Factores de autenticación y autenticación multifactor
Aprenda las tres categorías de factores de autenticación y cómo combinarlas en una autenticación multifactor mejora drásticamente la seguridad.
Factores de autenticación y autenticación multifactor es una lección gratuita de OAuth2 & OpenID Connect Deep Dive en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de OAuth2 & OpenID Connect Deep Dive, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de OAuth2 & OpenID Connect Deep Dive incluye 4 lecciones en total.
Partes de esta lección aún no han sido traducidas y se muestran en inglés.
Proving Who You Are
Authentication asks "are you really you?" — and answers it by checking authentication factors, pieces of evidence tied to your identity.
Three Factor Categories
Every factor fits one of three categories: something you know, something you have, or something you are.
Something You Know
Knowledge factors are secrets you remember — passwords, PINs, security answers. Cheap, but easily phished, guessed, or reused.
Something You Have
Possession factors are things you hold: a phone getting a code, a hardware key, or an authenticator app spitting out rotating codes like this one.
// TOTP code shown by an authenticator app
// changes every 30 seconds
482913Something You Are
Inherence factors are biometrics — fingerprint, face, voice. Convenient and hard to share, but you can't change them once compromised.
Single-Factor Weakness
Leaning on a single factor, usually a password, is fragile — one leak hands over full access. Most major breaches trace back to single-factor logins.
What MFA Means
Multi-factor authentication requires factors from two or more different categories. Password plus phone code is MFA; two passwords is not — both are knowledge.
Why MFA Is Stronger
MFA is stronger because an attacker must defeat several independent factors at once — stealing your password and your phone — making remote attacks far harder.
TOTP One-Time Passwords
A TOTP is a common possession factor: the server and app share a secret and both compute the same code, which rotates every 30 seconds.
// pseudo: code = HOTP(secret, floor(time / 30))
String code = totp(secret, System.currentTimeMillis());Push and Passkeys
Modern logins cut friction with push approvals on a trusted device and passkeys — combining a device (have) with biometrics (are) to resist phishing.
Adaptive Authentication
Adaptive authentication asks for extra factors only when risk spikes — a new device or odd location — balancing security against user convenience.
Quick Check
A login requires a password and a fingerprint. Why does this count as multi-factor?
Recap
Recap: the three factor categories are know, have, and are. Password-only is weak; MFA mixes categories, and TOTP, passkeys, and adaptive auth raise the bar.
Preguntas frecuentes
¿La lección «Factores de autenticación y autenticación multifactor» es gratis?
Sí — el texto completo de «Factores de autenticación y autenticación multifactor» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de OAuth2 & OpenID Connect Deep Dive, actualiza a CoddyKit PRO. El curso de OAuth2 & OpenID Connect Deep Dive incluye 4 lecciones en total.
¿Qué aprenderé en «Factores de autenticación y autenticación multifactor»?
Aprenda las tres categorías de factores de autenticación y cómo combinarlas en una autenticación multifactor mejora drásticamente la seguridad. Practicas OAuth2 & OpenID Connect Deep Dive con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.
¿Necesito experiencia previa para empezar OAuth2 & OpenID Connect Deep Dive?
No se requiere experiencia previa. OAuth2 & OpenID Connect Deep Dive en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.
¿Cuánto tiempo toma la lección «Factores de autenticación y autenticación multifactor»?
La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.
¿Puedo escribir y ejecutar código en esta lección de OAuth2 & OpenID Connect Deep Dive?
Sí. Cada lección de OAuth2 & OpenID Connect Deep Dive incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.
Todas las lecciones de este curso
- AuthN frente a AuthZ: explicación
- Evolución de la gestión de identidades
- Conceptos y terminología básica de seguridad
- Factores de autenticación y autenticación multifactor