You’re probably used to using your fingerprint to get into your phone. Or maybe you even smile for facial recognition in your everyday life.
But fingerprints and faces are just the beginning when it comes to biometrics. The next wave in security: identifying online users through digital behavior.
Whether you type, swipe, tap or click, the way you move -- or behave--- on digital devices is unique to you and now it can be tracked.
“Behavioral biometrics is a technology that uses artificial intelligence to develop a profile of a user based on the behaviors that they exhibit when they log into a website or an application,” said Jordan Blake, vice president of product management at biometrics company BehavioSec.
Blake said their technology tracks how you type, like time between keystrokes, or how you hold a device, but not what you type, like username or password.
Clients, like banks or e-tailers, use it to monitor and store customers’ digital behavioral characteristics.
“We build a profile. It usually takes a few sessions for us to recognize that you are who you are," Blake said. "And then after that, we're able to tell whether a fraudster or an intruder or someone else is trying to log into your account, even if they have the correct credentials.”
There are many biometrics options, including Biocatch, Typing DNA and Biometric Signature ID. They may work a speck differently, but they tout that proper identification is the mission.
Blake said that if done right, users won’t even know the technology is there.
“It's literally doing it all in the background," he said.
Pam Dixon, with the World Privacy Forum, agreed that this is the next wave in fraud protection, but she has a concern.
“There's really very little biometric regulation in the United States,” she said.
Dixon wants clear rules on notifying people if biometrics are being used and what’s being done with the information.
"If it's ever sold or used apart from any security purpose immediately related to, you know, the transaction at that website, it's inappropriate," Dixon said.
She’s also concerned that health information could be detected from, say, finger pulses or tremors, and used. Blake says that isn’t likely.
“The answer to that is, in theory, potentially in the future, this technology could be used. But in its current implementation, that information would be very, very difficult to glean," Blake said.
Behavioral biometrics is still new in the U.S. Behaviosec is currently working with some government agencies and is testing the technology with some banks. Another company, Biocatch, touts success with a top U.S. bank.
So what happens if possible fraud is detected? Blake said it is up to the company using the technology. Some banks, for example, might log you out of the transaction until you can offer further confirmation or call to confirm.
It’s important to note that everyone interviewed for this article said that a robot’s (bot’s) behavior looks very different from human behavior and can be easily detected.