Transmit Security is serving up unbeatable protection – and custom pickleball paddles at RSA 2025. Book a meeting to grab yours and take your security game to the next level!
Glossary
Knowledge-based authentication (KBA) verifies identity by asking questions only the legitimate user should be able to answer: either static questions the user set up, or dynamic questions generated from public and credit records. It’s the "security questions" approach, and it’s steadily being retired as a serious control.
KBA once made sense: ask something personal, and presumably only the real person knows it. The premise has collapsed.
The information KBA depends on is no longer secret. Decades of data breaches, social media oversharing, and data-broker aggregation mean the answers to most KBA questions are findable or purchasable. Attackers researching a target can often answer better than the target remembers. Static answers are guessable and reused across sites; dynamic KBA leans on data that’s been repeatedly breached. It also creates friction and failure for legitimate users who forget their own answers.
Modern identity has largely moved past KBA toward possession- and inherence-based methods (passkeys, biometrics) and, for identity proofing, document and biometric verification with liveness. Where identity needs to be re-established (such as account recovery) the stronger path is verified identity (an ID check plus liveness) rather than trivia an attacker can look up. KBA lingers in call centers and legacy recovery flows, which is precisely where a lot of account takeover now happens.
If KBA is so weak, why is it still everywhere? Inertia and coverage. It requires no app, no device enrollment, and no special hardware. It works for any customer who can answer a question, which makes it a tempting fallback for channels like the call center and for account recovery where stronger factors may not be set up. It’s also deeply embedded in legacy systems and processes that are expensive to change. So it survives not because it’s effective but because it’s convenient and already wired in.
That convenience is exactly what makes it dangerous. Attackers know KBA guards the soft underbelly (recovery flows and phone support) and they arrive armed with the breached and broker-sourced data needed to answer the questions, often better than the real customer can. The modern replacement for KBA in these moments is verified identity: a document-plus-liveness check, or pushing a passkey/biometric confirmation to the customer’s device, rather than trivia an attacker can look up. Closing the KBA gap in recovery and the call center is one of the highest-value moves an institution can make against account takeover.
What does KBA stand for?
Knowledge-based authentication.
Why is KBA considered weak?
The personal information it relies on is widely exposed through breaches, social media, and data brokers.
What replaces KBA?
Possession/inherence factors (passkeys, biometrics) and, for recovery, document-plus-liveness identity verification.
Why is KBA still used if it’s weak?
It needs no app or special hardware and is embedded in legacy call-center and recovery flows, convenient, which is also why attackers target it.
Related: Identity Verification (IDV) · Account Recovery · Account Takeover (ATO) · Biometric Authentication · Call Center / IVR Authentication