Skip to main content

Asking questions about smartphone use for logins may stop Netflix password sharing

A password screen with an indecipherable password inputted.
Image used with permission by copyright holder
Who was the first person to text you this morning? What song did you listen to during dinner last night? Which of the following news sites did you not browse this morning? These types of questions could act as superior forms of user authentication to the traditional passwords people use today when they log in to apps and websites, according to five researchers.

In a paper titled “ActivPass: Your Daily Activity is Your Password,” a group of researchers located in universities in Texas, Illinois, and India lay out a novel approach to improving the security of login activity. The main thrust of ActivPass is to observe a user’s recent Facebook, browser, phone, and SMS activities and ask them questions based on those activities, which in an ideal world only the users themselves would be able to answer. For example, “From whom did you get your first call this morning?” could be a question posed to a user when they try logging in to a website.

The ActivPass project aims to address areas where traditional passwords are failing, including the increasing burden on users to remember a growing number of passwords (or to ease that burden by choosing common passwords that diminish security), sharing of passwords for cloud-based services like Netflix, and the increasing vulnerability of passwords being stolen.

Users would be able to configure the system to determine how many questions must be answered for successful authentication, whether multiple-choice questions can be asked, and permissions to activity logs.

After an experiment involving 70 participants and their smartphone activity logs (tracked with an app), the researchers say their end-to-end ActivPass system was successful (i.e., authenticated legitimate users) 95 percent of the time. However, it was also compromised (i.e., authenticated impostors) 5.5 percent of the time.

“While this level of security is obviously inadequate for serious authentication systems, certain practices such as password sharing can immediately be thwarted from the dynamic nature of passwords,” according to the paper. While someone may be willing to share a password for their Netflix account with a friend, they may not be as willing to share their personal activities.

The researchers are speaking with companies like Yahoo and Intel to gauge how useful this approach to passwords could be for enterprise users and what could be done to make it work, said Romit Roy Choudhury, an associate professor at University of Illinois at Urbana-Champaign and a co-author of the paper, in an interview with MIT Technology Review.

Editors' Recommendations

Jason Hahn
Jason Hahn is a part-time freelance writer based in New Jersey. He earned his master's degree in journalism at Northwestern…
Huawei’s gorgeous Pura 70 phones just got expanded availability
Huawei Pura 70 pink, green, white, and black colors.

Huawei Pura 70 Huawei

After being announced for China in mid-April, the Huawei Pura 70 series is now confirmed for the EU market. Those in the European market can expect to preorder the Pura 70, Pura 70 Pro, and the top-tier Pura 70 Ultra starting May 2 for 999 euros, 1,199 euros, and 1,499 euros, respectively. This pricing is in line with what we saw in China, with the Ultra coming in at 9,999 yuan ($1,400) and the base Pura 70 at 5,499 yuan ($760).

Read more
The Honor Magic 6 RSR is my new favorite Android phone of 2024
Someone holding the Honor Magic 6 RSR outside.

There's no doubt that 2024 has already been an exciting year for Android phones. Samsung wowed us with the Galaxy S24 series at the beginning of the year, the OnePlus 12 and 12R are two of the best phones available right now, and Google is expected to impress later this month with the Google Pixel 8a.

But for the last few weeks, I haven't been thinking about any of those phones. Why? Because I've been using the Honor Magic 6 RSR. After launching in China this past March, the Magic 6 RSR is now available in the EU, and that's allowed more folks than ever to get their hands on the phone. And that's great, because the Honor Magic 6 RSR has quickly become my new favorite Android phone of 2024.
It has some of 2024's best smartphone hardware

Read more
5 phones you should buy instead of the Samsung Galaxy S24 Plus
A Samsung Galaxy S24 Plus laying on concrete.

Looking to upgrade your phone this year? You may be considering Samsung’s new Galaxy S24 Plus, which is the middle child of the S24 lineup. Given how solid the S24 Plus is, that's not a bad idea at all.

But is the Galaxy S24 Plus the best phone you can get? Maybe not, as there are plenty of other great choices that you can choose from as well. Here are some of the best alternatives to the Galaxy S24 Plus that you should take a look at before spending your hard-earned dollars.
Samsung Galaxy S24 Ultra

Read more