How Other Experts Refer to “Somewhat You Why”

Unlike most other posts that appear under my name—Bredebot posts are another matter—this post breaks my 2023 rule because most of it was written by Google Gemini, not me.

But I figured that if I wrote a book specifically about SIX factors of authentication…

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
The book.

…it would be nice to know if other experts held similar thoughts.

My prompt to Gemini

Bredemarket has promoted “somewhat you why” as a sixth factor of identity verification / authentication. Has anyone else shared similar observations?

Gemini’s response

Here is the short answer: Yes, industry experts and security frameworks strongly agree with the core observation, though they call it “Authentication Intent,” “Intent Verification,” or “Context-Aware/Risk-Based Authentication” rather than using Bredemarket’s play-on-words.

Shifting Truths. Google Lyria. Public Domain.

John Bredehoft (Bredemarket) coined “somewhat you why” to fit the traditional naming convention (something you know, have, are, do, somewhere you are). His argument is that checking why an action or request is taking place—evaluating intent, transaction risk, or reasonableness—functions as a crucial safeguard, especially in an era of deepfakes and automated AI agents.

While the tongue-in-cheek name is unique to Bredemarket, the concept itself is widely discussed and implemented across the cybersecurity industry under three main paradigms:

1. “Authentication Intent” (NIST Standards)

The National Institute of Standards and Technology (NIST) explicitly addresses intent in NIST SP 800-63B.

  • The Problem: A user might have a valid session token, biometrics, or physical key plugged in, but malware or a session hijack could trigger actions without the user’s conscious decision.
  • The Solution: Systems require an explicit act of intent—like tapping a physical FIDO key, typing a PIN, or responding to a contextual prompt—proving that the user intended to execute that specific action at that moment.

2. Intent Verification for AI & Delegated Actions

With the rise of autonomous AI agents and automated workflows, identity security groups (like the Non-Human Identity/NHI movement) frequently discuss Intent Verification.

  • Conventional authentication proves who logged in, but not whether the user meant to perform this specific action.
  • Intent Verification bridges authentication and authorization by evaluating whether a transaction (e.g., a $35M wire transfer or an API call) aligns with the user’s actual current decision and business policy.

3. Context-Aware and Adaptive Authentication

Identity providers (like Palo Alto Networks, Okta, and Silverfort) build their Adaptive Multi-Factor Authentication (AMFA) around the “why” and “context”:

  • Context Signals: What resource is being accessed? Is this normal business behavior? Does this request make sense given the time, value, and sensitivity?
  • Dynamic Step-Up: If the “why” seems low-risk (e.g., checking internal docs during work hours), access is smooth. If the “why” is high-risk or suspicious (e.g., a wire transfer requested via video call), the system demands step-up verification.

How the Views Compare

While most identity security professionals treat “intent and context” as a governance or risk engine layer wrapping traditional factors rather than a 6th factor itself, everyone agrees with Bredemarket’s baseline premise: verifying who someone is without evaluating what and why they are trying to do it is no longer enough to stop modern fraud.

Double It To 200 Proof, Steve

Coincidence again? I discussed something from long ago and found myself dealing with it today. Sort of. Prove me wrong.

I recently had occasion to refer to a year-old post that warned about authenticating online customers with knowledge based authentication. There is no guarantee that the person on the other end of the line is actually your customer.

JOE’S ALCOHOL EMPORIUM: Evelyn, what types of alcohol do you prefer?

“EVELYN’S TEENAGE SON WHO KNOWS HER PASSWORD IS HIS BIRTHDATE: 200 proof, man! Let’s get wasted!”

His mom is gonna be so mad…

Meanwhile Steve Craig—formerly of PEAK IDV, now with Prove—is participating in the launch of a new podcast.

Its name?

100proof Powered by Prove.

Steve, should you double the proof to attract the drunken teenager crowd?

Google Gemini. Deepfake. This is not real.

I guess not, since these aren’t Prove’s hungry people…I mean thirsty people.

But if you are in Prove’s…um…target audience, you will be (as LinkedIn says) excited and thrilled to learn that 100proof’s first guest is Steve Craig’s coworker Frances Zelazny, who has joined Prove as its General Manager of New Market Initiatives. Zelazny offers immense expertise in the identity industry. In fact we were coworkers for a few months at Safran, but she was on the other side of the impenetrable wall between MorphoTrust and MorphoTrak.

Join Steve and Frances today at 2pm Pacific Time on LinkedIn.

Despite the Friction, I Read This Message Anyway. And Wished I Hadn’t.

I simplified my social life a few months ago by no longer posting on Instagram. I don’t even have Instagram on my phone any more.

But Instagram Meta-relative Facebook is “nice” enough to inform me when I receive Instagam messages, as well as unsolicited Instagram message requests. Which I obvously can’t read on my phone (in part because I also removed Meta for Business).

Joining the “brand ambassador” inner circle

So one day when I happened to be on my laptop, I brought up my Instagram account. I wanted to see the latest message request, reportedly from “Navin Nandra”…even though I already knew it was in a languge using the Cyrillic alphabet. And probably wouldn’t bring Bredemarkeet a ton of business.

So here’s what I had to do:

  • Go from my phone to my laptop.
  • Log in to Instagram.
  • Find my message requests.
  • Translate the message request that I received.

After translating, I was right in guessing that this was a waste of time. Here is how the message began:

“Good day! This is the brand manager for the clothing brand PRIME Wear

“I’m messaging you from a tech/alternative account—we use these to avoid getting blocked by Instagram Direct limits.

“We absolutely love your style and the content on your blog!

We would love to invite you to join our inner circle of PRIME brand ambassadors.”

Um, no. These “we love your style” messages are always amusing to me. Especially when account number one tells you to contact account number two. Because reasons.

Google Gemini.

Yeah, “ambassador.” My last name isn’t Jenner, and my look isn’t Jenner either.

Google Gemini.

The underlying scams

So I asked Google Gemini about the scam behind these amazing offers, because I suspected a scam. To please me, Google Gemini said that there are scams related to this. I could have fact-checked this on a live web page, but I had already wasted too much time on this.

Here’s one of Gemini’s reported scams:

You are told you have been “hand-picked” to represent the brand. They offer to send you jewelry, sunglasses, or clothing for “free” so you can take photos with it.

  • The Catch: They give you a discount code that brings the item’s cost to $0, but you have to pay $10 to $15 for shipping.
  • The Reality: The brand is usually a front for a dropshipping operation. They buy the items from bulk wholesale sites for less than $1. Your “shipping fee” actually covers the cost of the item and gives the scammer a profit.
  • The Outcome: You paid full retail price (or more) for a low-quality, cheap item, while giving them free advertising.

Bad enough, but it could get a lot worse.

Some requests are much more malicious. A “talent scout” or “brand manager” will message you offering high-paying sponsorships ($500+ per post), even if you only have a few hundred followers.

  • The Catch: To “set up the partnership” or “verify your account,” they send you a link to a portal or ask for your 2FA (Two-Factor Authentication) code.
  • The Reality: The link leads to a fake Instagram login page designed to harvest your password. If you give them a 2FA code, they will immediately change the email associated with your account, lock you out, and hold your account hostage or use it to scam your friends.

So “Navin Nandra” is now blocked. And I can avoid Instagram again for a while.

Even Jedis Can Face Ephemeral Challenges

From a recent Identity Jedi post.

“NHI visibility and AI agent visibility feel like the same problem. They’re not. A service account is relatively static. It was created for a purpose, it has credentials, it authenticates to something. You can find it, document it, rotate its credentials, put it in a vault. That’s a solvable problem with existing tooling.

“An AI agent is different in almost every dimension that matters. It’s dynamic. It’s often ephemeral. It doesn’t have a fixed identity. It borrows one, or several. It makes decisions at runtime about what it needs to access. And it operates at machine speed, which means by the time your SIEM fires an alert, the transaction is already done.”

The Continuing Adventures of Will and Chad

Technically Chad Smith engaged in identity fraud on Saturday Night Live when he started giving Will Ferrell’s monologue.

But no harm was done.

And while the face modality fooled many of us, the voice modality gave Chad away. Score one for multimodal authentication.

Non-Human Identity Verification

How do you verify non-human identities?

One of the reasons that I titled my ebook “Proving Humanity” is because the six (yes, six) factors of identity verification and authentication that I discuss only apply to identifying humans, and do not apply to non-human identities.

Again, so how do you verify non-human identities?

Cryptographics

One way is via cryptographics. As I discussed previously, the Secure Production Identity Framework For Everyone (SPIFFE) and the SPIFFE Runtime Environment (SPIRE) provide non-person entities with “strongly attested, cryptographic identities.”

Problem solved, right?

As any human who has used a password knows, a single factor can be stolen. And that includes cryptographic factors.

Provenance

Which means that we have to look at provenance. But instead of looking at the provenance of an AI-generated image or video, we are looking at the provenance of an agent that performs actions. The network origin. The environment. The associated attributes. Is the agent running on a specific, authorized, and known virtual machine or container at a specific network address, or is it running…somewhere else?

Behavior

And if you’ve read my book, you know that human identities can be evaluated based upon their behavior (either tendencies or intent). You can also look at the behavior of agents. Is the agent acting at an unexpected time of day? Is it executing an unusually high volume of requests? Is it “scoping out the joint”?

Multi-factor authentication

Again, it’s possible to spoof one factor, but much harder to spoof multiple factors. And that applies to both humans and non-human agents.

Be safe out there.

Proof of Humanity Does Not Prove Identity

If you have a database of people worldwide, you can use irises to see whether someone is in the database or not.

This lets you buy the world a Coke. One per person.

But it doesn’t tell you WHO they are.

For that you need to test them against the factors of identity verification and authentication.

All six of them.

Learn more. Purchase the ebook.

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
Proving Humanity: The Six Factors of Identity Verification and Authentication.

Factors Are Independent

One important thing about factors is that they are independent of each other.

The fact that a person has a particular password bears no relation to the fact that a person has a particular fingerprint ridge structure.

And even modalities within a factor may be independent of each other. When Motorola sold its Biometric Business Unit to Safran in 2009, I joined a company (MorphoTrak) that promoted three biometric modalities: finger, face, and iris. While all three biometrics came from the same person, there was no relationship between any of them. Knowing a person’s right forefinger did not tell you what the person’s iris was like. (But beware: driver’s licenses and passports share information, such as dates of birth.)

If you have a critical security issue, you don’t want to depend upon just one factor, or one modality.

Double or triple them up by requiring multiple identity verifications and authentications with unrelated modalities and factors.

Learn more about the six identity factors

Six identity factors. One Bredemarket ebook. Total identity protection. Purchase “Proving Humanity: The Six Factors of Identity Verification and Authentication.”

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket., Click on the image to purchase.