← Explorations
Auth Factors & MFA
Know, Have, Are, Do, Somewhere. Why password + PIN is not MFA.
K

Something you KNOW

Knowledge factor
A secret only you know. Cheapest factor to deploy, but the easiest one to steal.
Examples
Password PIN Passphrase Security question
+ Free, no hardware needed
- Can be guessed, phished, or shared
H

Something you HAVE

Possession factor
A physical thing you possess. Stops attackers who only know your password.
Examples
TOTP code SMS code Push prompt Hardware key Smart card
+ Hard to phish, especially with a hardware security key
- Lost or stolen items have to be revoked
A

Something you ARE

Inherence (biometric) factor
A physical trait that identifies you. Always with you, but you cannot change it if it gets compromised.
Examples
Fingerprint Face Iris Retina Voice
Biometric error rates
FARFalse Acceptance Rate. Wrong person was let in. Security failure.
FRRFalse Rejection Rate. Right person was kept out. Usability failure.
CERCrossover Error Rate. Where FAR equals FRR. Lower = better overall system.
D

Something you DO

Behavioral factor
A pattern in HOW you act, not just who or what you are.
Examples
Typing rhythm Mouse pattern Signature pressure Gait
+ Continuous and invisible to the user
- Higher error rates than other factors, less common in practice
W

Somewhere you ARE

Location factor
Where you are connecting from, used as an extra signal.
Examples
GPS location IP geolocation On corporate Wi-Fi Geofencing
+ Used to silently raise or lower auth requirements
- Easy to spoof with a VPN or GPS spoofing
The rule: MFA needs two or more DIFFERENT factor categories.
Two passwords is not MFA. Two biometrics is not MFA. But a password (KNOW) + a TOTP code (HAVE) is real MFA. The categories have to differ.

Try a combination

+
Real-world combinations
Score: 0 / 0 (0%)
Streak: 0