For decades, digital security has rested on a simple, three-pronged triad:
- Something you know – Passwords, PINs
- Something you have – Phone, token, hardware key
- Something you are – Biometrics: face, fingerprint
Layer a second factor on, call it multi-factor authentication (MFA), and you were considered “secure.”
That worked when compute was expensive, attackers were mostly human, and deepfakes were science fiction.
It fails fundamentally in a world where:
- AI can clone your face and voice almost instantly.
- Quantum computing threatens to eventually break today’s public-key cryptography.
- Devices and biometric templates are stolen, copied, and leaked every day.
The old security triad isn’t bending. It’s snapping.
We are not going to fix this with “stronger MFA.” We are missing an entire, necessary fourth factor.
Why the Classic Three Factors Are Failing
Let’s be honest about how fragile our current approach really is.
1. Something You Know – The Quantum-Accelerated Problem
Passwords, PINs, and security questions are already leaky.
- Leakage: Passwords are easy for AI to guess and brute-force at scale. Many of them are already compromised.
- Future Risk: They depend on cryptography for safe storage and transmission. Once quantum attacks mature, a lot of that protection disappears.
The problem isn’t just that passwords are weak. It’s that the thing protecting them is on borrowed time.
2. Something You Have – The Single Point of Failure
Phones, tokens, and hardware keys sound strong, but they all reduce down to a single point of failure in time.
- Theft/Spoofing: Devices can be stolen. SIMs can be swapped. Sessions can be intercepted.
- Impersonation: On a new or compromised device, an attacker can “act like” you long enough to do real damage before you even realize it’s gone.
If the attacker controls the device at the right moment, they are you as far as most systems are concerned.
3. Something You Are – The AI Impersonation Problem
Biometrics offer convenience, but their compromise is permanent.
- Deepfake Vulnerability: State-of-the-art AI can convincingly mimic your face and voice, and many liveness checks are already struggling to keep up.
- Irrecoverable Loss: Face and fingerprint templates are stored somewhere. Once they leak, you can’t rotate your face or your fingerprints like you can a password.
The usual answer is friction: “Just layer them. More factors. More prompts. More checks.”
But all of that is still built around protecting a single moment in time:
- One login
- One code
- One scan
- One tap
If that moment is compromised, everything downstream is compromised.
So instead of asking, “How do we add another moment?” we should be asking:
What can’t be faked, even if an attacker can fake all the moments?
The Missing Factor: Something With a History You Can’t Fake
We don’t need another secret, another device, or another biometric. We need provenance.
A real fourth factor has to look like this:
Something with a verifiable history that cannot be quietly rewritten.
Not just “does this person have the right password or phone today,” but:
- Does this identity have a long, verifiable history?
- Which independent, trusted organizations have vouched for it?
- Is there an auditable, tamper-resistant trail of key rotations, revocations, and approvals?
This is where the technology behind decentralized identity and ledgers finally becomes useful in security—not to store passwords, but to store receipts.
We need append-only records that say things like:
- “This bank verified this human on this date.”
- “This employer linked this account to this person.”
- “This old key was revoked and replaced with this new key on this date.”
An attacker can steal a phone and use a password. They cannot quietly rewrite a historical timeline that multiple independent parties have cryptographically signed.
How a Provenance Identity Could Actually Work
This idea lines up with Self-Sovereign Identity (SSI) concepts. Let’s call the identity on a public ledger JEREMY-123.
1. Bootstrapping: Establishing Root Trust
It starts with a high-trust, real-world verifier (a government ID office, a major bank, etc.):
- They verify me using traditional methods (ID, in-person checks, existing records).
- They publish an immutable, signed statement: “We, BankOfX, assert that JEREMY-123 belongs to this verified person.”
This creates an anchor: a verifiable handle (JEREMY-123), a public key, and a timestamped statement from a real, trusted institution.
2. Accumulating History: Building a Trust Graph
Over time, other organizations add their own signed attestations (verifiable credentials):
- University: “JEREMY-123 completed this degree.”
- A financial provider: “We have an active business relationship with JEREMY-123.”
Now “Jeremy” is no longer just an account. It’s a graph of verified trust.
To claim this identity, a thief would need more than access to a device. They’d have to either steal the keys and somehow invalidate or override the years of accumulated trust from these institutions.
3. Authentication: Replacing Passwords With Proof
When I log into a service:
- The service looks up JEREMY-123 on the ledger and fetches the latest valid public key(s).
- It sends a random challenge.
- My device signs the challenge with the corresponding private key (similar to a Passkey).
- The service verifies the signature against the key bound to JEREMY-123 in the public history.
No password. No one-time SMS code.
The only way an attacker can cryptographically claim to be me is if they control a key that the identity’s history says is valid right now.
4. Recovery and Revocation: Resilience After Theft
If my device is stolen, I can go through a high-friction recovery process and publish a new transaction: “Revoke key A, add key B for JEREMY-123.”
The public record now shows: Old key: invalid. New key: valid. Change: timestamped and signed.
For high-risk actions, you could require:
- Two or three independent keys, or
- Approval from one or more institutions that have already vouched for me.
A thief with one stolen device doesn’t get to be me everywhere, forever.
What Provenance Actually Buys Us
This fourth factor changes the economics of impersonation.
Right now, the Snapshot Model encourages attack:
- Goal: Attackers need to steal data, compromise one channel, or exploit one weak moment.
- AI Threat: AI can fake your voice in a single phone call.
- Quantum Threat: Quantum can crack today’s encryption.
The Provenance / History Model raises the cost and complexity exponentially:
- Goal: Attackers must steal keys and fake an entire historical trail that many independent parties have signed.
- AI Defense: AI cannot rewrite a public, append-only history across independent systems.
- Quantum Defense: Quantum cannot go back in time and silently alter records that everyone already agreed on.
If the old triad is based on a snapshot—something you know / have / are—then the missing fourth pillar is based on a timeline:
Something with a history you can’t fake.
Where This Leaves Us
I don’t believe passwords survive the next decade.
I don’t believe “MFA everywhere” is the final answer.
I don’t believe biometrics alone can stand up to the combined pressure of AI and quantum computing.
If we’re serious about next-generation security, we have to stop patching the old triad and start building around provenance:
- Identities with receipts.
- Histories that can’t be quietly rewritten.
- Trust that is earned over time, not granted in a single login screen.
Because in the world we’re heading into, one uncomfortable truth is starting to emerge: If anyone can fake a moment, the only thing left to trust is history.

Leave a Reply