GeneratePass
CATEGORY HUB

Authentication Security

Beyond passwords: understand multi-factor authentication, passkeys, biometrics, and the cryptographic protocols that verify identity in the modern web.

Frequently Asked Questions

What are the three factors of authentication? ▾
The three factors are: Knowledge (something you know, like a password or PIN), Possession (something you have, like a phone or hardware key), and Inherence (something you are, like a fingerprint or face scan). Multi-factor authentication combines two or more of these.
What is multi-factor authentication (MFA)? ▾
MFA requires two or more independent verification factors to grant access. Typically it combines something you know (password) with something you have (authenticator app code or hardware key). This means a stolen password alone is insufficient to compromise an account.
Are passkeys more secure than passwords? ▾
Yes. Passkeys use public-key cryptography tied to your device's biometrics and are cryptographically bound to the website's domain. They are completely immune to phishing, credential stuffing, and brute-force attacks because no shared secret is ever transmitted.
Is SMS 2FA secure enough? ▾
SMS 2FA is significantly better than no MFA, but it is vulnerable to SIM-swapping attacks and SS7 protocol exploitation. For important accounts, prefer authenticator apps (TOTP) or hardware security keys (FIDO2/WebAuthn) instead.
What is TOTP authentication? ▾
TOTP (Time-based One-Time Password) generates a temporary 6-digit code that rotates every 30 seconds. It is based on a shared secret key and the current time. Apps like Google Authenticator, Aegis, and 1Password generate TOTP codes locally without requiring network access.
How do hardware security keys work? ▾
Hardware keys like YubiKeys use the FIDO2/WebAuthn protocol. They generate a unique cryptographic signature for each website, proving your identity without transmitting any reusable secret. They are phishing-proof because the key verifies the website's domain before authenticating.
What is the difference between authentication and authorization? ▾
Authentication verifies who you are (identity proof). Authorization determines what you are allowed to do (access control). Authentication always comes first — you prove your identity, then the system checks your permissions.
🛡️

GeneratePass Editorial Team

Verified Author

The GeneratePass team builds client-side security tools and writes educational content focused on local execution, zero-trust patterns, and client-side data sovereignty.

Focus: Authentication • Standard: zero-trust