Privacy concerns of implicit secondary factors for web authentication
Joseph Bonneau, Edward W. Felten, Prateek Mittal, Arvind Narayanan · 2014
These implicit factors can help transform authentication from a binary decision problem (based on passwords alone) into a classification problem with a spectrum of possible decisions. For example, unusual values for implicit factors can be used as an indicator to detect merely suspicious logins for which additional explicit authentication actions (such as sending an SMS code) can be taken. Alternately, known values for implicit factors can be used as an indicator that it is safe to relax normal rate-limiting constraints and avoid frustrating users by locking them out due to typos (or worse, requiring password resets). We highlight three distinct privacy issues in the next three sections. The first is well known from biometrics, whereas the second two appear specific to some web-based implicit factors. We observe that most of the published work on implicit factors has paid little or no attention to these issues. We are limiting our focus to web-based authentication. Implicit factors are also commonly mentioned for use in mobile devices, typically touchscreen-based smartphones and tablets, but privacy concerns are fundamentally different as data can be stored on-device and authentication implemented at the OS level. However, some proposals involve