How is the profiling data supposed to be used theoretically? I hope not as a full login. I'd count it as a "what you are" type of item like a fingerprint and would just only want to use it as a username.
I think session expiration could actually be an interesting use case. Instead of/in addition to "session expires after X minutes" you could expire the session after the behavioral delta is big enough.
But I'd assume a different login mechanism.
Could be good session hijacking protection, especially for applications that require regular interaction anyway.
Love that there's countermeasures already. Well written article, too :)
Love that there's countermeasures already. Well written article, too :)