<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: BaffiSan</title>
    <description>The latest articles on DEV Community by BaffiSan (@baffisan).</description>
    <link>https://dev.to/baffisan</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4119121%2F1e156857-7b65-481a-8253-c6f13bd9fd30.png</url>
      <title>DEV Community: BaffiSan</title>
      <link>https://dev.to/baffisan</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/baffisan"/>
    <language>en</language>
    <item>
      <title>HOLogram deep dive: the Input Vault — intercepting keystrokes before JavaScript reads them</title>
      <dc:creator>BaffiSan</dc:creator>
      <pubDate>Fri, 25 Sep 2026 07:28:02 +0000</pubDate>
      <link>https://dev.to/baffisan/hologram-deep-dive-the-input-vault-intercepting-keystrokes-before-javascript-reads-them-1knb</link>
      <guid>https://dev.to/baffisan/hologram-deep-dive-the-input-vault-intercepting-keystrokes-before-javascript-reads-them-1knb</guid>
      <description>&lt;p&gt;&lt;em&gt;This is part 3 of "Building HOLogram", a series on the open protocol&lt;br&gt;
for behavioral biometrics protection in the browser.&lt;br&gt;
&lt;a href="https://dev.to/baffisan/why-javascript-can-read-your-behavioral-identity-and-what-hologram-does-about-it-pjo"&gt;Part 0 — introduction&lt;/a&gt; | &lt;a href="https://dev.to/baffisan/hologram-deep-dive-the-persona-mixer-why-random-noise-isnt-enough-1nh"&gt;Part 1 — Persona Mixer&lt;/a&gt; | &lt;a href="https://dev.to/baffisan/hologram-deep-dive-the-behavioral-privacy-budget-controlling-exposure-over-time-2mi5"&gt;Part 2 — Privacy Budget&lt;/a&gt; | Part 3 — Input Vault&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;The ShadowDOM Input Vault is HOLogram's first module — and arguably&lt;br&gt;
its most technically constrained.&lt;/p&gt;

&lt;p&gt;Its job sounds simple: intercept keyboard events before page scripts&lt;br&gt;
can read them, remove the timing information that identifies the user,&lt;br&gt;
and re-emit synthetic events that are functionally identical&lt;br&gt;
but behaviorally anonymous.&lt;/p&gt;

&lt;p&gt;In practice, implementing this correctly requires navigating a minefield&lt;br&gt;
of browser API differences, timing attack surfaces, and semantic&lt;br&gt;
preservation requirements.&lt;/p&gt;




&lt;h2&gt;
  
  
  What the Input Vault must do
&lt;/h2&gt;

&lt;p&gt;The threat model is specific. Keystroke dynamics classifiers extract&lt;br&gt;
&lt;strong&gt;inter-keystroke interval (IKI)&lt;/strong&gt; timing — the time between consecutive&lt;br&gt;
keydown and keyup events — as their primary feature. These intervals,&lt;br&gt;
measured across a typing session, produce a timing signature that is&lt;br&gt;
highly individual and stable across time.&lt;/p&gt;

&lt;p&gt;The Input Vault must:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Intercept&lt;/strong&gt; native keyboard events at the earliest possible point —
before any page script can observe the real timestamps&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Remove&lt;/strong&gt; the timing information — specifically, the high-resolution
timestamps that make IKI measurement possible&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Re-emit&lt;/strong&gt; synthetic events that carry the correct semantic content
(which key was pressed) but not the real timing&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Preserve&lt;/strong&gt; all other aspects of the interaction — the key identity,
the event sequence, the modifier keys — so the page functions correctly&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The semantic content of what you type must be preserved exactly.&lt;br&gt;
The temporal pattern must not.&lt;/p&gt;




&lt;h2&gt;
  
  
  The browser API challenge
&lt;/h2&gt;

&lt;p&gt;This is where the implementation gets complicated.&lt;/p&gt;

&lt;p&gt;Browser extensions operate in a layered security model. Page scripts&lt;br&gt;
run in the page context. Extension content scripts run in an isolated&lt;br&gt;
world that can access the DOM but is separate from the page's JavaScript.&lt;br&gt;
The extension background runs in yet another context.&lt;/p&gt;

&lt;p&gt;The question for the Input Vault is: &lt;strong&gt;at which layer can we intercept&lt;br&gt;
keyboard events before the page sees them?&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Option A: Content script event listener
&lt;/h3&gt;

&lt;p&gt;A content script can register an event listener on &lt;code&gt;document&lt;/code&gt; with&lt;br&gt;
&lt;code&gt;useCapture: true&lt;/code&gt; — which fires during the capture phase, before&lt;br&gt;
the event reaches the page's own listeners.&lt;/p&gt;

&lt;p&gt;This gives us early access to the event, but &lt;strong&gt;not before the page&lt;/strong&gt;.&lt;br&gt;
The capture phase fires before the target and bubble phases, but&lt;br&gt;
a page script that also registers a capture-phase listener on &lt;code&gt;document&lt;/code&gt;&lt;br&gt;
would still receive the real event with the real timestamp.&lt;/p&gt;

&lt;h3&gt;
  
  
  Option B: Event interception at the window level
&lt;/h3&gt;

&lt;p&gt;Some browser APIs allow intercepting events at the &lt;code&gt;window&lt;/code&gt; level&lt;br&gt;
before they propagate to &lt;code&gt;document&lt;/code&gt;. Whether this provides true&lt;br&gt;
pre-page interception depends on the browser and the specific API.&lt;/p&gt;

&lt;h3&gt;
  
  
  Option C: Shadow DOM isolation
&lt;/h3&gt;

&lt;p&gt;The "ShadowDOM" in "ShadowDOM Input Vault" refers to using Shadow DOM's&lt;br&gt;
encapsulation to isolate input handling. Input elements inside a&lt;br&gt;
closed Shadow DOM are not directly accessible to page scripts —&lt;br&gt;
events dispatched from within the shadow root can be re-emitted&lt;br&gt;
as synthetic events to the page without exposing the original.&lt;/p&gt;

&lt;p&gt;This approach has promise but comes with significant constraints:&lt;br&gt;
it requires that input elements be inside a Shadow DOM we control,&lt;br&gt;
which is not always the case for arbitrary web pages.&lt;/p&gt;

&lt;h3&gt;
  
  
  Option D: Browser-native input interception API
&lt;/h3&gt;

&lt;p&gt;Some browsers provide extension APIs that allow intercepting input&lt;br&gt;
at a level below the page context entirely — before the event&lt;br&gt;
enters the DOM at all. The availability, behavior, and permissions&lt;br&gt;
required for these APIs vary significantly across Chrome, Firefox, and Safari.&lt;/p&gt;




&lt;h2&gt;
  
  
  The semantic preservation requirement
&lt;/h2&gt;

&lt;p&gt;Whatever interception approach is used, the re-emitted synthetic event&lt;br&gt;
must be semantically identical to the original — or the page breaks.&lt;/p&gt;

&lt;p&gt;This means the synthetic event must correctly carry:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The key identity (&lt;code&gt;key&lt;/code&gt;, &lt;code&gt;code&lt;/code&gt;, &lt;code&gt;keyCode&lt;/code&gt;, &lt;code&gt;charCode&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;The modifier state (&lt;code&gt;shiftKey&lt;/code&gt;, &lt;code&gt;ctrlKey&lt;/code&gt;, &lt;code&gt;altKey&lt;/code&gt;, &lt;code&gt;metaKey&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;The event type sequence (&lt;code&gt;keydown&lt;/code&gt; → &lt;code&gt;keypress&lt;/code&gt; → &lt;code&gt;keyup&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;bubbles&lt;/code&gt; and &lt;code&gt;cancelable&lt;/code&gt; properties&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;composed&lt;/code&gt; property (for Shadow DOM scenarios)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The only thing that must be different is the timestamp — or more precisely,&lt;br&gt;
the high-resolution timing information that IKI classifiers extract.&lt;/p&gt;




&lt;h2&gt;
  
  
  IME: the unsolved problem
&lt;/h2&gt;

&lt;p&gt;Input Method Editors (IMEs) are used to type characters in non-Latin scripts&lt;br&gt;
— Chinese, Japanese, Korean, Arabic, and others. IME input doesn't follow&lt;br&gt;
the standard &lt;code&gt;keydown&lt;/code&gt;/&lt;code&gt;keypress&lt;/code&gt;/&lt;code&gt;keyup&lt;/code&gt; sequence. It uses composition&lt;br&gt;
events: &lt;code&gt;compositionstart&lt;/code&gt;, &lt;code&gt;compositionupdate&lt;/code&gt;, &lt;code&gt;compositionend&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;How the Input Vault handles IME input is an open question.&lt;br&gt;
Getting it wrong means HOLogram breaks input for a significant portion&lt;br&gt;
of the world's users.&lt;/p&gt;




&lt;h2&gt;
  
  
  What we need to find out
&lt;/h2&gt;

&lt;p&gt;The Input Vault design is specified. The implementation requires answers&lt;br&gt;
to questions that only empirical browser API research can provide:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Which API gives us the earliest interception point in each browser?&lt;/li&gt;
&lt;li&gt;Does any approach give us true pre-page interception, or are we always racing?&lt;/li&gt;
&lt;li&gt;What permissions does each approach require in the extension manifest?&lt;/li&gt;
&lt;li&gt;How do Chrome, Firefox, and Safari differ in their event timing behavior?&lt;/li&gt;
&lt;li&gt;How do we handle IME composition events without breaking non-Latin input?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is exactly the scope of&lt;br&gt;
&lt;strong&gt;&lt;a href="https://github.com/BaffiSan/HOLogram/issues" rel="noopener noreferrer"&gt;R-01: Survey browser APIs for input event interception&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;
— the most foundational research issue in the project.&lt;/p&gt;

&lt;p&gt;If you have experience with browser extension development, especially&lt;br&gt;
with input event handling, this is where your contribution would have&lt;br&gt;
the highest impact.&lt;/p&gt;




&lt;h2&gt;
  
  
  How to contribute
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;📋 &lt;strong&gt;&lt;a href="https://github.com/BaffiSan/HOLogram/issues" rel="noopener noreferrer"&gt;R-01: Browser API survey for input event interception&lt;/a&gt;&lt;/strong&gt; — foundational research&lt;/li&gt;
&lt;li&gt;📋 &lt;strong&gt;&lt;a href="https://github.com/BaffiSan/HOLogram/issues" rel="noopener noreferrer"&gt;D-03: HCT compliance test spec for the Input Vault&lt;/a&gt;&lt;/strong&gt; — define what "correct" means&lt;/li&gt;
&lt;li&gt;💻 &lt;a href="https://github.com/BaffiSan/HOLogram" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;💬 &lt;a href="https://github.com/BaffiSan/HOLogram/discussions" rel="noopener noreferrer"&gt;Discussions&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;📄 &lt;a href="https://www.hologramprotocol.org/download/" rel="noopener noreferrer"&gt;Whitepaper v1.0&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;This concludes the "Building HOLogram" series — for now.&lt;br&gt;
The next articles will be written by contributors as they work through&lt;br&gt;
the research issues. If you pick up R-01 or D-03 and want to write&lt;br&gt;
about your findings, we'd love to publish it here as part of the series.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>javascript</category>
      <category>security</category>
      <category>opensource</category>
    </item>
    <item>
      <title>HOLogram deep dive: the Behavioral Privacy Budget — controlling exposure over time</title>
      <dc:creator>BaffiSan</dc:creator>
      <pubDate>Mon, 21 Sep 2026 12:16:00 +0000</pubDate>
      <link>https://dev.to/baffisan/hologram-deep-dive-the-behavioral-privacy-budget-controlling-exposure-over-time-2mi5</link>
      <guid>https://dev.to/baffisan/hologram-deep-dive-the-behavioral-privacy-budget-controlling-exposure-over-time-2mi5</guid>
      <description>&lt;p&gt;&lt;em&gt;This is part 2 of "Building HOLogram", a series on the open protocol&lt;br&gt;
for behavioral biometrics protection in the browser.&lt;br&gt;
&lt;a href="https://dev.to/baffisan/why-javascript-can-read-your-behavioral-identity-and-what-hologram-does-about-it-pjo"&gt;Part 0 — introduction&lt;/a&gt; | &lt;a href="https://dev.to/baffisan/hologram-deep-dive-the-persona-mixer-why-random-noise-isnt-enough-1nh"&gt;Part 1 — Persona Mixer&lt;/a&gt; | Part 2 — Privacy Budget | Part 3 — Input Vault&lt;/em&gt;&lt;/p&gt;



&lt;p&gt;Obfuscating individual behavioral events is necessary. It's not sufficient.&lt;/p&gt;

&lt;p&gt;A sufficiently patient adversary doesn't need to identify you from a single&lt;br&gt;
interaction. They observe you over time — across many events, many sessions —&lt;br&gt;
and build a statistical picture that individual obfuscation can't defeat.&lt;/p&gt;

&lt;p&gt;This is the problem the &lt;strong&gt;Behavioral Privacy Budget&lt;/strong&gt; was designed to address.&lt;/p&gt;


&lt;h2&gt;
  
  
  The core idea
&lt;/h2&gt;

&lt;p&gt;The Privacy Budget tracks the &lt;strong&gt;cumulative behavioral exposure&lt;/strong&gt; of a session.&lt;/p&gt;

&lt;p&gt;Every interaction has a cost. The more behaviorally distinctive an interaction&lt;br&gt;
is — the more information it leaks about the real user — the higher its cost.&lt;br&gt;
As the session progresses and the budget is consumed, the protocol&lt;br&gt;
automatically escalates its obfuscation strategy.&lt;/p&gt;

&lt;p&gt;When the budget is exhausted, the session is considered fully exposed —&lt;br&gt;
and the user is notified via the Exposure HUD.&lt;/p&gt;


&lt;h2&gt;
  
  
  The cost formula
&lt;/h2&gt;

&lt;p&gt;The cost of each behavioral event is computed as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;cost = w_type × f_freq × g_geom × h_entropy
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Where:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;code&gt;w_type&lt;/code&gt;&lt;/strong&gt; — event type weight&lt;br&gt;
Different event types carry different amounts of behavioral information.&lt;br&gt;
A typing burst is more identifying than a single scroll event.&lt;br&gt;
A precise pointer click is more identifying than a smooth pan.&lt;br&gt;
&lt;code&gt;w_type&lt;/code&gt; assigns a base weight to each event category.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;code&gt;f_freq&lt;/code&gt;&lt;/strong&gt; — frequency factor&lt;br&gt;
A single mouse movement reveals little. Ten thousand mouse movements&lt;br&gt;
in a session reveal a lot, even if each individual event is obfuscated.&lt;br&gt;
&lt;code&gt;f_freq&lt;/code&gt; scales the cost based on how many events of this type&lt;br&gt;
have occurred in the session — the more frequent, the higher the cost.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;code&gt;g_geom&lt;/code&gt;&lt;/strong&gt; — geometric complexity factor&lt;br&gt;
A straight pointer path is less identifying than a complex, curved trajectory.&lt;br&gt;
&lt;code&gt;g_geom&lt;/code&gt; measures the geometric complexity of the event — curvature,&lt;br&gt;
directionality, acceleration — and scales the cost accordingly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;code&gt;h_entropy&lt;/code&gt;&lt;/strong&gt; — entropy factor&lt;br&gt;
Events with high behavioral entropy — high variability, unpredictability —&lt;br&gt;
carry more identifying information than predictable, regular events.&lt;br&gt;
&lt;code&gt;h_entropy&lt;/code&gt; measures the local entropy of the behavioral signal&lt;br&gt;
and scales the cost accordingly.&lt;/p&gt;




&lt;h2&gt;
  
  
  Three escalation thresholds
&lt;/h2&gt;

&lt;p&gt;The Privacy Budget operates with three escalation levels:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Level 1 — Standard protection&lt;/strong&gt;&lt;br&gt;
Normal operation. The Persona Mixer and DP Engine apply their&lt;br&gt;
configured parameters. Cost accumulation is tracked.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Level 2 — Enhanced obfuscation&lt;/strong&gt;&lt;br&gt;
When the budget crosses the first threshold, the protocol automatically&lt;br&gt;
increases the aggressiveness of the Persona Mixer parameters and&lt;br&gt;
the noise magnitude of the DP Engine. The user sees a subtle&lt;br&gt;
indicator change in the Exposure HUD.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Level 3 — Maximum protection&lt;/strong&gt;&lt;br&gt;
When the budget crosses the second threshold, the protocol applies&lt;br&gt;
maximum obfuscation across all modules. The Exposure HUD displays&lt;br&gt;
a clear warning that the session has reached high exposure.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Budget exhausted&lt;/strong&gt;&lt;br&gt;
When the budget is fully consumed, the user is notified that the session&lt;br&gt;
has reached its exposure limit. The protocol continues operating at&lt;br&gt;
maximum protection, but the user is informed that further interaction&lt;br&gt;
may be identifiable despite obfuscation.&lt;/p&gt;




&lt;h2&gt;
  
  
  Regeneration
&lt;/h2&gt;

&lt;p&gt;The budget regenerates over time — during idle periods and across sessions.&lt;/p&gt;

&lt;p&gt;The regeneration model ensures that:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Short bursts of high-intensity interaction don't permanently exhaust the budget&lt;/li&gt;
&lt;li&gt;Sustained, continuous interaction over long sessions correctly accumulates exposure&lt;/li&gt;
&lt;li&gt;The budget starts fresh at the beginning of each new session&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  What we don't know yet
&lt;/h2&gt;

&lt;p&gt;The Privacy Budget formula is designed but the actual numeric values&lt;br&gt;
are not yet defined. Specifically:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What are the correct values for &lt;code&gt;w_type&lt;/code&gt;, &lt;code&gt;f_freq&lt;/code&gt;, &lt;code&gt;g_geom&lt;/code&gt;, &lt;code&gt;h_entropy&lt;/code&gt;?&lt;/strong&gt;&lt;br&gt;
These need to be calibrated empirically — against real behavioral data&lt;br&gt;
and real classifier performance. Too conservative and the budget is&lt;br&gt;
consumed too quickly, degrading usability. Too permissive and the&lt;br&gt;
budget fails to catch cumulative exposure.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What are the correct threshold values?&lt;/strong&gt;&lt;br&gt;
The three escalation thresholds need to be set based on empirical&lt;br&gt;
evidence of what level of cumulative exposure allows successful&lt;br&gt;
re-identification.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is the correct regeneration rate?&lt;/strong&gt;&lt;br&gt;
Too fast and the budget doesn't meaningfully track exposure.&lt;br&gt;
Too slow and normal browsing sessions hit the limit constantly.&lt;/p&gt;

&lt;p&gt;These are among the most important open design questions in HOLogram.&lt;/p&gt;




&lt;h2&gt;
  
  
  How to contribute
&lt;/h2&gt;

&lt;p&gt;The most impactful contribution for this module is&lt;br&gt;
&lt;strong&gt;&lt;a href="https://github.com/BaffiSan/HOLogram/issues" rel="noopener noreferrer"&gt;D-02: Design the Behavioral Privacy Budget consumption model&lt;/a&gt;&lt;/strong&gt; —&lt;br&gt;
proposing concrete values for all parameters and thresholds,&lt;br&gt;
with sensitivity analysis.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;💻 &lt;a href="https://github.com/BaffiSan/HOLogram" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;💬 &lt;a href="https://github.com/BaffiSan/HOLogram/discussions" rel="noopener noreferrer"&gt;Discussions&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;📄 &lt;a href="https://www.hologramprotocol.org/download/" rel="noopener noreferrer"&gt;Whitepaper v1.0&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Next in the series: [Part 3 — Building HOLogram's Input Vault: browser API survey]&lt;/em&gt;&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>javascript</category>
      <category>security</category>
      <category>opensource</category>
    </item>
    <item>
      <title>HOLogram deep dive: the Persona Mixer — why random noise isn't enough</title>
      <dc:creator>BaffiSan</dc:creator>
      <pubDate>Tue, 15 Sep 2026 11:06:53 +0000</pubDate>
      <link>https://dev.to/baffisan/hologram-deep-dive-the-persona-mixer-why-random-noise-isnt-enough-1nh</link>
      <guid>https://dev.to/baffisan/hologram-deep-dive-the-persona-mixer-why-random-noise-isnt-enough-1nh</guid>
      <description>&lt;p&gt;&lt;em&gt;This is part 1 of "Building HOLogram", a series on the open protocol&lt;br&gt;
for behavioral biometrics protection in the browser.&lt;br&gt;
&lt;a href="https://dev.to/baffisan/why-javascript-can-read-your-behavioral-identity-and-what-hologram-does-about-it-pjo"&gt;Part 0 — introduction&lt;/a&gt; | Part 1 — Persona Mixer | Part 2 — Privacy Budget | Part 3 — Input Vault&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;Most approaches to behavioral privacy make the same mistake: they add noise.&lt;/p&gt;

&lt;p&gt;Random noise injected into mouse movements or keystroke timings seems like&lt;br&gt;
a reasonable defense. It corrupts the signal. It should confuse a classifier.&lt;/p&gt;

&lt;p&gt;The problem is that &lt;strong&gt;random noise is itself a signal&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;A behavioral biometrics classifier doesn't just look at the absolute values&lt;br&gt;
of your timing or trajectory data. It looks at the statistical distribution&lt;br&gt;
of those values over time. Random noise has a characteristic distribution —&lt;br&gt;
flat, uniform, uncorrelated. A trained classifier can distinguish "human +&lt;br&gt;
noise" from "human" with relatively high accuracy, because the noise pattern&lt;br&gt;
doesn't look like any human behavioral pattern ever observed.&lt;/p&gt;

&lt;p&gt;This is the problem the &lt;strong&gt;Persona Mixer&lt;/strong&gt; was designed to solve.&lt;/p&gt;




&lt;h2&gt;
  
  
  What the Persona Mixer does
&lt;/h2&gt;

&lt;p&gt;Instead of adding random noise to your real behavioral signals,&lt;br&gt;
the Persona Mixer generates a &lt;strong&gt;session-consistent synthetic behavioral&lt;br&gt;
signature&lt;/strong&gt; — a stable set of behavioral parameters that define a&lt;br&gt;
plausible synthetic human for the duration of the session.&lt;/p&gt;

&lt;p&gt;The output doesn't look like noise. It looks like a specific person —&lt;br&gt;
just not you. And not the same synthetic person across sessions.&lt;/p&gt;




&lt;h2&gt;
  
  
  The five parameters
&lt;/h2&gt;

&lt;p&gt;The Persona Mixer operates on five parameters:&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;code&gt;pointerJitterRange&lt;/code&gt;
&lt;/h3&gt;

&lt;p&gt;The magnitude of synthetic micro-movements added to pointer coordinates.&lt;br&gt;
Human pointer movement is never perfectly smooth — there's always a small&lt;br&gt;
amount of biological tremor and motor noise. The jitter range defines&lt;br&gt;
the amplitude of this synthetic tremor.&lt;/p&gt;

&lt;p&gt;The key constraint: the range must be within human plausibility bounds.&lt;br&gt;
Too small and it's indistinguishable from no jitter. Too large and it&lt;br&gt;
looks like a hardware malfunction, not a human.&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;code&gt;scrollPauseProbability&lt;/code&gt;
&lt;/h3&gt;

&lt;p&gt;The probability of inserting a micro-pause during a scroll event.&lt;br&gt;
Humans naturally pause while scrolling — to read, to process, to hesitate.&lt;br&gt;
This parameter controls how often the synthetic persona "hesitates"&lt;br&gt;
during scroll interactions.&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;code&gt;typingLatencyOffset&lt;/code&gt;
&lt;/h3&gt;

&lt;p&gt;An offset applied to inter-keystroke intervals. Rather than replacing&lt;br&gt;
the natural timing distribution of your keystrokes, this parameter&lt;br&gt;
shifts the entire distribution by a consistent amount — making the&lt;br&gt;
synthetic persona type slightly faster or slower than the real user,&lt;br&gt;
but with a pattern that remains internally consistent.&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;code&gt;smoothingAggressiveness&lt;/code&gt;
&lt;/h3&gt;

&lt;p&gt;The degree of trajectory smoothing applied to pointer paths.&lt;br&gt;
Some people move their mouse in smooth arcs; others in jagged, direct lines.&lt;br&gt;
This parameter controls where on that spectrum the synthetic persona falls.&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;code&gt;curvatureSoftening&lt;/code&gt;
&lt;/h3&gt;

&lt;p&gt;A reduction of sharp angular changes in pointer movement. Humans rarely&lt;br&gt;
make perfect right-angle movements — sharp angles get softened into curves.&lt;br&gt;
The aggressiveness of this softening varies between individuals.&lt;/p&gt;




&lt;h2&gt;
  
  
  Session consistency: the critical property
&lt;/h2&gt;

&lt;p&gt;All five parameters are &lt;strong&gt;stable for the duration of a session&lt;/strong&gt; — they&lt;br&gt;
don't change between interactions.&lt;/p&gt;

&lt;p&gt;This is what makes the Persona Mixer fundamentally different from noise&lt;br&gt;
injection. A real human has consistent behavioral traits across a session.&lt;br&gt;
Their typing rhythm is recognizable. Their pointer style is stable.&lt;/p&gt;

&lt;p&gt;The synthetic persona must have the same property: a classifier observing&lt;br&gt;
the session should see a consistent behavioral identity, just not the&lt;br&gt;
real user's identity.&lt;/p&gt;

&lt;p&gt;At the start of each new session, a new set of parameters is sampled —&lt;br&gt;
creating a different synthetic persona. This breaks cross-session correlation&lt;br&gt;
even if an adversary has a full session recording.&lt;/p&gt;




&lt;h2&gt;
  
  
  What we don't know yet
&lt;/h2&gt;

&lt;p&gt;The Persona Mixer is designed but not yet implemented or empirically validated.&lt;/p&gt;

&lt;p&gt;Several open questions remain:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What are the actual human plausibility ranges for each parameter?&lt;/strong&gt;&lt;br&gt;
We need empirical data on human behavioral variance to set the bounds.&lt;br&gt;
A synthetic persona that falls outside human plausibility bounds is&lt;br&gt;
detectable as synthetic — exactly what we're trying to avoid.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How does the Persona Mixer interact with anti-bot systems?&lt;/strong&gt;&lt;br&gt;
reCAPTCHA, hCaptcha, Cloudflare — these systems also model "human" behavior.&lt;br&gt;
A Persona Mixer parameter set that defeats a behavioral biometrics classifier&lt;br&gt;
might still trigger an anti-bot system. We need to understand the overlap.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can the parameter distribution itself become a fingerprint?&lt;/strong&gt;&lt;br&gt;
If all HOLogram users sample their Persona Mixer parameters from the same&lt;br&gt;
distribution, that distribution might become detectable. The sampling&lt;br&gt;
strategy matters as much as the parameters themselves.&lt;/p&gt;

&lt;p&gt;These are active open questions in our GitHub Discussions and research issues.&lt;/p&gt;




&lt;h2&gt;
  
  
  How to contribute
&lt;/h2&gt;

&lt;p&gt;If you have experience with behavioral biometrics research, HCI, or&lt;br&gt;
statistical analysis of human motor behavior, we need your input.&lt;/p&gt;

&lt;p&gt;The most impactful contribution right now is&lt;br&gt;
&lt;strong&gt;&lt;a href="https://github.com/BaffiSan/HOLogram/issues" rel="noopener noreferrer"&gt;D-01: Define human plausibility ranges for Persona Mixer parameters&lt;/a&gt;&lt;/strong&gt; —&lt;br&gt;
researching the empirical bounds for each of the five parameters.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;💻 &lt;a href="https://github.com/BaffiSan/HOLogram" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;💬 &lt;a href="https://github.com/BaffiSan/HOLogram/discussions" rel="noopener noreferrer"&gt;Discussions&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;📄 &lt;a href="https://www.hologramprotocol.org/download/" rel="noopener noreferrer"&gt;Whitepaper v1.0&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Next in the series: [Part 2 — How we designed the Behavioral Privacy Budget]&lt;/em&gt;&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>javascript</category>
      <category>security</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Why JavaScript can read your behavioral identity — and what HOLogram does about it</title>
      <dc:creator>BaffiSan</dc:creator>
      <pubDate>Thu, 10 Sep 2026 12:27:26 +0000</pubDate>
      <link>https://dev.to/baffisan/why-javascript-can-read-your-behavioral-identity-and-what-hologram-does-about-it-pjo</link>
      <guid>https://dev.to/baffisan/why-javascript-can-read-your-behavioral-identity-and-what-hologram-does-about-it-pjo</guid>
      <description>&lt;p&gt;Every page you visit runs JavaScript.&lt;/p&gt;

&lt;p&gt;And that JavaScript is reading you — not just what you type,&lt;br&gt;
but &lt;em&gt;how&lt;/em&gt; you type it. The rhythm between keystrokes. The trajectory&lt;br&gt;
of your pointer. The micro-pauses in your scroll. The way your hand&lt;br&gt;
hesitates before clicking.&lt;/p&gt;

&lt;p&gt;These signals are called &lt;strong&gt;behavioral biometrics&lt;/strong&gt;. And they are today&lt;br&gt;
one of the most powerful identification tools available to tracking systems,&lt;br&gt;
AI classifiers, and fraud detection platforms.&lt;/p&gt;

&lt;p&gt;They work without cookies.&lt;br&gt;
They work across VPNs.&lt;br&gt;
They work even on Tor.&lt;br&gt;
Because they happen inside the page, before anything leaves your browser.&lt;/p&gt;




&lt;h2&gt;
  
  
  The threat no privacy tool addresses
&lt;/h2&gt;

&lt;p&gt;Most privacy tools protect the network layer:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;VPNs&lt;/strong&gt; hide your IP address&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;uBlock Origin&lt;/strong&gt; blocks known trackers&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Privacy Badger&lt;/strong&gt; stops cross-site tracking cookies&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tor&lt;/strong&gt; anonymizes your traffic&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of them protect your behavioral signals — because those signals are&lt;br&gt;
collected by JavaScript running inside the page you're visiting,&lt;br&gt;
before any network request is made.&lt;/p&gt;

&lt;p&gt;A classifier trained on behavioral biometrics can identify you with&lt;br&gt;
high accuracy across sessions, across sites, and across devices —&lt;br&gt;
using only the way you interact with a keyboard and a mouse.&lt;/p&gt;

&lt;p&gt;This isn't theoretical. Behavioral biometrics systems are commercially&lt;br&gt;
deployed today for fraud detection, user tracking, and cross-site&lt;br&gt;
identity correlation. Companies like BioCatch, ThreatMetrix, and others&lt;br&gt;
offer this as a service to banks, e-commerce platforms, and publishers.&lt;/p&gt;




&lt;h2&gt;
  
  
  What HOLogram is
&lt;/h2&gt;

&lt;p&gt;HOLogram is an open protocol that introduces a &lt;strong&gt;local obfuscation layer&lt;/strong&gt;&lt;br&gt;
between the user and the page.&lt;/p&gt;

&lt;p&gt;It intercepts behavioral signals at the browser layer — before JavaScript&lt;br&gt;
can read them — and replaces them with a &lt;strong&gt;synthetic behavioral profile&lt;/strong&gt;&lt;br&gt;
that is functionally identical but behaviorally unidentifiable.&lt;/p&gt;

&lt;p&gt;The page receives correct input. It just doesn't receive &lt;em&gt;your&lt;/em&gt; input.&lt;/p&gt;

&lt;p&gt;The protocol is MIT licensed, local-only, zero-retention, and designed&lt;br&gt;
as a formalizable open standard — not a proprietary tool.&lt;/p&gt;




&lt;h2&gt;
  
  
  How it works: six independent modules
&lt;/h2&gt;

&lt;h3&gt;
  
  
  1. ShadowDOM Input Vault
&lt;/h3&gt;

&lt;p&gt;Intercepts native keyboard events (&lt;code&gt;keydown&lt;/code&gt;, &lt;code&gt;keyup&lt;/code&gt;, &lt;code&gt;keypress&lt;/code&gt;) before&lt;br&gt;
page scripts can read them. Removes micro-timing information —&lt;br&gt;
the inter-keystroke intervals that are the primary feature used by&lt;br&gt;
keystroke dynamics classifiers. Re-emits functionally identical&lt;br&gt;
synthetic events with timing information removed.&lt;/p&gt;

&lt;p&gt;The semantic content of what you type is preserved exactly.&lt;br&gt;
The temporal pattern is not.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Pointer &amp;amp; Scroll Normalizer
&lt;/h3&gt;

&lt;p&gt;Applies downsampling, coordinate quantization, and trajectory smoothing&lt;br&gt;
to mouse movement and scroll events. Reduces the granularity of pointer&lt;br&gt;
data to the level where individual identification becomes infeasible,&lt;br&gt;
while keeping movements natural-looking.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Persona Mixer
&lt;/h3&gt;

&lt;p&gt;This is the key differentiator from naive noise injection.&lt;/p&gt;

&lt;p&gt;Instead of adding random noise — which is statistically detectable as noise —&lt;br&gt;
the Persona Mixer generates a &lt;strong&gt;session-consistent synthetic behavioral&lt;br&gt;
signature&lt;/strong&gt;. Each session gets a stable set of synthetic behavioral parameters:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;pointerJitterRange&lt;/code&gt; — magnitude of pointer micro-movements&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;scrollPauseProbability&lt;/code&gt; — probability of micro-pauses during scroll&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;typingLatencyOffset&lt;/code&gt; — offset applied to inter-keystroke intervals&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;smoothingAggressiveness&lt;/code&gt; — degree of trajectory smoothing&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;curvatureSoftening&lt;/code&gt; — reduction of sharp angular changes&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The output looks like a specific, plausible human — just not you.&lt;br&gt;
And not the same synthetic human across sessions.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Behavioral DP Engine
&lt;/h3&gt;

&lt;p&gt;Applies calibrated noise inspired by differential privacy principles&lt;br&gt;
to the real-time event stream. Reduces the sensitivity of the output&lt;br&gt;
to individual behavioral variations without making the output&lt;br&gt;
statistically implausible.&lt;/p&gt;

&lt;p&gt;Note: this is explicitly &lt;em&gt;inspired by&lt;/em&gt; differential privacy, not&lt;br&gt;
formal DP on static datasets. The whitepaper documents this distinction&lt;br&gt;
openly and considers it an area for future formalization.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Behavioral Privacy Budget
&lt;/h3&gt;

&lt;p&gt;Tracks the cumulative behavioral exposure per session. Every interaction&lt;br&gt;
has a cost — computed as a function of event type, frequency, geometric&lt;br&gt;
complexity, and entropy. When the budget approaches defined thresholds,&lt;br&gt;
the protocol escalates its obfuscation strategy automatically.&lt;/p&gt;

&lt;h3&gt;
  
  
  6. Exposure HUD
&lt;/h3&gt;

&lt;p&gt;A minimal, non-intrusive interface that shows the user their current&lt;br&gt;
protection level and which modules are active. Transparency as a feature.&lt;/p&gt;




&lt;h2&gt;
  
  
  Prior art: how HOLogram differs
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Kloak&lt;/strong&gt; (used in Whonix) is the closest existing tool. It operates&lt;br&gt;
at the OS/kernel level on Linux, requires root, and introduces random&lt;br&gt;
delays between physical events and their delivery to applications.&lt;br&gt;
It's a solid tool — but it's OS-level, not browser-native, requires root,&lt;br&gt;
doesn't generate session-consistent synthetic personas, and isn't a&lt;br&gt;
formalizable open standard. Kloak itself acknowledges it doesn't protect&lt;br&gt;
writing style, high-level cognitive behavior, or scroll patterns.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;MouseFaker&lt;/strong&gt; (Leiva et al., CHIIR 2021) is a research Chrome extension&lt;br&gt;
that applies adversarial noise to mouse coordinates. Mouse only, no&lt;br&gt;
session consistency, not actively maintained.&lt;/p&gt;

&lt;p&gt;These tools and HOLogram are complementary. None of them defines a formal&lt;br&gt;
open protocol with compliance tests and a community governance model.&lt;/p&gt;




&lt;h2&gt;
  
  
  Where we are — and what we need
&lt;/h2&gt;

&lt;p&gt;The whitepaper v1.0 is complete and notarized (SHA-256 + IPFS).&lt;br&gt;
The architecture is defined. The governance model, RFC process, and&lt;br&gt;
compliance test specification (HCT) are in place.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The reference implementation doesn't exist yet.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is where you come in.&lt;/p&gt;

&lt;p&gt;We're looking for contributors with experience in:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Browser extension development&lt;/strong&gt; (Chrome/Firefox/Safari)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Privacy engineering&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Differential privacy applied to event streams&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Behavioral biometrics research&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Research and design contributions are equally welcome — not just code.&lt;br&gt;
Good first issues are open and ready to be picked up:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;[R-01]&lt;/code&gt; Survey browser APIs for input event interception&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;[R-02]&lt;/code&gt; Survey pointer and scroll event APIs across browsers&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;[R-03]&lt;/code&gt; Behavioral biometrics classifier survey&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;[R-04]&lt;/code&gt; DP libraries for real-time event streams&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;[R-05]&lt;/code&gt; Anti-bot system behavior analysis&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;[D-01]&lt;/code&gt; Define human plausibility ranges for Persona Mixer parameters&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Links
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;🌐 &lt;a href="https://www.hologramprotocol.org" rel="noopener noreferrer"&gt;hologramprotocol.org&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;📄 &lt;a href="https://www.hologramprotocol.org/download/" rel="noopener noreferrer"&gt;Whitepaper v1.0&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;💻 &lt;a href="https://github.com/BaffiSan/HOLogram" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;📋 &lt;a href="https://github.com/BaffiSan/HOLogram/issues?q=label%3Agood-first-issue" rel="noopener noreferrer"&gt;Good first issues&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;💬 &lt;a href="https://github.com/BaffiSan/HOLogram/discussions" rel="noopener noreferrer"&gt;GitHub Discussions&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;HOLogram is an independent open project. No company, no VC, no advertising interest.&lt;br&gt;
Community-driven from day one.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>opensource</category>
      <category>javascript</category>
      <category>security</category>
    </item>
  </channel>
</rss>
