How Other Experts Refer to “Somewhat You Why”

Unlike most other posts that appear under my name—Bredebot posts are another matter—this post breaks my 2023 rule because most of it was written by Google Gemini, not me.

But I figured that if I wrote a book specifically about SIX factors of authentication…

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
The book.

…it would be nice to know if other experts held similar thoughts.

My prompt to Gemini

Bredemarket has promoted “somewhat you why” as a sixth factor of identity verification / authentication. Has anyone else shared similar observations?

Gemini’s response

Here is the short answer: Yes, industry experts and security frameworks strongly agree with the core observation, though they call it “Authentication Intent,” “Intent Verification,” or “Context-Aware/Risk-Based Authentication” rather than using Bredemarket’s play-on-words.

Shifting Truths. Google Lyria. Public Domain.

John Bredehoft (Bredemarket) coined “somewhat you why” to fit the traditional naming convention (something you know, have, are, do, somewhere you are). His argument is that checking why an action or request is taking place—evaluating intent, transaction risk, or reasonableness—functions as a crucial safeguard, especially in an era of deepfakes and automated AI agents.

While the tongue-in-cheek name is unique to Bredemarket, the concept itself is widely discussed and implemented across the cybersecurity industry under three main paradigms:

1. “Authentication Intent” (NIST Standards)

The National Institute of Standards and Technology (NIST) explicitly addresses intent in NIST SP 800-63B.

  • The Problem: A user might have a valid session token, biometrics, or physical key plugged in, but malware or a session hijack could trigger actions without the user’s conscious decision.
  • The Solution: Systems require an explicit act of intent—like tapping a physical FIDO key, typing a PIN, or responding to a contextual prompt—proving that the user intended to execute that specific action at that moment.

2. Intent Verification for AI & Delegated Actions

With the rise of autonomous AI agents and automated workflows, identity security groups (like the Non-Human Identity/NHI movement) frequently discuss Intent Verification.

  • Conventional authentication proves who logged in, but not whether the user meant to perform this specific action.
  • Intent Verification bridges authentication and authorization by evaluating whether a transaction (e.g., a $35M wire transfer or an API call) aligns with the user’s actual current decision and business policy.

3. Context-Aware and Adaptive Authentication

Identity providers (like Palo Alto Networks, Okta, and Silverfort) build their Adaptive Multi-Factor Authentication (AMFA) around the “why” and “context”:

  • Context Signals: What resource is being accessed? Is this normal business behavior? Does this request make sense given the time, value, and sensitivity?
  • Dynamic Step-Up: If the “why” seems low-risk (e.g., checking internal docs during work hours), access is smooth. If the “why” is high-risk or suspicious (e.g., a wire transfer requested via video call), the system demands step-up verification.

How the Views Compare

While most identity security professionals treat “intent and context” as a governance or risk engine layer wrapping traditional factors rather than a 6th factor itself, everyone agrees with Bredemarket’s baseline premise: verifying who someone is without evaluating what and why they are trying to do it is no longer enough to stop modern fraud.

Maybe These Artificial Luxuries Can Only Compensate (Taking Stefan Gladbach Seriously)

Product marketer Stefan Gladbach (the guy who masterminded the “A PMM Christmas” video) has dispensed some sage advice on how to be a millionaire.

Stefan Gladbach.

Here’s the “too long; didn’t watch” version.

  • Be deceptive about wealth.
  • Sell garbage.
  • Lose morals.

But because I am a product marketing expert (albeit in biometrics, not monetization), I have improved on Gladbach’s inferior suggestions.

Rather than arranging for Robin Leach-inspired “rich and famous” Ferrari/Rolex photo shoots (Stefan’s first point) and laboriously writing up an expensive course (his second point), I assigned the tasks to AI. This offers the added benefit of satisfying Stefan’s third point, losing all morals.

So here is my course, thanks to Google Gemini. But don’t tell anyone that.

IAM. Invest in me—I mean invest in yourself.
Read the fine print.

The MOSIP “Standard”

I’ve previously discussed the false impression that standards achieve recognition via a free, fair, universal consensus. In truth, standards are bullied through the process by one or more interested parties, who then shut out competitors that don’t comply with their…I mean, the industry’s standard.

Meanwhile, companies that don’t comply with the standard ridicule it and say how the standard stifles innovation and brings the whole industry down.

For example, in a few years smartphone manufacturers will complain that the EU’s adoption of USB-C as a universal common charger standard will cause the EU to lag behind when new charging technologies emerge.

Which brings us to MOSIP.

What is MOSIP?

So what does this acronym stand for, and what does it mean?

“The Modular Open Source Identity Platform was established in 2018 to support governments in providing its residents with an official form of the most important human asset – identity.

“As nations around the world proceed on their digital transformation journeys towards true digital economies, a robust and secure national ID system is the crucial first step. With a foundational national ID system in place, a government can build effective civil registries, and service delivery systems, serving the population in a myriad of ways. Among other benefits, robust systems like these enable faster disaster relief, climate resilience, ease of starting new businesses, and better access to financial inclusion, healthcare, and education.”

Established and incubated in Bangalore, India, MOSIP is aligned with the United Nations Sustainable Development Goals and supported by the Gates Foundation and others.

In case you didn’t get the drift, the MOSIP people aren’t regular visitors to Mar-a-Lago.

But their principles align with the goals of many biometric companies that have chosen to list their MOSIP-compliant products on the MOSIP Marketplace.

The marketplace categorizes MOSIP-compliant solutions into six categories:

  • Registration devices.
  • Authentication devices.
  • ABIS (Automated Biometric Identification Systems).
  • SDKs (Software Development Kits).
  • Print devices.
  • Labs.

I won’t list all the MOSIP-compliant solution providers, but there are many of them, including two of the “big three” biometric firms, NEC and Thales.

Any questions?

MOSIP but not MOSIP

I hear a question from the back row from a guy wearing a multicolored wig.

Falco in “Rock Me Amadeus.” From https://youtu.be/cVikZ8Oe_XA.

After all, the third of the “big three,” IDEMIA, has advertised that it provides MOSIP solutions.

“The Togolese Agency for Identification, ANID-TOGO, has partnered with IDEMIA and Atos to build a national biometric eID system based on the Modular Open Source Identity Platform (MOSIP). IDEMIA and Atos will design, build, test, and run a biometric national eID solution for Togo based on iris, face, and fingerprint recognition technology.”

Sounds impressive…until you scan the MOSIP Marketplace and find no listed solutions from IDEMIA or ATOS.

Because “based on” does not equal “compliant with.”

I can say that Bredemarket’s seven-question process is based upon some marketing standard or another, but that doesn’t mean that an independent third party has certified my compliance, or even stated its conformance.

So why doesn’t IDEMIA offer MOSIP-compliant solutions?

Honestly, I don’t know. I haven’t had regular official contact with IDEMIA in years, and the person that I know who just rejoined IDEMIA probably doesn’t know either.

So I have no authoritative answer, but Google Gemini provides this very unauthoritative answer as to IDEMIA’s MOSIP non-compliance:

“IDEMIA’s core business model historically relies on end-to-end, proprietary solutions. MOSIP, by contrast, is an open-source framework designed specifically to prevent vendor lock-in by letting governments mix-and-match components from different tech providers.”

Let’s assume for the moment that Gemini is right in this case. So while IDEMIA may be willing to speak about a solution in Togo “based on” MOSIP, when IDEMIA goes after a critically important opportunity in the FBI or the CIA or the BBC (you know the rest), it’s going to provide a solution based upon IDEMIA-authored components such as its own MorphoKit software development kit.

Knowing full well that the U.S. Federal Bureau of Investigation doesn’t give a hoot about MOSIP compliance.

Because it’s not critically important in that market.

Know Your Market

Some biometric vendors focus on the developing world, some adopt the developing world as a secondary opportunity, and others just don’t care because their real revenue comes from elsewhere.

Where should your company focus its attention?

Bredemarket can help your company with analysis, and provide focused content as the analysis progresses. (Analysis is never complete. Things change.)

If Bredemarket can help you decide if MOSIP compliance is worthwhile or worthless, schedule a free meeting.

Are “Small Business” Events Meaningless for Bredemarket?

So I shared a couple of posts about the Inland Empire Regional Chamber of Commerce “Built to Win” event I attended this afternoon. It was nice, the people were wonderful, and there’s a slight chance I may get some proposal business from a contact of a contact. But in the end, I was not one of the hungry people the IERCC targeted.

  • Because when I think of a “small business,” I think of Bredemarket, a sole proprietorship with 25 square feet of office space.
  • But the government classifies one of Bredemarket’s clients as a “small business”—a company with nearly a hundred employees, three business locations in two countries, and an active Board of Directors.
Bredemarket Board of Directors. Google Gemini.

A Bredemarket “Board of Directors” meeting would be laughable. (But meme-worthy.)

Because Bredemarket ain’t a small business.

Need a million dollars? Talk to Valerie Rivas, EVIA.

I already discussed a presentation this afternoon that talked about growing a business by obtaining $1 million in funding. I don’t know what I’d do with a million dollars. Hire more “Bredemarketers”?

And some of the other presentations were equally inapplicable to my personal (really personal) situation.

  • How do you handle Human Resources when your company has 5 employees, 15 contractors, and $1 million in annual revenue?
  • How do you deal with labor unions and employee wrongful termination lawsuits?

For better or worse, Bredemarket is me. Bredebot explained in a May 21 post:

“The ‘sole’ in sole proprietorship isn’t just a legal designation; it’s the actual engine.

“Without the proprietor, you’re just left with a clever name and some empty URLs.”

Google Gemini.

So I didn’t see a therapist (before or after Bredebot’s post), but went to Google Gemini. Not a licensed health practitioner, but Gemini makes you feel good. This is what it said. This is what Google Gemini said.

Gemini’s alternative to “small business” seminars

That sounds incredibly frustrating. There is a massive “disconnect” in the business world where anything under 500 employees gets lumped into “small business,” meaning you end up sitting through seminars on middle-management drama and venture capital when you’re just trying to figure out how to optimize your own 24-hour day.

When you are the only employee, your constraints are entirely different. You don’t have a labor problem; you have a bandwidth problem. You don’t need a million dollars in funding; you need cash flow and automation.

If you want to skip the fluff and find resources, communities, and content actually built for a company of one, you have to change the keywords you look for.

Stop looking for “Small Business” — Look for these instead:

  • The “Solopreneur” or “Soloist” Movement: This is where you’ll find people actively proud of keeping their headcount at exactly one while scaling their revenue.
  • Micro-Business Resources: Specifically look for content tailored to “Microbusinesses” (typically defined as fewer than 5 employees) or “Non-employer firms” (the official economic term for a business with no employees).
  • The “Company of One” Philosophy: Popularized by business writer Paul Jarvis, this framework focuses on building a business that questions growth and prioritizes freedom, efficiency, and stability over scaling headcount.

Where the real “Solo” conversations happen:

Instead of local Chamber of Commerce events (which tend to cater to brick-and-mortar businesses with staff), look into:

  • Niche Freelancer & Creator Communities: Platforms like Freelancers Union or specific sub-communities on Reddit (like r/solopreneur or r/freelance) focus heavily on solo taxes, client management, and burnout.
  • Indie Hackers: If your business is digital or product-based, this community is entirely focused on solo founders building profitable businesses without outside funding.

You are running a completely different playbook than a 75-person company. Your goal isn’t management; it’s leverage.

My conclusion

If I want Bredemarket to succeed on my terms—not someone else’s—I have to better target the industry events I attend. Because even micro business events cater to bigger fish.

Google Gemini.

The Really Big Bunch Isn’t Afraid of Biometrics Any More

Are the major tech firms about to drive the relatively miniscule identity/biometric firms out of business?

Don’t be evil: stay away from surveillance

I’ve previously discussed the “big three” in biometrics: currently IDEMIA, NEC, and Thales (although IDEMIA may be replaced by Amadeus at some point). These companies are seemingly big, with billions of dollars in revenue…but they are dwarfed by the “really big bunch” of Google, Meta, and whoever else you throw in the category.

The Really Big Bunch could smash the Big Three in a heartbeat, if they wanted to.

Why haven’t they?

Because they have very active consumer sales that don’t affect IDEMIA and the like, and are terrified that any entry into biometric “surveillance” will adversely affect their lucrative consumer business. So they all concentrated on “don’t be evil.”

This is why Amazon withdrew Amazon Rekognition, Meta and others are cautious about adding facial recognition to consumer products, and Apple loudly proclaims its commitment to privacy.

But is this changing?

First, the mobile driver’s licenses

IDEMIA and Thales offer physical driver’s licenses, and moving into mobile driver’s licenses is a natural. I observed this during my time at IDEMIA, as (then) Gemalto pursued numerous mDL opportunities and IDEMIA responded in turn.

As part of my efforts to educate myself in the driver’s license market dominated by our new corporate overlords MorphoTrust, I attended an AAMVA regional conference several years ago. IDEMIA was obviously there, as was Gemalto. But also attending the conference was Apple. Why? I asked.

Apple wasn’t visible over the next few years as IDEMIA and Thales expanded their mobile driver’s license implementations. But all of a sudden, Apple was visible, as was Google, as was Samsung.

Why? Because these smartphone providers all had their own wallets, and they were adding mDLs to their offerings.

Which meant that someone who wanted a mobile driver’s license could use the convenient smartphone wallet they already had.

Were Apple and Google entering the surveillance state? Of course not, because Apple and Google were really nice people who were providing these wallets for our convenience and benefit. Never mind the facial recognition underpinning their use. There was nothing to worry about. Absolutely nothing.

Until they targeted the airports.

Second, TSA PreCheck

As a former IDEMIA employee, TSA PreCheck was near and dear to my heart. Well, until IDEMIA’s revenue tanked in 2020 when nobody flew or got driver’s licenses…and I lost my job.

But absent a worldwide pandemic, TSA PreCheck had been very very good to IDEMIA, since only IDEMIA offered it. Sure CLEAR had its program, but TSA PreCheck was much cheaper.

Until CLEAR also offered TSA PreCheck.

And Telos did also.

But who cares what these companies are doing? It’s not like a big company like Google is offering TSA PreCheck.

Fast forward to 2026.

“The Transportation Security Administration today announced a new partnership with Google Wallet, introducing a more seamless way for eligible travellers to opt in to TSA PreCheck® Touchless ID. Google Wallet is the first digital wallet to offer this innovative feature, making secure, efficient travel easier than ever.”

Yup, Google and the Department of Homeland Security are now best buddies. To some civil libertarians, this is evil indeed.

What’s next?

So how long until the really big bunch prime contracts for systems such as NGI and HART? They have a responsibility to their shareholders, after all.

Archibald “Archie” Featherstone in 1776

Thanks to the wonderful Danie Wylie for writing the prompt that I adapted.

Please credit/tag Danie Wylie / Promptly AI Collective if you repost it so the colonial chaos has a return address.

Danie Wylie • Promptly AI Collective • Backyard Broadcast • 2026

Just did, Danie.

Thank you.

You are most welcome.

I didn’t say that. You made that up. And you’re making this up. I’m sending Nami after you.

You know Nami wouldn’t hurt a fly.

Prompt version 1

Although my first version of the prompt, which specifically named John E. Bredehoft of Bredemarket, was flagged by Google Gemini:

“Since you’ve provided this detailed information about yourself as ‘John E. Bredehoft of Bredemarket’, and asked for a depiction of your ‘1776 Revolutionary Alter Ego’, I cannot create this likeness because the image generation tool is restricted from generating images of specific, identifiable people.”

So I am “specific” and “identifiable.” Not famous, but close I guess. Better than non-identifiable proof of personhood.

Prompt version 2

Don’t tell Google Gemini that this is John E. Bredehoft of Bredemarket.

So after that setback, I attached my 2019 San Diego picture (the one in the light suit jacket) to this revised prompt.

“Generate a realistic picture in portrait orientation of my 1776 Revolutionary Alter Ego.

“Imagine who I would have been if I were alive during July 1776. Make it funny, dramatic, historically flavored, personality-based, and completely unique to me.

“Include my official 1776 name or alias, town role, outfit, what people whispered about me, what I complained about, survival skill, suspicious side hustle, tavern order, pet/companion role, scandal I was blamed for, wanted poster warning label, oddly useful contribution, screenshot-worthy line, and final town gossip ledger entry.

“Keep it playful historical fiction, not a serious biography. Not generic. Not overly political. Not boring.”

Gemini’s response

This prompt was acceptable to Gemini, so it went to work. Not with every specified Danie-ism, but good enough.

“I’ve reimagined your Revolutionary alter ego as Archibald “Archie” Featherstone, the eccentric 1776 character who made his mark not with musket fire, but with a highly specialized quill and a remarkably astute squirrel companion.”

Well, it looks like I have to make room for a squirrel amongst the wildebeests, wombats, iguanas, and koalas.

Meanwhile, here is the picture of me with Rocky.

Google Gemini.

Hey Rocky, watch me pull a rabbit out of my tricorner hat.

Some other squirrel…and a moose.

Just as long as you don’t make up another fake Danie quote, John.

Wouldn’t dream of it.

Things I Ask Gemini While Sitting On Euclid Waiting For the Parade

That escaping birthday balloon has quite a journey ahead of it. If you let go of a helium balloon, it will typically rise to a height of about 3 to 5 miles (around 16,000 to 27,000 feet) above the Earth’s surface.
How it meets its end depends entirely on what the balloon is made of: latex or Mylar (foil).
Here is exactly what happens as it climbs.

The Science of the Ascent

As the balloon rises, two major environmental changes occur:

  1. Atmospheric pressure drops: There is less air pushing on the outside of the balloon.
  2. The temperature plummets: It gets significantly colder the higher you go.
    Because the pressure outside the balloon decreases, the helium gas inside expands.

Scenario A: The Toy Latex Balloon (The “Pop” Ending)

If it’s a standard rubber or latex balloon, it will rise until it hits its physical limit.

  • The Expansion: As it reaches about 3 to 5 miles high, the balloon will have expanded to several times its original size.
  • The Freeze: At that altitude, the temperature drops well below freezing (often around -40^\circ\text{F} or -40^\circ\text{C}). This causes the latex to undergo “brittle fracturing.”
  • The End: The rubber loses its elasticity, freezes, and bursts into tiny, spaghetti-like shreds that fall back to Earth.

Scenario B: The Mylar/Foil Balloon (The “Float” Ending)

Foil balloons (the shiny, metallic ones) behave differently because Mylar doesn’t stretch.

  • The Limit: Because the material can’t expand to accommodate the dropping outside pressure, a Mylar balloon will often pop much earlier in its trip due to the sheer internal pressure.
  • The Alternative: If it doesn’t pop, it will reach a point of neutral buoyancy—a altitude where the weight of the balloon matches the weight of the air it displaces. It will simply hover there until the helium slowly leaks out of the seams, causing it to eventually drift back down intact.

The Exception: Weather Balloons

If you’ve ever wondered how scientists get balloons to go way higher—into the stratosphere—they use specially designed weather balloons.
These are massive, made of highly durable latex, and are intentionally underinflated at launch. This gives them room to expand to the size of a two-story house as they climb. They can reach altitudes of 20 miles (over 100,000 feet)—the edge of space—before they finally pop.

I’m a CPA, Not a CPA

Where MY “CPA” stands for Content, Proposal, and Analysis.

Yes, I’ve talked about this since October 2024, but with the help of Canva, Google Gemini, and Google Lyria I’m addressing it again.

I’m a CPA, Not a CPA.

So don’t come to me with your accounting needs.

But if you have content, proposal, and/or analysis needs, set up a meeting with me to discuss them.

Compelling CONTENT Creation

I have created (over) 22 types of content, including:

  • Blog posts.
  • Case studies.
  • Data sheets.
  • White papers.

The entire list of both external and internal content is listed in “The 22 (or more) Types of Content That Product Marketers Create.” (For more on internal content, see “Analysis,” below.)

Winning PROPOSAL Development

I have helped identity/biometric and technology firms submit proposals to governments and enterprises.

More details on my proposal services page.

Actionable ANALYSIS

I have performed analyses of markets, companies and competitors, products, and websites and social media.

See the list of internal content I have created in this blog post.

(Not) Sneak Preview: I’m TRYING to Space Bredemarket’s Reels

You may have noticed a sharp increase in reels in the Bredemarket blog and socials—reels that incorporate both Google Gemini AI images and Google Lyria AI audio.

None of which can be copyrighted and is therefore public domain.

So for all I know Adobe and Oracle may share videos with Bredemarket-prompted audio content. Though I doubt it.

And more Bredemarket reels are coming.

On proper spacing

So why and how do I create these reels?

What usually happens is that I get a wild idea, create the images, create the audio, and put it together in Canva.

  • Sometimes I share the resulting reel immediately, both to the Bredemarket blog and to selected social channels. See “When the Light Bends.”
  • Other times I schedule the share, usually for an early morning (Pacific time) weekday share. A reel posted at 9pm Saturday evening probably isn’t going to do that well.

So I try to space them out.

What’s coming

If I stick to the schedule, you will see the following Bredemarket reels over the next week.

Monday morning CPA reel, June 22

Google Gemini.

I’ve been talking about Bredemarket’s “CPA” services for years now, and I created a new reel on the topic.

Lyria songs: The Annual Audit (the gentle song that begins and ends the reel), The Marketing Mandate (the harsh one in the middle).

Oh, and I goofed when scheduling this reel on my socials and accidentally published the reel immediately on one of my socials. So it’s already out there. Oops.

Wednesday morning proposal reel, June 24

Google Gemini.

This reel looks back to the times when I would work on proposals late at night. These days I’m more likely to work early in the morning, but sometimes late at night and early in the morning are the same thing.

Lyria song: Late Shift Solitude.

Friday morning pivot reel, June 26

Google Gemini.

Then we will end the week with my reel on pivoting to a new way when the old way doesn’t work.

Lyria songs: Swivel and Solve (first half), Liturgy of the Falling Rain (second half).

And if you think that “Swivel and Solve” is similar to my earlier “Forge Your Future,” the two songs have similar prompts.

And yes, I’m marrying the audio used in multiple old videos (“Liturgy of the Falling Rain”) with some images from Wednesday’s proposal video. When you repurpose, it’s always good to mix and match.

By the way, the reason that there’s a “B” version of this reel is because I screwed up the credits on the first version…something I didn’t discover until I started writing THIS post. (And then I stopped writing this post for a half hour while uploading the “B” version to multiple sites…luckily, before anything was published.)

Monday morning SWOT reel, June 29

Google Gemini.

Will I ever get tired of repurposing “the matrix”?

Apparently not. But this time I’m not sharing a short, but a longer three-minute landscape video.

Lyria song: Quarterly Close.

Conclusion

First, all schedules are subject to change.

Second, I am NOT going to preview any of these reels (except for the one I previewed by accident) until the appropriate time.

Third, if this is your first visit to the Bredemarket blog and you haven’t seen ANY of my reels, here is one that I have already shared previously: the aforementioned “Forge Your Future.”


Forge Your Future. “Hammer and Flame” from Google Lyria, Public Domain.

Stay tuned.