You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In 800-63B 5.1.2 "Look-Up Secrets" and 5.1.4 "Single-Factor OTP Device" the possession respectively of a look-up secret authenticator and of an OTP device is proved by the knowledge of a secret that has to be transmitted to the verifier.
The secret may be disclosed to an attacker, which can lure the claimant for example using the technical support scam, see 8.1 "Authenticator Threats".
Conclusion: to prove "something you have" by "something you know" degrades what you have to what you know, or in another words using a look-up secret authenticator or an OTP device does not change the authenticator factor that remains "Something you know", as defined in 800-63-3 4.3.1 "Authenticators".
The text was updated successfully, but these errors were encountered:
In 800-63B 5.1.2 "Look-Up Secrets" and 5.1.4 "Single-Factor OTP Device" the possession respectively of a look-up secret authenticator and of an OTP device is proved by the knowledge of a secret that has to be transmitted to the verifier.
The secret may be disclosed to an attacker, which can lure the claimant for example using the technical support scam, see 8.1 "Authenticator Threats".
Conclusion: to prove "something you have" by "something you know" degrades what you have to what you know, or in another words using a look-up secret authenticator or an OTP device does not change the authenticator factor that remains "Something you know", as defined in 800-63-3 4.3.1 "Authenticators".
The text was updated successfully, but these errors were encountered: