The “Safe Word” KBA is as Vulnerable as Other KBAs

Why knowledge-based authentication? Because, in theory, it’s something you know that no one else knows.

“Safe words” are a form of KBA.

  • You get a call from your son, who says he’s in jail and won’t be released unless you send money now. The voice sounds like your son, so you send the money. Of course, it isn’t your son, but a deepfake engineered to scam you of your money..
  • But if your son volunteers the “safe words” that the two of you previously selected, you have a much higher assurance that the voice on the phone is your son.

But, as Secrets of Privacy notes, safe words are also vulnerable. Some of their tips:

Safe words, not safe word

While password length requirements sometimes become ridiculous, they have a purpose. A longer password is harder to guess than a shorter one.

Similarly, four safe words are harder to guess than a single one.

Provided the words are unrelated. “The quick brown fox” is a terrible safe phrase.

That no one else knows

If someone can read your safe phrase online, it’s unsafe. I cannot use “California State University Fullerton” (on my LinkedIn profile) or “biometric product marketing expert” (all over this website).

Established together, preferably in person

Don’t rely on online establishment. People see things.

“Don’t text the safe phrase (even via Signal), never email it and don’t save it somewhere like in a cloud document or note app.”

And one more thing

If your purported son calls you, he’s the one to use the safe phrase…not you.

“Eva Velasquez, CEO of the Identity Theft Resource Center, sees this mistake constantly. A family sets up a safe word, and then in the panic of an actual emergency call, the intended victim blurts it out themselves trying to be helpful or trying to speed things along. A scammer who hears “wait, is this about our safe word, it’s soggy trombone” now owns your safe word. The rule has to run one direction only. Whoever is asking for money says the phrase unprompted, or the call gets treated as fraud, no exceptions.”

Admittedly the victim is under extreme pressure, but try to remember this. Blurting out the safe word is the equivalent of leaving your house keys in your front door lock, with a red arrow labeled “For burglars.”

When done right, safe phrases work

But don’t let this scare you away from safe phrases.

“The reason a safe phrase beats even a flawless voice clone is that it doesn’t rely on the voice being fake or real. It relies on information the scammer physically cannot have.”

How Other Experts Refer to “Somewhat You Why”

Unlike most other posts that appear under my name—Bredebot posts are another matter—this post breaks my 2023 rule because most of it was written by Google Gemini, not me.

But I figured that if I wrote a book specifically about SIX factors of authentication…

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
The book.

…it would be nice to know if other experts held similar thoughts.

My prompt to Gemini

Bredemarket has promoted “somewhat you why” as a sixth factor of identity verification / authentication. Has anyone else shared similar observations?

Gemini’s response

Here is the short answer: Yes, industry experts and security frameworks strongly agree with the core observation, though they call it “Authentication Intent,” “Intent Verification,” or “Context-Aware/Risk-Based Authentication” rather than using Bredemarket’s play-on-words.

Shifting Truths. Google Lyria. Public Domain.

John Bredehoft (Bredemarket) coined “somewhat you why” to fit the traditional naming convention (something you know, have, are, do, somewhere you are). His argument is that checking why an action or request is taking place—evaluating intent, transaction risk, or reasonableness—functions as a crucial safeguard, especially in an era of deepfakes and automated AI agents.

While the tongue-in-cheek name is unique to Bredemarket, the concept itself is widely discussed and implemented across the cybersecurity industry under three main paradigms:

1. “Authentication Intent” (NIST Standards)

The National Institute of Standards and Technology (NIST) explicitly addresses intent in NIST SP 800-63B.

  • The Problem: A user might have a valid session token, biometrics, or physical key plugged in, but malware or a session hijack could trigger actions without the user’s conscious decision.
  • The Solution: Systems require an explicit act of intent—like tapping a physical FIDO key, typing a PIN, or responding to a contextual prompt—proving that the user intended to execute that specific action at that moment.

2. Intent Verification for AI & Delegated Actions

With the rise of autonomous AI agents and automated workflows, identity security groups (like the Non-Human Identity/NHI movement) frequently discuss Intent Verification.

  • Conventional authentication proves who logged in, but not whether the user meant to perform this specific action.
  • Intent Verification bridges authentication and authorization by evaluating whether a transaction (e.g., a $35M wire transfer or an API call) aligns with the user’s actual current decision and business policy.

3. Context-Aware and Adaptive Authentication

Identity providers (like Palo Alto Networks, Okta, and Silverfort) build their Adaptive Multi-Factor Authentication (AMFA) around the “why” and “context”:

  • Context Signals: What resource is being accessed? Is this normal business behavior? Does this request make sense given the time, value, and sensitivity?
  • Dynamic Step-Up: If the “why” seems low-risk (e.g., checking internal docs during work hours), access is smooth. If the “why” is high-risk or suspicious (e.g., a wire transfer requested via video call), the system demands step-up verification.

How the Views Compare

While most identity security professionals treat “intent and context” as a governance or risk engine layer wrapping traditional factors rather than a 6th factor itself, everyone agrees with Bredemarket’s baseline premise: verifying who someone is without evaluating what and why they are trying to do it is no longer enough to stop modern fraud.

Double It To 200 Proof, Steve

Coincidence again? I discussed something from long ago and found myself dealing with it today. Sort of. Prove me wrong.

I recently had occasion to refer to a year-old post that warned about authenticating online customers with knowledge based authentication. There is no guarantee that the person on the other end of the line is actually your customer.

JOE’S ALCOHOL EMPORIUM: Evelyn, what types of alcohol do you prefer?

“EVELYN’S TEENAGE SON WHO KNOWS HER PASSWORD IS HIS BIRTHDATE: 200 proof, man! Let’s get wasted!”

His mom is gonna be so mad…

Meanwhile Steve Craig—formerly of PEAK IDV, now with Prove—is participating in the launch of a new podcast.

Its name?

100proof Powered by Prove.

Steve, should you double the proof to attract the drunken teenager crowd?

Google Gemini. Deepfake. This is not real.

I guess not, since these aren’t Prove’s hungry people…I mean thirsty people.

But if you are in Prove’s…um…target audience, you will be (as LinkedIn says) excited and thrilled to learn that 100proof’s first guest is Steve Craig’s coworker Frances Zelazny, who has joined Prove as its General Manager of New Market Initiatives. Zelazny offers immense expertise in the identity industry. In fact we were coworkers for a few months at Safran, but she was on the other side of the impenetrable wall between MorphoTrust and MorphoTrak.

Join Steve and Frances today at 2pm Pacific Time on LinkedIn.

How to Figure Out Someone’s Mother’s Maiden Name

Something you know…and that someone else knows. It can happen.

Many systems require more than one knowledge-based modality, which is why they sometimes ask for other things like your mother’s maiden name.

This of course is not foolproof. Your sister that hates your guts, for example, obviously knows your mother’s maiden name. And even complete strangers, especially those with nefarious intent, can deduce your personal information.

Let me introduce you to Doug.

How Doug learned Donna’s mother’s maiden name…and more

Assume that Doug wants to hack Donna’s account but needs some personal information to do so. This is somewhat tough, since Donna’s Facebook account is private and can only be seen by her friends. Well, Doug knows that Belle is a friend of Donna’s, and Belle’s Facebook password is “password1.” Problem solved.

Doug uses Belle’s account to read Donna’s posts and finds some remarkably interesting ones. Not that she’s posting her Social Security Number or anything, but what did she post?

  • “Happy birthday to my mom!” (This particular post was loved by Jane Davis, who wrote “Thank you dear daughter.”)
  • “Happy 30th birthday to me!”
  • “Hey, look at this picture of my new driver’s license. My picture actually looks halfway decent.”
  • “Hey, look at this picture of my senior citizen bus pass. Yeah, I’m old.”
  • “I cried when I looked at this old picture of my dog Scamper, taken in front of my childhood home on Mulberry Street.”

If you’re keeping score at home, Doug now knows the following information about Donna:

  • Her mother’s maiden name.
  • Her date of birth (from her birthday post and her driver’s license picture; her senior citizen’s bus pass doesn’t have her birthdate but does have her birthday).
  • Her driver’s license number.
  • The name of her favorite pet.
  • The name of the street she lived on as a child.

More than enough for Doug to impersonate Donna.

Learn more about the six identity factors

Six identity factors. One Bredemarket ebook. Total identity protection. Purchase “Proving Humanity: The Six Factors of Identity Verification and Authentication.”

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket., Click on the image to purchase.

Types of Knowledge-Based Modalities

Something you know.

We know a lot of things, we can tell the system the things we know, and the system can confirm that the person accessing the system knows these same things.

Here are a few examples of knowledge-based information:

  • Passwords.
  • Personal Identification Numbers (PINs).
  • Social Security Numbers.
  • Driver’s License Numbers.
  • Dates of Birth.
  • Employee IDs.
  • Mother’s maiden name.
  • Name of your favorite pet.
  • Name of the street you lived on as a child.

Some of these pieces of personally identifiable information (PII) are more commonly known than others. The, um, secret is to choose a piece of knowledge that ONLY YOU know.

But remember: anything that you know is potentially known by others.

Learn more about the six identity factors

Six identity factors. One Bredemarket ebook. Total identity protection. Purchase “Proving Humanity: The Six Factors of Identity Verification and Authentication.”

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket., Click on the image to purchase.

Names Are Replaceable

(Patti Smith picture by Harald Krichel – Own work, CC BY-SA 4.0, https://commons.wikimedia.org/w/index.php?curid=151929930.)

My very first bad blog joke (back in October 2003) was tangentially related to knowledge-based authentication:

“When Patti Smith married Fred Smith, did she take her husband’s last name, or keep her maiden name?”

Because Patti didn’t change her name, but many people do.

Which means that even if a name is unique, it is not as accurate a form of identification as, say, irises.

If you don’t believe me, ask Richard Meyers and Thomas Joseph Miller.

Better known as Richard Hell and Tom Verlaine.

Patti Smith.

My Favorite Knowledge-Based Authentication (KBA) Failure

If the identity you’re protecting is important, knowledge-based authentication (KBA) isn’t sufficient to protect it. There’s an example of a KBA failure that I originally discussed in 2024 in a “The Wildebeest Speaks” article, but since I’m citing it again on LinkedIn I might as well mention it here.

Consider the following four criteria:

  • The person is a famous musician.
  • The person uses a particular first and last name.
  • The person is of a particular nationality.
  • The person plays a particular musical instrument.

That’s not enough to identify an individual.

Just ask the famous musician Mick Jones, the English guitarist.

Here he is (on the left) playing guitar for the song “Urgent.” (Or, more accurately miming to a previous recording. The recording included Junior Walker and Thomas Dolby, but the video did not.)

And here is Jones again, playing guitar and singing “Should I Stay Or Should I Go.”

“Wait a minute, John!” you’re saying. “Those are two different bands and two different people!”

Right.

And for those who thought all the members of Foreigner were American

“By 1974 we found in Spooky [Tooth] that we were getting a better reception in the States than back home in Britain, so made a collective decision to relocate to New York….

“[After Gary Wright quit Spooky Tooth] I [Mick Jones the English guitarist] was left high and dry in New York, and without a clue as to what my next move was going to be. I seriously considered returning to England and starting over a whole new career, such as going to medical school or becoming a dentist. The second option was the most attractive to me, because it took less time to qualify and paid good money.”

But dentistry’s loss was music’s gain, as Jones assembled two other British people and three Americans into a band called Foreigner.

And considering that the other Mick Jones was kicked out of the Clash, we can figure out how THAT band got its name.

Anyway, “Mick Jones the English guitarist” remains my favorite example of a knowledge-based authentication failure.

Grok.

Because you need multiple ways to verify and authenticate identities. I should know.

Biometric product marketing expert.

The “Biometric Digital Identity Deepfake and Synthetic Identity Prism Report” is Coming

As you may have noticed, I have talked about both deepfakes and synthetic identity ad nauseum.

But perhaps you would prefer to hear from someone who knows what they’re talking about.

On a webcast this morning, C. Maxine Most of The Prism Project reminded us that the “Biometric Digital Identity Deepfake and Synthetic Identity Prism Report” is scheduled for publication in May 2025, just a little over a month from now.

As with all other Prism Project publications, I expect a report that details the identity industry’s solutions to battle deepfakes and synthetic identities, and the vendors who provide them.

And the report is coming from one of the few industry researchers who knows the industry. Max doesn’t write synthetic identity reports one week and refrigerator reports the next, if you know what I mean.

At this point The Prism Project is soliciting sponsorships. Quality work doesn’t come for free, you know. If your company is interested in sponsoring the report, visit this link.

While waiting for Max, here are the Five Tops

And while you’re waiting for Max’s authoritative report on deepfakes and synthetic identity, you may want to take a look at Min’s (my) views, such as they are. Here are my current “five tops” posts on deepfakes and synthetic identity.