A Shared Secret is a static word, phrase, or string of characters agreed upon by two parties in order to confirm identity as a form of knowledge-based authentication (KBA).
"Secret questions" commonly seen in two-step authentication, such as "What is your mother's maiden name?" or "What was the name of your first pet?" are also instances of shared secrets frequently used for authentication purposes.
Shared secret authentication is both particularly common and also particularly insecure, as the secrets are static, rather short for very practical reasons, often very easy to either brute force or to guess, and relatively easy to steal or lose, whether through phishing, various forms of snooping or interception, or user carelessness.
Plurilock offers a full line of industry-leading cybersecurity, technology, and services solutions for business and government.
Talk to us today.
Copyright © 2022 Plurilock Security Inc.