Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think it has the potential to be used as a 2FA. However, for this to work - much more training data is required.


Maybe better as locking trigger. When a system detect the previously authenticated user is no longer the active user it could lock keychains, tokens and sudo timers. This is less intrusive compared to locking a complete system every time you take a step out of the room.


It doesn't seem like using it for automatic 2FA would be practical. For one thing, it wouldn't allow for password managers, and if the environment changes significantly it wouldn't match up (on mobile, using an on-screen or touch keyboard, finger pecking on a laptop while eating at the dinner table, etc.)


I imagined that it would just ask to enter a pre-defined phrase along with the password.


it used in Coursera to detect students (e.g., make sure that the assignment is submitted by the authorized user)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: