How Other Experts Refer to “Somewhat You Why”

Unlike most other posts that appear under my name—Bredebot posts are another matter—this post breaks my 2023 rule because most of it was written by Google Gemini, not me.

But I figured that if I wrote a book specifically about SIX factors of authentication…

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
The book.

…it would be nice to know if other experts held similar thoughts.

My prompt to Gemini

Bredemarket has promoted “somewhat you why” as a sixth factor of identity verification / authentication. Has anyone else shared similar observations?

Gemini’s response

Here is the short answer: Yes, industry experts and security frameworks strongly agree with the core observation, though they call it “Authentication Intent,” “Intent Verification,” or “Context-Aware/Risk-Based Authentication” rather than using Bredemarket’s play-on-words.

Shifting Truths. Google Lyria. Public Domain.

John Bredehoft (Bredemarket) coined “somewhat you why” to fit the traditional naming convention (something you know, have, are, do, somewhere you are). His argument is that checking why an action or request is taking place—evaluating intent, transaction risk, or reasonableness—functions as a crucial safeguard, especially in an era of deepfakes and automated AI agents.

While the tongue-in-cheek name is unique to Bredemarket, the concept itself is widely discussed and implemented across the cybersecurity industry under three main paradigms:

1. “Authentication Intent” (NIST Standards)

The National Institute of Standards and Technology (NIST) explicitly addresses intent in NIST SP 800-63B.

  • The Problem: A user might have a valid session token, biometrics, or physical key plugged in, but malware or a session hijack could trigger actions without the user’s conscious decision.
  • The Solution: Systems require an explicit act of intent—like tapping a physical FIDO key, typing a PIN, or responding to a contextual prompt—proving that the user intended to execute that specific action at that moment.

2. Intent Verification for AI & Delegated Actions

With the rise of autonomous AI agents and automated workflows, identity security groups (like the Non-Human Identity/NHI movement) frequently discuss Intent Verification.

  • Conventional authentication proves who logged in, but not whether the user meant to perform this specific action.
  • Intent Verification bridges authentication and authorization by evaluating whether a transaction (e.g., a $35M wire transfer or an API call) aligns with the user’s actual current decision and business policy.

3. Context-Aware and Adaptive Authentication

Identity providers (like Palo Alto Networks, Okta, and Silverfort) build their Adaptive Multi-Factor Authentication (AMFA) around the “why” and “context”:

  • Context Signals: What resource is being accessed? Is this normal business behavior? Does this request make sense given the time, value, and sensitivity?
  • Dynamic Step-Up: If the “why” seems low-risk (e.g., checking internal docs during work hours), access is smooth. If the “why” is high-risk or suspicious (e.g., a wire transfer requested via video call), the system demands step-up verification.

How the Views Compare

While most identity security professionals treat “intent and context” as a governance or risk engine layer wrapping traditional factors rather than a 6th factor itself, everyone agrees with Bredemarket’s baseline premise: verifying who someone is without evaluating what and why they are trying to do it is no longer enough to stop modern fraud.

The Current State of ANSI INCITS 378 / MINEX III Compliant Fingerprint Template Generators and Matchers

Vendors that develop fingerprint templates and matchers usually develop their own proprietary algorithms, but there is one instance in which the vendors work together.

ANSI INCITS 378-2009 (S2019) specifies a universal fingerprint format, and vendors can develop 378-compatible template generators and matchers.

How are these measured? By NIST’s MINEX III testing.

To find the current results dfor MINEX III compliant template generators and matchers, visit https://www.nist.gov/itl/iad/btg/minex-iii-compliant-submissions.

When sorted in NIST default order for a false negative match rate at a given false match rate (“Pooled 2 Fingers FNMR @ FMR≤10-2), the top vendors include IDEMIA, Innovatrics, and Neurotechnology.

But remember that this only matters when using ANSI INCITS 378 templates. It doesn’t matter if you’re using a vendor’s proprietary template.

So who uses ANSI INCITS 378 templates?

  • Cards and systems based upon Personal Identity Verification (PIV) templates, as specified by Homeland Security Presidential Directive 12 (HSPD-12) and FIPS 201.
  • Certain cards using Match-on-Card technology.

But most systems you encounter will NOT use ANSI INCITS 378, so the standard may not matter to you at all.

Do your customers care?

But even if you are deploying systems that use ANSI INCITS 378, your customers don’t care.

They just care about complying with federal regulations for PIV cards.

If you need help stating customer-focused benefits rather than vendor-focused features, turn to Bredemarket’s content-proposal-analysis services for identity, biometric, and technology firms.

Marketing a Biometric Product Without a Biometric Product Marketing Expert

Bob and Judy had left television production and started a biometric company. Bob handled sales, Judy engineering. As their company grew, they both realized they needed help.

Bob turned to Judy one day. “What we need is a product marketer, but not just any product marketer. We need a biometric product marketing expert. I know a guy-“

Judy cut him off. “Forget it. Any so-called expert is hampered by legacy. We need new thinking.”

As they used to say, you won’t believe what happened next!

All the features

Ron, their new hire, was a fast learner who listened to Judy for hours, soaking up everything she knew until Ron understood every feature perfectly.

Google Gemini.

Ron assembled his product marketing materials, clearly differentiating the superior technical advantages of his product. Bob then took the materials out on a sales call.

That afternoon Bob returned, dejected.

“The prospect threw the brochures in the trash.”

“Why?” Ron asked.

“They didn’t make sense and didn’t speak to their needs.”

None of the use cases

Ron belatedly realized that the materials didn’t address the benefits the prospect would realize from using Bob and Judy’s biometric solution. And the owners realized that Ron needed to understand the biometric market so that his materials resonated with customers.

Google Gemini.

So Ron studied the market carefully, spending a lot of time with cops and forensic experts before rewriting his brochures to infuse them with industry knowledge.

A well-prepared Bob flew out to meet his next prospect, a well-known sports team in Chicago.

And returned the next day, dejected again.

“They loved the first hour,” Bob reported, “although all the talk about investigative leads confused them. Then they asked about consent.”

Ron, fresh from police station booking rooms, was confused. “Who needs consent to take bionetrics?”

“Sports teams, banks, hotels, office buildings, hospitals, you name it,” Bob replied. “Especially in Illinois.”

Fumbling Towards Insolvency

Sarah McLachlan. “Found a Job” it’s NOT.

Maybe “insolvency” is harsh, but if a biometric firm doesn’t have the embedded knowledge to speak the language of its prospects and customers, the firm’s success will be limited. Immediate expertise is impossible.

“A Patient Hand.” Google Lyria. Public Domain.

Bob, Judy, and Ron may be fictional, but lack of biometric expertise happens in real life. I still remember the time I worked with a company that was bragging about its three-year old NIST FRTE facial recognition accuracy rankings. I gently explained that FRTE results change monthly, with better algorithms appearing all the time. Those old results were worthless.

And your product marketing will be worthless also, unless you understand the many products and many markets.

Bredemarket can help you speak the language of your biometric prospects. Talk to Bredemarket.

Noah Kalina Everyday and NIST Face and Iris Testing

(Image By Noah Kalina – https://flickr.com/photos/arvadacenter/7205535002/, Fair use, https://en.wikipedia.org/w/index.php?curid=69354953)

When the National Institute of Standards and Technology (NIST) performs biometric testing, it generally uses government data from law enforcement, homeland security, and similar sources.

Plus some specialized data that government databases can’t match.

On January 10, 2000, Noah Kalina took a selfie. The next day, he took another. And he kept on doing it every day, with some exceptions, for many years. (Here he is on June 1, 2026.) By centering his nose in the center of the frame, the pictures provide a consistent chronicle of Kalina’s appearance, along with the exact day on which the pictures were taken. NIST purchased rights to some of these photos to use in its age estimation testing. Since NIST knew Kalina’s true age on any given day, it could measure an age estimation algorithm’s accuracy.

But that’s not why I’m writing about Noah Kalina.

Let’s move to irises

Consider the irises of the face, how they are captured. They are usually captured with expensive cameras that take a picture from a short distance away.

But what if a normal camera captured a person, and their irises? Could the camera images yield useful information?

James Matey wanted to find out.

[The Kalina images] “provide us with interesting opportunities to explore the effects of time lapse on iris recognition employed on images that were not originally intended for iris recognition. NIST obtained a license from Kalina to use a subset (7 half years from 2009-2015) of original, high resolution, digital images in biometric studies.”

So were they useful?

“…even though the majority of the images in this dataset did not provide solid matches, there are instances where mated iris image pairs from visible light images that were not obtained for the purpose of iris recognition match with match scores corresponding to a false match rate of 0:1% at a true accept rate of 1% . Though such performance is not useful in applications such as access control, there are cases where it may be useful.”

No, your irises can’t be easily captured in 2026, but what about later?

Another Great Renaming (From 2024)

In August 2023, I talked about what I called a “great renaming” in which the National Institute of Standards and Technology (NIST) differentiated between its face recognition tests and its face analysis tests: a very important distinction and a critical update.

FRVT becomes FRTE and FATE. From NIST.

The ramifications of that renaming persist. Just last week I reminded a biometric firm that its references to “FRVT” were dated.

But what if references to biometrics are dated?

Find…what?

Over twenty years ago a publication called FindBiometrics was established that discussed you-know-what. Fingerprints, faces, irises, and all sorts of stuff.

You would think that a name that incorporated “biometrics” would be all inclusive. It certainly was twenty years ago. But as the industry evolved, the name became a little dated. While biometrics remain critically important, I have to say (with apologies to my former Motorola colleague Edward Chen) that biometrics is not “4” ALL. (You see what I did there.)

The publication realized this also, and performed its own great renaming.

“TORONTO, ONTARIO, CANADA, November 21, 2024 /EINPresswire.com/ — FindBiometrics, a leading news media platform for the biometrics and digital identity industry, is now ID Tech—a refreshed brand identity that reflects the beginning of a new era in the identity technology space.”

Why?

“…the scope of identity tech has expanded to integrate new developments in areas like artificial intelligence, blockchain, and digital ID.”

One example being mobile driver’s licenses, which can utilize biometrics but goes far beyond it. After all, biometrics (something you are) is just one of the six factors of identity verification and authentication. See below.

So now the former FindBiometrics platform is called “ID Tech,” and its URL is now https://idtechwire.com/. And biometrics now shares the stage with other factors.

Biometrics shares the stage. “Revealed” from Google Lyria; Public Domain.

But ID Tech isn’t the only place to learn about identity beyond biometrics. There’s also my book.

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.

Today’s Acronyms Are NIST, FRIF, TE, E1N, and ROC

ROC (previously known as Rank One Computing) posted this about its latest resukts in the NIST Friction Ridge Image and Features Technology Evaluation Exemplar One-to-Many (FRIF TE E1N) evaluation.

“ROC’s performance in the NIST FRIF TE E1N evaluation, including #1 global ranking in Class B slap fingerprints, a critical capture format for high-scale civil and government identity programs, proves that American technology can now lead at the highest levels of global biometric performance….

“The NIST Friction Ridge Image and Features Technology Evaluation Exemplar One-to-Many evaluation, known as NIST FRIF TE E1N, evaluates one-to-many fingerprint identification at massive scale, testing how accurately algorithms can identify a subject from large enrollment repositories. Across the evaluation, ROC delivered top-tier performance in every category tested, including Class A, Class B, and Class C. “

As with every NIST biometric test, FRIF yields a massive amount of data. Just looking at the Class B slap data alone, here is what you can find, showing the top 7 entries out of 12 for the Class B Left Slap FNIR (another acronym: false negativce identification rate) at rank less than or equal to 10. Even this view excludes all other slap data and all other ranking data (1, 2, and 5).

(Data captured Friday, May 29, 2026 and may become outdated when new algorithms are tested.)

National Institute of Standards and Technology.

With this massive wealth of data, just about every vendor probably performed well in something, which is why ROC took the time to point out why Class B slap results are important.

“ROC’s most significant milestone came in Class B slap fingerprints. This performance is especially important for high-scale ABIS environments, including national ID programs, border management, civil enrollment, and high-stakes criminal justice workflows, where handling immense scale without sacrificing accuracy is mandatory.”

Although ROC may be the only entity trumpeting May results, other vendors have promotede earlier NIST FRIF TE E1N achievements, including IDEMIA, Identy.IO, Innovatrics, and Neurotechnology.

But they’re foreign. (As is Thales Group, for those keeping score.)

How Do You Talk About the Product “Plumbing”?

There are a variety of hungry people (target audiences) who look at your product marketing content. And they all have different needs.

  • When talking about an elegant water fountain, some readers only care that the fountain works.
  • Other readers want to know HOW it works. Issues such as support and maintenance are critically important to these folks, but matter little to the first group who simply wants a working fountain.

If you are forced to speak to both target audiences in a single piece of content, how do you do it?

Very carefully.

My preference is to discuss the high-level benefits at the beginning of the content, and save the more technical uptime details and/or feature lists for later in the narrative.

Unless you are ONLY speaking to technical folks, leading with the “plumbing” kills your content. Someone who wants their police agency to solve more burglaries will fall asleep at a mention of 1000 pixels per inch fingerprint resolution or NIST-compliant lower palm print image dimensions.

Stay light, and only go deep to buttress your lightness.

Close to a Milestone

One of Bredemarket’s clients is microscopically close to achieving an important milestone with a major customer. As project manager I’m performing the issue tracking and am happy. It is premature to announce this customer milestone, but hopefully the day will come.

The only drawback was that a last-minute Bredemarket / client / customer call prevented me from attending Tuesday’s live iProov / Ingenium webinar on independent testing to standards such as NIST SP 800-63-4 and CEN/TS 18099. But that’s why webinars have replays.

The Bredemarket post below is not directly related to the webinar, but is tangentially related since it discusses independent testing.

iProov’s Four Questions on Independent Testing

I hope you’re sitting down for this…but vendors make assertions that favor themselves. Or in this case “favour,” because the vendor in question is iProov.

The English company shared four questions on independent testing of vendor claims, and I think we can all predict how iProov would answer these four questions.

But that doesn’t negate the importance of the questions.

  1. Which independent lab(s) tested the system? Not just a vendor red team, or a partner story. An accredited third party.
  2. Against which standard? ISO/IEC 30107-3, CEN/TS 18099, FIDO Face Verification, or a combination? Defending against the full attack spectrum matters.
  3. At what level? Substantial, High? If the level isn’t listed, be sure to ask why.
  4. When? Standards evolve. Threat models evolve faster. Certifications can age quickly.

Yes, you can claim that customer testing is more important than independent testing.

And some have claimed that independent testing is flawed because it doesn’t test properly. (One semi-related example: because FBI EBTS Appendix F assumes that the fingerprints contact the capture surface, it is useless for contactless solutions. The powers that be are working on an alternative.)

But if your solution doesn’t have independent test or conformance results, you’d better have a good reason.

Three Ways in Which My Identity/Biometric Experience Exhibits My “Bias”

Yeah, I’m still focused on that statement:

“I think too much knowledge is actually bad in tech: you’re biased.”

Why does this quote affect me so deeply? Because with my 30-plus years of identity/biometric experience, I obviously have too much knowledge of the industry, which is obviously bad. After all, all a biometric company needs is a salesperson, an engineer, an African data labeler, and someone to run the generative AI for everything else. The company doesn’t need someone who knows that Printrak isn’t spelled with a C.

Google Gemini.

In this post I will share three of the “biases” I have developed in my 30-plus years in identity and biometrics, and how to correct these biases by stripping away that 20th century experience and applying novel thinking.

And if that last paragraph made you throw up in your mouth…read to the end of the post.

But first, let’s briefly explore these three biases that I shamefully hold due to my status as a biometric product marketing expert:

  1. Independent algorithmic confirmation is valuable.
  2. Process is valuable.
  3. Artificial intelligence is merely a tool.
Biometric product marketing expert.

Bias 1: Independent Algorithmic Confirmation is Valuable

Biometric products need algorithms to encode and match the biometric samples, and ideally to detect presentation and injection attacks.

But how do prospects know that these algorithms work? How accurate are they? How fast are they? How secure are they?

My bias

My brain, embedded with over 30 years of bias, gravitates to the idea that vendors should submit their algorithms for independent testing and confirmation.

From a NIST facial recognition demographic bias text.

This could be an accuracy test such as the ones NIST and DHS administer, or confirmation of presentation attack detection capabilities (as BixeLab, iBeta, and other organizations perform), or confirmation of injection attack detection capabilities.

Novel thinking

But you’re smarter than that and refuse to support the testing-industrial complex. They have their explicit or implicit agendas and want to force the biometric vendors to do well on the tests. For example, the U.S. Federal Bureau of Investigation’s “Appendix F” fingerprint capture quality standard specifically EXCLUDES contactless solutions, forcing everyone down the same contact path.

But you and your novel thinking reject these unnecessary impediments. You’re not going to constrain yourself by the assertions of others. You are going to assert your own benefits. Develop and administer your own tests. Share with your prospects how wonderful you are without going through an intermediary. That will prove your superiority…right?

Bias 2: Process is Valuable

A biometric company has to perform a variety of tasks. Raise funding. Hire people. Develop, market, propose, sell, and implement products. Throw parties.

How will the company do all these things?

My bias

My brain, encumbered by my experience (including a decade at Motorola), persists in a belief that process is the answer. The process can be as simple as scribblings on a cocktail napkin, but you need some process if you want to cash out in a glorious exit—I mean, deliver superior products to your customers.

Perhaps you need a development processs that defines, among other things, how long a sprint should be. A capture and proposal process (Shipley or simpler) that defines, among other things, who has the authority to approve a $10 million proposal A go-to-market process that defines the deliverables for different tiers, and who is responsible, accountable, consulted, and informed. Or maybe just an onboarding process when starting a new project, dictating the questions you need to ask at the beginning.

Bredemarket’s seven questions. I ask, then I act.

Novel thinking

Sure all that process is fine…if you don’t want to do anything. Do you really want to force your people to wait two weeks for the latest product iteration? Impose a multinational bureauracy on your sales process? Go through an onerous checklist before marketing a product?

Google Gemini.

Just code it.

Just sell it.

Just write it.

Bias 3: Artificial Intelligence is Merely a Tool

The problem with experienced people is that they think that there is nothing new under the sun.

You talk about cloud computing, and they yawn, “Sounds like time sharing.” You talk about quantum computing, and they yawn, “Sounds like the Pentium.” You talk about blockchain, and they yawn, “Sounds like a notary public.”

My bias

As I sip my Pepperidge Farm, I can barely conceal my revulsion at those who think “we use AI” is a world-dominating marketing message. Artificial intelligence is not a way of life. It is a tool. A tool that in and of itself does not merit much of a mention.

Google Gemini.

How many automobile manufacturers proclaim “we use tires” as part of their marketing messaging? Tires are essential to an automobile’s performance, but since everyone has them, they’re not a differentiator and not worthy of mention.

In the same way, everyone has AI…so why talk about its mere presence? Talk about the benefits your implementation provides and how these benefits differentiate you from your competitors.

Novel thinking

Yep, the grandpas that declare “AI is only a tool” are missing the significance entirely. AI is not like a Pentium chip. It is a transformational technology that is already changing the way we create, sell, and market.

Therefore it is critically important to highlight your product’s AI use. AI isn’t a “so what” feature, but an indication of revolutionary transformative technology. You suppress mention of AI at your own peril.

How do I overcome my biases of experience?

OK, so I’ve identified the outmoded thinking that results from too much experience. But how do I overcome it?

I don’t.

Because if you haven’t already detected it, I believe that experience IS valuable, and that all three items above are essential and shouldn’t be jettisoned for the new, novel, and kewl.

  • Are you a identity/biometric marketing leader who needs to tell your prospects that your algorithms are validated by reputable independent bodies?
  • Or that you have a process (simple or not) that governs how your customers receive your products?
  • Or that your AI actually does unique things that your competitors don’t, providing true benefits to your customers?

Bredemarket can help with strategy, analysis, content, and/or proposals for your identity/biometric firm. Talk to me (for free).

By the way, here’s MY process (and my services and pricing).

Bredemareket: Services, Process, and Pricing.