0Pricing
OAuth2 & OpenID Connect Deep Dive · Lección

Factores de autenticación y autenticación multifactor

Aprenda las tres categorías de factores de autenticación y cómo combinarlas en una autenticación multifactor mejora drásticamente la seguridad.

Factores de autenticación y autenticación multifactor es una lección gratuita de OAuth2 & OpenID Connect Deep Dive en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de OAuth2 & OpenID Connect Deep Dive, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de OAuth2 & OpenID Connect Deep Dive incluye 4 lecciones en total.

Partes de esta lección aún no han sido traducidas y se muestran en inglés.

Proving Who You Are

Authentication asks "are you really you?" — and answers it by checking authentication factors, pieces of evidence tied to your identity.

Three Factor Categories

Every factor fits one of three categories: something you know, something you have, or something you are.

Something You Know

Knowledge factors are secrets you remember — passwords, PINs, security answers. Cheap, but easily phished, guessed, or reused.

Something You Have

Possession factors are things you hold: a phone getting a code, a hardware key, or an authenticator app spitting out rotating codes like this one.

// TOTP code shown by an authenticator app
// changes every 30 seconds
482913

Something You Are

Inherence factors are biometrics — fingerprint, face, voice. Convenient and hard to share, but you can't change them once compromised.

Single-Factor Weakness

Leaning on a single factor, usually a password, is fragile — one leak hands over full access. Most major breaches trace back to single-factor logins.

What MFA Means

Multi-factor authentication requires factors from two or more different categories. Password plus phone code is MFA; two passwords is not — both are knowledge.

Why MFA Is Stronger

MFA is stronger because an attacker must defeat several independent factors at once — stealing your password and your phone — making remote attacks far harder.

TOTP One-Time Passwords

A TOTP is a common possession factor: the server and app share a secret and both compute the same code, which rotates every 30 seconds.

// pseudo: code = HOTP(secret, floor(time / 30))
String code = totp(secret, System.currentTimeMillis());

Push and Passkeys

Modern logins cut friction with push approvals on a trusted device and passkeys — combining a device (have) with biometrics (are) to resist phishing.

Adaptive Authentication

Adaptive authentication asks for extra factors only when risk spikes — a new device or odd location — balancing security against user convenience.

Quick Check

A login requires a password and a fingerprint. Why does this count as multi-factor?

Recap

Recap: the three factor categories are know, have, and are. Password-only is weak; MFA mixes categories, and TOTP, passkeys, and adaptive auth raise the bar.

Preguntas frecuentes

¿La lección «Factores de autenticación y autenticación multifactor» es gratis?

Sí — el texto completo de «Factores de autenticación y autenticación multifactor» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de OAuth2 & OpenID Connect Deep Dive, actualiza a CoddyKit PRO. El curso de OAuth2 & OpenID Connect Deep Dive incluye 4 lecciones en total.

¿Qué aprenderé en «Factores de autenticación y autenticación multifactor»?

Aprenda las tres categorías de factores de autenticación y cómo combinarlas en una autenticación multifactor mejora drásticamente la seguridad. Practicas OAuth2 & OpenID Connect Deep Dive con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.

¿Necesito experiencia previa para empezar OAuth2 & OpenID Connect Deep Dive?

No se requiere experiencia previa. OAuth2 & OpenID Connect Deep Dive en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.

¿Cuánto tiempo toma la lección «Factores de autenticación y autenticación multifactor»?

La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.

¿Puedo escribir y ejecutar código en esta lección de OAuth2 & OpenID Connect Deep Dive?

Sí. Cada lección de OAuth2 & OpenID Connect Deep Dive incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.

Todas las lecciones de este curso

  1. AuthN frente a AuthZ: explicación
  2. Evolución de la gestión de identidades
  3. Conceptos y terminología básica de seguridad
  4. Factores de autenticación y autenticación multifactor
← Volver a OAuth2 & OpenID Connect Deep Dive