Rich On Tech Almost Got It Right Regarding Safe Words

But his heart was in the right place in this post.

“The BBC highlighted a case where a mother got a terrifying call that sounded exactly like her teenage son, supposedly saying he was in danger. It wasn’t him. Scammers had cloned his voice.

“That’s where a family code word can help. If someone calls claiming a loved one has been hurt, arrested or needs money urgently, ask for the code word. A scammer may be able to fake a voice, but they probably don’t know your family secret.”

Good, but as I previously noted, not great.

“While password length requirements sometimes become ridiculous, they have a purpose. A longer password is harder to guess than a shorter one.

“Similarly, four safe words are harder to guess than a single one.

“Provided the words are unrelated. “The quick brown fox” is a terrible safe phrase.”

Oh, and a note on monetization. Originally I simply planned to comment on Rich DeMuro’s original post, but only paid subscribers could comment. Therefore I’m posting my thoughts on my own platform.

People reading Bredemarket are more interested in knowledge-based authentication (KBA) anyway.

And if your firm provides KBA and other identity factors—there are six factors, you know—then perhaps Bredemarket can help your firm with content-proposal-analysis services.

CPA

How Other Experts Refer to “Somewhat You Why”

Unlike most other posts that appear under my name—Bredebot posts are another matter—this post breaks my 2023 rule because most of it was written by Google Gemini, not me.

But I figured that if I wrote a book specifically about SIX factors of authentication…

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
The book.

…it would be nice to know if other experts held similar thoughts.

My prompt to Gemini

Bredemarket has promoted “somewhat you why” as a sixth factor of identity verification / authentication. Has anyone else shared similar observations?

Gemini’s response

Here is the short answer: Yes, industry experts and security frameworks strongly agree with the core observation, though they call it “Authentication Intent,” “Intent Verification,” or “Context-Aware/Risk-Based Authentication” rather than using Bredemarket’s play-on-words.

Shifting Truths. Google Lyria. Public Domain.

John Bredehoft (Bredemarket) coined “somewhat you why” to fit the traditional naming convention (something you know, have, are, do, somewhere you are). His argument is that checking why an action or request is taking place—evaluating intent, transaction risk, or reasonableness—functions as a crucial safeguard, especially in an era of deepfakes and automated AI agents.

While the tongue-in-cheek name is unique to Bredemarket, the concept itself is widely discussed and implemented across the cybersecurity industry under three main paradigms:

1. “Authentication Intent” (NIST Standards)

The National Institute of Standards and Technology (NIST) explicitly addresses intent in NIST SP 800-63B.

  • The Problem: A user might have a valid session token, biometrics, or physical key plugged in, but malware or a session hijack could trigger actions without the user’s conscious decision.
  • The Solution: Systems require an explicit act of intent—like tapping a physical FIDO key, typing a PIN, or responding to a contextual prompt—proving that the user intended to execute that specific action at that moment.

2. Intent Verification for AI & Delegated Actions

With the rise of autonomous AI agents and automated workflows, identity security groups (like the Non-Human Identity/NHI movement) frequently discuss Intent Verification.

  • Conventional authentication proves who logged in, but not whether the user meant to perform this specific action.
  • Intent Verification bridges authentication and authorization by evaluating whether a transaction (e.g., a $35M wire transfer or an API call) aligns with the user’s actual current decision and business policy.

3. Context-Aware and Adaptive Authentication

Identity providers (like Palo Alto Networks, Okta, and Silverfort) build their Adaptive Multi-Factor Authentication (AMFA) around the “why” and “context”:

  • Context Signals: What resource is being accessed? Is this normal business behavior? Does this request make sense given the time, value, and sensitivity?
  • Dynamic Step-Up: If the “why” seems low-risk (e.g., checking internal docs during work hours), access is smooth. If the “why” is high-risk or suspicious (e.g., a wire transfer requested via video call), the system demands step-up verification.

How the Views Compare

While most identity security professionals treat “intent and context” as a governance or risk engine layer wrapping traditional factors rather than a 6th factor itself, everyone agrees with Bredemarket’s baseline premise: verifying who someone is without evaluating what and why they are trying to do it is no longer enough to stop modern fraud.

For Those Who Still Write User Manuals, They’re Better Now

1984 John would have been so jealous of me on Tuesday.

On Tuesday I was writing an installation guide for a Bredemarket client. Even though it was a simply formatted guide, its formatting was light years ahead the software user manuals I wrote around 1984 (no significance, just coincidence).

As I previously mentioned, 1984 John wrote user manuals using a software package called multiWRITE. You’ve probably never heard of it. multiWRITE was a word processor for the THEOS operating system that was developed by my employer, Logic eXtension Resources. So when I wrote the user manual for multiWRITE, I used…multiWRITE. Yeah, I ate my own wildebeest food even in the 1980s.

Google Gemini.

Now multiWRITE was a pretty good software package for the time, and THEOS was a pretty good operating system for the time. But by 2026 standards it was atrocious.

  • The output was bi-tonal, just black and white with no colors or even grayscale output.
  • The output was monospaced, just like a typewriter. Typewriters were still very common in 1984.

Things started to change as Logic eXtension Resources started to offer Macintosh software and started using Macs for internal document creation. But for my first years at Logic eXtension Resources it was basically typewriter-looking text saved to disk.

Fast forward to 2026, and I had to create a simple installation guide using today’s tools. The manual wasn’t fancy by any stretch of the imagination: even my ebook on the six factors of identity verification is fancier.

Oh, have I mentioned my ebook recently? Now I have. Click the image to buy.

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
Proving Humanity: The Six Factors of Identity Verification and Authentication.

But the client’s installation guide had several features that left multiWRITE in the dust.

One example: back in 1984 my text highlighting options were limited.

Re-creation of multiWRITE 1984 text.

On Tuesday I wrote a sentence that looked like this.

Actual Microsoft Word 2026 text.

Yeah, blue text. 1984 me would have been shocked.

Google Gemini.

But then again, other than me, who writes user manuals any more?

The Wildebeest Speaks Again After a Long Silence

Well, well, well. I haven’t updated “The Wildebeest Speaks” since (checks notes) March. Because reasons.

So I’ll provide an update about the work I’ve performed, the experiments I’ve conducted, and my latest contribution to the sum of human literature.

Visit LinkedIn to view the latest edition of The Wildebeest Speaks, “Bredemarket Update: Work, Experiments, and My Latest Publication.”

Google Gemini. Source.

The Bangladesh Identities Weren’t Synthetic Identities, But They Failed The “Somewhat You Why” Test

Andrew Austin at Sardine has written an eye-catching blog post that discusses a fraud ring exhibiting unusual patterns.

  • Some fraudsters use synthetic identities to fool systems, but good systems can catch the synths.
  • But other fraudsters use mules and other techniques that pass identity verification checks, because the people are REAL people.
Google Gemini.

Austin’s post discusses an example of the latter.

Sign-up patterns in Bangladesh

In this particular case (Example 3 of 3), a gig economy company had discovered a fraud ring operating out of Bangladesh, but the identities were those of real people. The investigator noticed something right off the bat:

“When we looked into it, something was off: all of the locations seemed to be clustered in a few small towns.”

But wait…it gets better.

“The fraudsters were going door-to-door and signing up anyone who was willing to share their information….

“Dozens of routes snaked through neighborhoods where new accounts were being created, each of them running from North to South and then back to their starting point on the next street over.”

It turns out that the fraudsters were going down each street, paying people to borrow their identities, and then moving on to the next street.

Google Gemini.

How identity factors (in the plural) identified the fraud

In Bredemarket’s view, this raised alarms surrounding two factors of identity verification and authentication.

  • The first was geolocation. Once the identities were plotted, it seems strange that all of the identities lined up down each street and on to the next street.
  • The second is what I call somewhat you why. It’s reasonable to believe that if person A signs up for a service, their neighbors may sign up also. But it’s NOT reasonable to believe that people would sign up for the service in address order, moving from street to street. “No, Jim, 158 1st street can’t sign up for the service! 156 1st street hasn’t signed up yet!”

Now even if you don’t believe that “somewhat you why” is a real factor (Sardine prefers to talk about “device and behavior intelligence“), it’s clear that fraudsters were using the identities of real people to engage in a massive fraud scheme.

Look at the patterns, and you can discover from unusual ones.

And now a word from our sponsor

And if you’re wondering why I discuss SIX factors of identity verification and authentication (rather than five or three), check out my ebook “Proving Humanity: The Six Factors of Identity Verification and Authentication.”

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.

Non-Human Identity Verification

How do you verify non-human identities?

One of the reasons that I titled my ebook “Proving Humanity” is because the six (yes, six) factors of identity verification and authentication that I discuss only apply to identifying humans, and do not apply to non-human identities.

Again, so how do you verify non-human identities?

Cryptographics

One way is via cryptographics. As I discussed previously, the Secure Production Identity Framework For Everyone (SPIFFE) and the SPIFFE Runtime Environment (SPIRE) provide non-person entities with “strongly attested, cryptographic identities.”

Problem solved, right?

As any human who has used a password knows, a single factor can be stolen. And that includes cryptographic factors.

Provenance

Which means that we have to look at provenance. But instead of looking at the provenance of an AI-generated image or video, we are looking at the provenance of an agent that performs actions. The network origin. The environment. The associated attributes. Is the agent running on a specific, authorized, and known virtual machine or container at a specific network address, or is it running…somewhere else?

Behavior

And if you’ve read my book, you know that human identities can be evaluated based upon their behavior (either tendencies or intent). You can also look at the behavior of agents. Is the agent acting at an unexpected time of day? Is it executing an unusually high volume of requests? Is it “scoping out the joint”?

Multi-factor authentication

Again, it’s possible to spoof one factor, but much harder to spoof multiple factors. And that applies to both humans and non-human agents.

Be safe out there.

Factor This Into Your Budget

Proving Humanity: The Six Factors of Identity Verification and Authentication.

Was your bank account hacked? Your tax return? Your health records?

How do banks, government agencies, and medical facilities protect your personally identifiable information (PII) from fraudsters?

By different methods, called FACTORS.

Understand these factors, how they work, and how they protect you.

KYP (Know Your Publisher): Flattery Will Get You Everywhere

Jobseekers and independent contractors are ideal targets for fraud, but they’re not the only ones.

As Phyllis Chesler notes, writers are also prey to the fraudsters.

“[T]he most extensive scam imaginable was launched against me and against many other writers….

“Two women (or two men? Political prisoners in China–or Nigeria? Or even in Iran?) emailed me. Each impersonated a real editor and a real literary agent. This began on April 23rd and continued on through April 27th or April 28th. They appropriated the name of Marilyn Kreztner at Blackstone Publishing and Caitlin Mahony at William Morris Endeavor….

“Please understand: Given the realities of publishing, most writers are a desperate lot. And oh-so-vulnerable to flattery. If a publishing person praises our work–we melt. We glow. Writers specialize in Big Dreams.”

And despite some lingering suspicions, Chesler sent some of her work to both people. But before she could send $700 for an editorial consultant to “improve” her work, Chesler had already contacted the real Blackstone Publishing and the real Wiolliam Morris Endeavor and confirmed that these were not the real Kreztner or Mahony.

If you’re a writer, you must check the site Chesler recommended, Writer Beware. It include a detailed post about this sort of scam, including examples of the scammer communications.

Reminder: while I write books, mine aren’t sold by publishing houses. Visit my Gumroad site to purchase my ebook, “Proving Humanity: The Six Factors of Identity Verification and Authentication.”

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.