About this interactive
Multi-factor authentication is only strong when the factors are genuinely different kinds of evidence, and that is what the four categories are for. Something You Know is recalled from memory. Something You Have is a physical object in your possession. Something You Are is a measurement of your body. Somewhere You Are is your position when you ask for access. Two passwords are not two factors, because both are the same kind of proof and both fall to the same theft. The category is the point, not the count. The Know bin is memory, and nothing else. A password, a passphrase and a PIN are obviously recalled. Two others in this set are less obvious and are worth slowing down for. A security question answer feels personal — your first pet, your mother's maiden name — and that personal flavour tempts people toward Something You Are. It is not. Nothing is being measured about your body; you are reciting a stored fact, which is exactly why security questions are weak, since the fact is often published on the social media of the person you are trying to protect. A pattern unlock on a touchscreen tempts people the other way, toward Something You Have, because it happens on a phone. The phone is the reader, not the factor. The pattern is a remembered shape, and a remembered shape is a password you draw. The Have bin is where the most common mistake in this activity lives. A hardware security key and a PIV or CAC smart card are easy — they are objects, and you can drop them. The trap is the codes. A TOTP code from an authenticator app and an SMS code sent to a registered phone both arrive as digits you read and type, which makes them feel like knowledge. They are not. The code is not the factor; the enrolled device that produced or received it is. A TOTP app holds a seed that was planted at enrolment and derives the digits from that seed and the clock, so the code proves possession of that enrolled app. An SMS code proves control of a registered phone number. This is also why the two are not equally trusted: SMS is the weakest widely deployed second factor, because a SIM swap moves the number to an attacker's phone without ever touching your account. Both are still possession — one is just easier to steal. The Are bin is measurement. A fingerprint, a face, an iris and a voice are all read off the body, and they share a property no other factor has: you cannot change them after a breach. You can rotate a password and re-issue a token, but a leaked fingerprint template is leaked permanently, which is why biometrics are usually paired with another factor rather than trusted alone. Somewhere You Are is the least common of the four and is almost never a primary factor, because location is a weak claim about identity. A GPS check that you are within fifty miles of the office and an IP restriction that only permits logins from the corporate range both describe where the request came from, not who sent it. Anyone standing in the right building or connected to the right VPN satisfies them, and an attacker with stolen credentials and a VPN endpoint satisfies them too. That is why location is used to narrow risk rather than to prove identity — it is a supplemental control layered under real factors, and it is the category most often left out of the list entirely.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →