Authenticator
A password, passkey, security key, one-time code or other mechanism used to prove control of an account.
Plain-language definitions of common account, authentication, threat, recovery and security terms.
A password, passkey, security key, one-time code or other mechanism used to prove control of an account.
A single-use recovery code provided when MFA is configured.
Automated attempts to use leaked username-and-password pairs on other services.
A process that transforms readable data into protected form using a key.
A one-way transformation used for tasks such as password verification and integrity checking.
Multi-factor authentication: sign-in using more than one factor or a multi-factor authenticator.
A public-key credential used to sign in without sending a reusable password to the service.
A deceptive attempt to make someone reveal information or approve an action through an impostor message or site.
Malware that disrupts access to data or systems and demands payment or another action.
A phone number, email, trusted device, backup code or process used to regain account access.
A takeover of a phone number by moving it to another SIM or eSIM.
A physical cryptographic authenticator, often using FIDO/WebAuthn standards.
A period during which an account remains signed in after authentication.
Falsifying an identity signal such as a sender address, caller ID or website appearance.
A weakness that could be exploited to affect confidentiality, integrity or availability.
A security approach that avoids assuming trust solely because a user or device is inside a network.