Proving control of an account
Returning to an account
Imagine returning to the photo-sharing application a week after creating your account. You enter your email address, but anyone who knows that address could do the same. The application needs more than a way to find your account. It needs evidence that you are the one who controls it.
During registration, you chose a password. When you return, the application checks the password you provide against a securely stored representation of it. Your email address identifies the account; the password supplies evidence supporting your claim to use it.
What authentication establishes
Authentication checks whether someone controls an authenticator associated with an account. An authenticator might be a password, an application that generates one-time codes, or a security key.
The association matters. Having a security key does not let you authenticate to any account. The service must first register it to the appropriate account through a trusted process.
Successful authentication gives the service confidence in that connection. It does not establish that every detail in the account is true, or guarantee that the person signing in is its rightful holder. Someone who steals a password may be able to satisfy the same check.
Different kinds of evidence
Authentication factors describe the kinds of evidence involved:
- Something you know: a secret, such as a password or PIN.
- Something you have: control of an authenticator, such as a security key.
- Something you are: a biometric characteristic, such as a fingerprint.
A fingerprint can unlock an authenticator on your device, which then proves control to the service. The fingerprint itself does not need to be sent to the website.
Building confidence
The photo-sharing application might require both your password and a code from an authenticator app. This combines knowledge of a secret with control of a registered authenticator.
Multi-factor authentication (MFA) uses more than one type of factor. Two passwords are still the same type, even if they appear on separate screens. The number of steps alone does not tell you how strong the authentication is.
Methods also resist different attacks. A fake login page can trick someone into entering a password and a one-time code. Phishing-resistant methods are designed to prevent that kind of impersonation.
The Authentication methods lessons, starting with Methods, credentials, and factors, look at each of these in detail: how passwords, one-time codes, and passkeys are checked, how authenticators are enrolled, replaced, and recovered, and what makes a method resistant to phishing.
From authentication to access
After signing in, you might be able to edit your own photos while only viewing someone else’s shared album. The application has accepted your authentication, but it still needs to decide which actions to allow.
That next decision is authorization.
Continue to Deciding what someone can do to explore how permissions and policy determine access.