<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Sujoy Gupta]]></title><description><![CDATA[Architecting the Trust & Identity Layer for a Decentralized AGI Economy]]></description><link>https://www.sujoyg.com</link><image><url>https://substackcdn.com/image/fetch/$s_!FBbD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b726cdd-474b-4f92-a755-e61ca66efa97_857x857.jpeg</url><title>Sujoy Gupta</title><link>https://www.sujoyg.com</link></image><generator>Substack</generator><lastBuildDate>Mon, 18 May 2026 04:54:12 GMT</lastBuildDate><atom:link href="https://www.sujoyg.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Sujoy Gupta]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[sujoyg@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[sujoyg@substack.com]]></itunes:email><itunes:name><![CDATA[Sujoy Gupta]]></itunes:name></itunes:owner><itunes:author><![CDATA[Sujoy Gupta]]></itunes:author><googleplay:owner><![CDATA[sujoyg@substack.com]]></googleplay:owner><googleplay:email><![CDATA[sujoyg@substack.com]]></googleplay:email><googleplay:author><![CDATA[Sujoy Gupta]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Move over MFA, come in UHA]]></title><description><![CDATA[We need to stop pretending that standard Multi-Factor Authentication (MFA) is still &#8220;secure&#8221; in the age of AI.]]></description><link>https://www.sujoyg.com/p/move-over-mfa-come-in-uha</link><guid isPermaLink="false">https://www.sujoyg.com/p/move-over-mfa-come-in-uha</guid><dc:creator><![CDATA[Sujoy Gupta]]></dc:creator><pubDate>Fri, 19 Dec 2025 21:17:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tyf_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tyf_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tyf_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png 424w, https://substackcdn.com/image/fetch/$s_!tyf_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png 848w, https://substackcdn.com/image/fetch/$s_!tyf_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!tyf_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tyf_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png" width="1456" height="803" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:803,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5909291,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.sujoyg.com/i/182125299?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tyf_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png 424w, https://substackcdn.com/image/fetch/$s_!tyf_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png 848w, https://substackcdn.com/image/fetch/$s_!tyf_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!tyf_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6d2269-0bce-45d3-bad1-469e0444e794_2784x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We need to stop pretending that standard Multi-Factor Authentication (MFA) is still &#8220;secure&#8221; in the age of AI.</p><p>For the last decade, security architects have relied on the &#8220;Holy Trinity&#8221; of authentication:</p><ol><li><p><strong>Something you know</strong> (passwords)</p></li><li><p><strong>Something you have</strong> (phones/keys)</p></li><li><p><strong>Something you are</strong> (biometrics)</p></li></ol><p>In 2025, this model is fundamentally broken.</p><h2><strong>The Pillars Are Crumbling</strong></h2><p>To understand why we need a new standard, we have to look at how the current pillars are failing under the weight of AI agents and deepfakes:</p><p><strong>Knowledge Factor (Passwords):</strong> Dead on arrival. Most passwords are reused across sites and apps. While browsers now offer inbuilt mechanisms to alert users on compromised passwords, the friction of changing them is so daunting that most people simply don&#8217;t do it.</p><p><strong>Possession Factor (Device/SMS):</strong> SMS is the most common type of MFA today, yet it is susceptible to SIM swaps and phishing. Hardware keys (like YubiKeys) offer phishing resistance by requiring a human presence, but they are physically stealable.</p><p><strong>Inherence Factor (Biometrics):</strong> A person&#8217;s unique biometrics (fingerprints, face) are authenticated against a known fingerprint or face. Therein lies the problem. It requires someone keeping a central database of biometrics to match an authenticating individual. It is a privacy nightmare for users, organizations and regulators.</p><p>The root of trust for most consumer biometrics like FaceID isn&#8217;t your face - it&#8217;s your passcode. If I have your device (&#8221;possession factor&#8221;) and your passcode (&#8221;knowledge factor&#8221;), I can delete your face and enroll my own. The system will then accept <em>my</em> face as <em>yours</em>.</p><h2><strong>UHA: The Final Boss of MFA</strong></h2><p><strong>Unique Human Authentication (UHA)</strong> changes the game. It is person-bound, non-forgeable, and self-custodial.<br><br>UHA can be a <strong>deterministic anchor</strong> for the entire identity stack, potentially replacing the need for multiple weak factors with one gold-standard signal.</p><h4><strong>Non-Transferable Binding</strong></h4><p>Standard biometrics match a face to a device. UHA binds the identity to the unique biological entity using high-entropy iris patterns and hardware attestation. You can reset a password, you can overwrite a local FaceID enrollment, you can even update a biometric database, but you cannot &#8220;reset&#8221; or &#8220;transfer&#8221; your biological singularity.</p><h4><strong>Self-Custodial Privacy</strong></h4><p>Biometric verification creates centralized &#8220;honeypots&#8221; of sensitive data. UHA leverages Zero-Knowledge Proofs (ZKP). Users can prove their identity without ever revealing their raw biometric data to the relying party.</p><h2><strong>The Epitome of Trust</strong></h2><p>By verifying the unique human rather than just existence, UHA is the ultimate security layer for the age of AGI. It is the only signal that AI cannot forge, and it is the necessary evolution for a digital world that wants to remain human-centric.</p><p>The future of trust isn&#8217;t about having a key. <strong>It&#8217;s about being the key with no one else keeping a copy in their lockbox.</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.sujoyg.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Please subscribe to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>