What is a digital identity?
A digital identity is the information a service associates with an account.
Study 3 Identity and Authentication with 12 free online flashcards. Review key terms, definitions, and concepts with this interactive flashcard deck.
What is a digital identity?
A digital identity is the information a service associates with an account.
Does a username prove account ownership?
An identifier names an account, but does not prove that the person presenting it controls that account.
How do authentication and authorization differ?
Authentication checks control of an account’s authenticators; authorization determines what the authenticated account may do.
What are the three common authentication-factor categories?
Something you know, such as a password; something you have, such as a security key; or something you are, such as a fingerprint.
Do two passwords count as multifactor authentication?
No. Both passwords are something you know, so they are the same factor category rather than two distinct factors.
Why should every account have a unique password?
Use a long, unique password for each account. Uniqueness prevents a password exposed at one service from being reused to attack another account.
How can a password manager improve account security?
It can create and store strong, distinct passwords, so you do not need to memorize each one.
What is a passphrase?
A memorable phrase made from several words chosen to be hard to guess; it can be an effective password.
Why are predictable password substitutions weak?
Predictable substitutions add little protection; length and uniqueness matter more than changes such as turning `password` into `Password1!`.
When should a password be changed?
NIST advises against arbitrary periodic changes. Change a password if it may have been exposed or compromised.
What does MFA add to account protection?
MFA requires more than one distinct factor. It makes account takeover harder if one factor is stolen, but does not eliminate every risk.
Which sign-in methods resist many phishing attacks?
Passkeys and security keys use cryptographic authentication bound to the legitimate service, making them resistant to many phishing attacks.