Most everyone is familiar with Elon Musk and SpaceX. Elon used first design principles to reimagine the space rocket industry. Breaking down the basic components of a rocket and designing a practical reusable version resulted in a revolutionary way to transport humans and supplies into space.
When I look at the most used multi-factor authentication (MFA) process, which is password plus SMS OTP, I can use a first principles approach to diagram something that is easier for the end user and much more secure. Now before I start tearing down what has become somewhat of an institutional process, let’s look at how password plus SMS OTP got started and why it worked.
Authentication started with username and password, and this is the first type of authentication – something a user knows. When applications that require a user to authenticate moved to the internet, bad actors quickly came up with methods to acquire these passwords. Hacking into corporate networks and stealing passwords from the central database using sophisticated techniques was one method. Another was to use software viruses whose sole job was to install a keystroke logger, which would replicate on the internet and find their way to a person’s personal computer. Eventually, rather than try to find someone skilled to write these sophisticated software programs, an easier way to get the password was to just ask the user for it. By creating fake websites and programs that the user thought was legitimate, bad actors could obtain the passwords faster.
Thus, the password method needed something else. In the corporate world, companies bought hardware devices that generated a one-time a visible numeric passcode (OTP), usually 6-8 digits. The OTP was only valid for that session for a limited time – usually less than 3 minutes and the user would quickly enter the OTP right after the password. Because the user had to be in possession of the special hardware device that generated valid OTP’s, this was labeled as a second type of authentication - something a user has. The downside of this method was that it was expensive to implement and cost prohibitive for anyone but high-level corporate access or users of high value goods and services such as banking and investments.
As mobile phones became common, SMS delivery offered an alternative to dedicated OTP hardware. Both approaches can represent possession of an authenticator; entering the displayed code does not reclassify them as knowledge factors. Their risks differ: SMS delivery adds telephone-network and SIM-swap exposure, while a manually entered OTP from either source can still be relayed by phishing.
A password combined with a possession-based OTP can be MFA and can improve on a password alone. The fake-login scenario remains relevant because an attacker can request and relay both values. Effective MFA needs distinct factors, not necessarily all three factor types; phishing resistance depends on how authentication is bound to the intended service.
For this first-principles redesign, keep the web or application dialogue and the person’s mobile device, but remove the need to copy an SMS code. The design question is how an enrolled app can connect the expected service, device possession and the person’s approval using distinct factors and an understandable request.
The username tells the application which account is being requested; it does not supply a knowledge factor. An enrolled smartphone app can prove possession of its authenticator, while local biometrics can activate it as a second factor. App-store installation or secure hardware alone does not prove enrollment, key protection or that the person intended this request.
PasswordFree® applies this redesign through an enrolled-device approval experience instead of a password and copied SMS code. Full Duplex Authentication® adds the established service relationship to that flow. Users already accustomed to checking a phone can transition to approving a contextual request, with enrollment and recovery planned explicitly; the username is not counted as a third factor.

