Introducing TypingDNA Human Likeness – A Novel Bot Detection Approach for the AI Age 

Multi-Factor Authentication (MFA)

Multi-Factor Authentication, also known as MFA (or just 2FA), is a process of identity verification that enhances security when a user logs in to an account, system, or application. MFA requires users to verify their identity using two or more authentication factors.

A common first authentication factor is a password, typically entered together with a username. Other authentication factors range from SMS One-Time Passcodes (OTPs), physical security keys, and push notifications to physiological and behavioral biometrics.

What is Multi-Factor Authentication (MFA), and how does it work?

MFA is a security measure that helps prevent unauthorized users from accessing an account. MFA works by requiring someone attempting to log in to an account, system, or application to prove their identity in more than one way before being granted access. Two-factor authentication (2FA) is a form of MFA that uses two authentication factors.

There are three main categories of Multi-Factor Authentication factors: knowledge, possession, and inherence. A common drawback of traditional MFA is increased user friction, as users may have to perform additional steps before accessing an account. Depending on the authentication methods used, MFA can also add implementation and operational costs.

  1. MFA knowledge factors - something you know. Knowledge-based MFA methods such as passwords, PINs, and security questions can be compromised through phishing, credential theft, reuse, or guessing. Find out why passwords are no longer enough.

  2. MFA possession factors - something you have. These include SMS one-time passcodes (OTPs), authenticator apps, push notifications, and physical security keys. Possession factors can significantly improve account security, although some methods require users to have access to an additional device and may introduce extra steps into the login experience. SMS OTP however, is vulnerable to SIM swap, phone theft, and MITM, but can be strengthened with solutions such as TypingDNA SMS+, which adds a typing biometrics challenge before the OTP is revealed.

  3. MFA inherence factors - something you are. Inherence factors authenticate users based on individual characteristics, including physiological biometrics and behavioral biometrics. Physiological biometrics include fingerprint and face recognition, while behavioral biometrics include technologies such as typing biometrics that can verify identity based on how a person behaves.

TypingDNA provides different ways to use typing biometrics within MFA. TypingDNA Verify 2FA verifies users based on how they type 4 short words displayed on-screen, providing 2FA without requiring a phone or additional hardware. For organizations that want to keep SMS OTP, TypingDNA SMS+ strengthens the existing SMS flow by replacing the exposed OTP with a secure link where users complete a short typing challenge before the OTP is revealed. Both approaches can integrate with existing authentication and most IAM environments.