — but it is impossible for you to reveal your credentials, because you do not actually know them. They are buried in your subconscious.

A team of researchers from Stanford and Northwestern universities and SRI International presented a system based on this idea at the 2012 USENIX Security Symposium. Their paper — "Neuroscience Meets Cryptography: Designing Crypto Primitives Secure Against Rubber Hose Attacks," led by Stanford's Hristo Bojinov — targets the weakest link in any security system: the human user.

The trick is a concept from neuroscience called implicit learning: the process by which you absorb new information without being aware that you have learned anything — like learning to ride a bike. The researchers built a simple computer game, something like Guitar Hero, in which players tap keys as dots descend on a screen. Hidden within the game was a sequence of 30 successive positions that repeated more than 100 times during a 30-to-45-minute session.

The players' brains unconsciously learned the pattern. Their error rates dropped as they played — and they still remembered it two weeks later. Yet when asked, none of them could consciously identify the sequence.

Authentication works the same way in reverse. To log in, the user plays a round of the game in which their trained sequence is interspersed with random ones. To pass, they must reliably perform better on their own sequence. Since they cannot recite what they know, no amount of coercion — what cryptographers grimly call a "rubber hose attack" — can extract it.

The researchers envision applications where the stakes justify the hassle: high-security government installations, nuclear facilities, military access. They are upfront about the limits — hundreds of players were tested in initial experiments, and nobody is proposing this for your email login tomorrow.

But the underlying insight is striking. For decades, authentication has been about who you are (biometrics), what you know (passwords), or what you have (tokens). This proposes a fourth category: what you know without knowing you know it. The human memory system turns out to be both more fragile and more capable than the security models built on top of it.

securityneurosciencepasswordsStanford

Related Stories