But his heart was in the right place in this post.
“The BBC highlighted a case where a mother got a terrifying call that sounded exactly like her teenage son, supposedly saying he was in danger. It wasn’t him. Scammers had cloned his voice.
“That’s where a family code word can help. If someone calls claiming a loved one has been hurt, arrested or needs money urgently, ask for the code word. A scammer may be able to fake a voice, but they probably don’t know your family secret.”
“While password length requirements sometimes become ridiculous, they have a purpose. A longer password is harder to guess than a shorter one.
“Similarly, four safe words are harder to guess than a single one.
“Provided the words are unrelated. “The quick brown fox” is a terrible safe phrase.”
Oh, and a note on monetization. Originally I simply planned to comment on Rich DeMuro’s original post, but only paid subscribers could comment. Therefore I’m posting my thoughts on my own platform.
People reading Bredemarket are more interested in knowledge-based authentication (KBA) anyway.
And if your firm provides KBA and other identity factors—there are six factors, you know—then perhaps Bredemarket can help your firm with content-proposal-analysis services.
Unlike most other posts that appear under my name—Bredebot posts are another matter—this post breaks my 2023 rule because most of it was written by Google Gemini, not me.
But I figured that if I wrote a book specifically about SIX factors of authentication…
The book.
…it would be nice to know if other experts held similar thoughts.
My prompt to Gemini
Bredemarket has promoted “somewhat you why” as a sixth factor of identity verification / authentication. Has anyone else shared similar observations?
Gemini’s response
Here is the short answer: Yes, industry experts and security frameworks strongly agree with the core observation, though they call it “Authentication Intent,” “Intent Verification,” or “Context-Aware/Risk-Based Authentication” rather than using Bredemarket’s play-on-words.
Shifting Truths. Google Lyria. Public Domain.
John Bredehoft (Bredemarket) coined “somewhat you why” to fit the traditional naming convention (something you know, have, are, do, somewhere you are). His argument is that checking why an action or request is taking place—evaluating intent, transaction risk, or reasonableness—functions as a crucial safeguard, especially in an era of deepfakes and automated AI agents.
While the tongue-in-cheek name is unique to Bredemarket, the concept itself is widely discussed and implemented across the cybersecurity industry under three main paradigms:
1. “Authentication Intent” (NIST Standards)
The National Institute of Standards and Technology (NIST) explicitly addresses intent in NIST SP 800-63B.
The Problem: A user might have a valid session token, biometrics, or physical key plugged in, but malware or a session hijack could trigger actions without the user’s conscious decision.
The Solution: Systems require an explicit act of intent—like tapping a physical FIDO key, typing a PIN, or responding to a contextual prompt—proving that the user intended to execute that specific action at that moment.
2. Intent Verification for AI & Delegated Actions
With the rise of autonomous AI agents and automated workflows, identity security groups (like the Non-Human Identity/NHI movement) frequently discuss Intent Verification.
Conventional authentication proves who logged in, but not whether the user meant to perform this specific action.
Intent Verification bridges authentication and authorization by evaluating whether a transaction (e.g., a $35M wire transfer or an API call) aligns with the user’s actual current decision and business policy.
3. Context-Aware and Adaptive Authentication
Identity providers (like Palo Alto Networks, Okta, and Silverfort) build their Adaptive Multi-Factor Authentication (AMFA) around the “why” and “context”:
Context Signals: What resource is being accessed? Is this normal business behavior? Does this request make sense given the time, value, and sensitivity?
Dynamic Step-Up: If the “why” seems low-risk (e.g., checking internal docs during work hours), access is smooth. If the “why” is high-risk or suspicious (e.g., a wire transfer requested via video call), the system demands step-up verification.
How the Views Compare
While most identity security professionals treat “intent and context” as a governance or risk engine layer wrapping traditional factors rather than a 6th factor itself, everyone agrees with Bredemarket’s baseline premise: verifying who someone is without evaluating what and why they are trying to do it is no longer enough to stop modern fraud.
1984 John would have been so jealous of me on Tuesday.
On Tuesday I was writing an installation guide for a Bredemarket client. Even though it was a simply formatted guide, its formatting was light years ahead the software user manuals I wrote around 1984 (no significance, just coincidence).
As I previously mentioned, 1984 John wrote user manuals using a software package called multiWRITE. You’ve probably never heard of it. multiWRITE was a word processor for the THEOS operating system that was developed by my employer, Logic eXtension Resources. So when I wrote the user manual for multiWRITE, I used…multiWRITE. Yeah, I ate my own wildebeest food even in the 1980s.
Google Gemini.
Now multiWRITE was a pretty good software package for the time, and THEOS was a pretty good operating system for the time. But by 2026 standards it was atrocious.
The output was bi-tonal, just black and white with no colors or even grayscale output.
The output was monospaced, just like a typewriter. Typewriters were still very common in 1984.
Things started to change as Logic eXtension Resources started to offer Macintosh software and started using Macs for internal document creation. But for my first years at Logic eXtension Resources it was basically typewriter-looking text saved to disk.
Fast forward to 2026, and I had to create a simple installation guide using today’s tools. The manual wasn’t fancy by any stretch of the imagination: even my ebook on the six factors of identity verification is fancier.
Oh, have I mentioned my ebook recently? Now I have. Click the image to buy.
Proving Humanity: The Six Factors of Identity Verification and Authentication.
But the client’s installation guide had several features that left multiWRITE in the dust.
One example: back in 1984 my text highlighting options were limited.
Re-creation of multiWRITE 1984 text.
On Tuesday I wrote a sentence that looked like this.
Actual Microsoft Word 2026 text.
Yeah, blue text. 1984 me would have been shocked.
Google Gemini.
But then again, other than me, who writes user manuals any more?
Andrew Austin at Sardine has written an eye-catching blog post that discusses a fraud ring exhibiting unusual patterns.
Some fraudsters use synthetic identities to fool systems, but good systems can catch the synths.
But other fraudsters use mules and other techniques that pass identity verification checks, because the people are REAL people.
Google Gemini.
Austin’s post discusses an example of the latter.
Sign-up patterns in Bangladesh
In this particular case (Example 3 of 3), a gig economy company had discovered a fraud ring operating out of Bangladesh, but the identities were those of real people. The investigator noticed something right off the bat:
“When we looked into it, something was off: all of the locations seemed to be clustered in a few small towns.”
But wait…it gets better.
“The fraudsters were going door-to-door and signing up anyone who was willing to share their information….
“Dozens of routes snaked through neighborhoods where new accounts were being created, each of them running from North to South and then back to their starting point on the next street over.”
It turns out that the fraudsters were going down each street, paying people to borrow their identities, and then moving on to the next street.
Google Gemini.
How identity factors (in the plural) identified the fraud
In Bredemarket’s view, this raised alarms surrounding two factors of identity verification and authentication.
The first was geolocation. Once the identities were plotted, it seems strange that all of the identities lined up down each street and on to the next street.
The second is what I call “somewhat you why.“ It’s reasonable to believe that if person A signs up for a service, their neighbors may sign up also. But it’s NOT reasonable to believe that people would sign up for the service in address order, moving from street to street. “No, Jim, 158 1st street can’t sign up for the service! 156 1st street hasn’t signed up yet!”
Now even if you don’t believe that “somewhat you why” is a real factor (Sardine prefers to talk about “device and behavior intelligence“), it’s clear that fraudsters were using the identities of real people to engage in a massive fraud scheme.
Look at the patterns, and you can discover from unusual ones.
One way is via cryptographics. As I discussed previously, the Secure Production Identity Framework For Everyone (SPIFFE) and the SPIFFE Runtime Environment (SPIRE) provide non-person entities with “strongly attested, cryptographic identities.”
Problem solved, right?
As any human who has used a password knows, a single factor can be stolen. And that includes cryptographic factors.
Provenance
Which means that we have to look at provenance. But instead of looking at the provenance of an AI-generated image or video, we are looking at the provenance of an agent that performs actions. The network origin. The environment. The associated attributes. Is the agent running on a specific, authorized, and known virtual machine or container at a specific network address, or is it running…somewhere else?
Behavior
And if you’ve read my book, you know that human identities can be evaluated based upon their behavior (either tendencies or intent). You can also look at the behavior of agents. Is the agent acting at an unexpected time of day? Is it executing an unusually high volume of requests? Is it “scoping out the joint”?
Multi-factor authentication
Again, it’s possible to spoof one factor, but much harder to spoof multiple factors. And that applies to both humans and non-human agents.
“[T]he most extensive scam imaginable was launched against me and against many other writers….
“Two women (or two men? Political prisoners in China–or Nigeria? Or even in Iran?) emailed me. Each impersonated a real editor and a real literary agent. This began on April 23rd and continued on through April 27th or April 28th. They appropriated the name of Marilyn Kreztner at Blackstone Publishing and Caitlin Mahony at William Morris Endeavor….
“Please understand: Given the realities of publishing, most writers are a desperate lot. And oh-so-vulnerable to flattery. If a publishing person praises our work–we melt. We glow. Writers specialize in Big Dreams.”
And despite some lingering suspicions, Chesler sent some of her work to both people. But before she could send $700 for an editorial consultant to “improve” her work, Chesler had already contacted the real Blackstone Publishing and the real Wiolliam Morris Endeavor and confirmed that these were not the real Kreztner or Mahony.
If you’re a writer, you must check the site Chesler recommended, Writer Beware. It include a detailed post about this sort of scam, including examples of the scammer communications.
Reminder: while I write books, mine aren’t sold by publishing houses. Visit my Gumroad site to purchase my ebook, “Proving Humanity: The Six Factors of Identity Verification and Authentication.”