Blog
Introducing TypingDNA Human Likeness – A Novel Bot Detection Approach for the AI Age
For years, customers and partners have asked us whether typing biometrics could help distinguish natural human typing from synthetic or automated input. That question is becoming more important as bots, browser automation, scripted form filling, and AI agents become increasingly capable of interacting with websites and applications in ways that may appear human. We decided…
Finally, a Portable Vault for 2FA, Passwords, and Secure Notes, Secured by TypingDNA
Built for organizations who want a portable phone-free 2FA authenticator and vault for sensitive information, running on Mac, Windows, and Linux. For a long time, there has been a gap between simple authenticator apps and full password managers. One gives you 2FA codes but little else. The other often pushes you toward a cloud vault,…
The Corporate 2FA Blind Spot: What Happens When Phones Are Banned?
Most corporate MFA policies were designed with one assumption baked in: employees have a smartphone. For a significant portion of the workforce, that assumption is wrong – not because of personal preference, but because of company policy. 1. The Industries Where Phones Are Already Banned This is not a hypothetical. Across several major verticals, personal…
Using Windows Hello as 2FA for Microsoft Entra? Here’s the Uncomfortable Truth
This article focuses on Windows Hello for Business as used within Microsoft Entra ID (formerly Azure AD) MFA flows. Many of the same principles apply to other desktop-based authentication methods like Okta Fastpass. 1. Windows Hello Is Not 2FA Windows Hello lets users unlock their Windows device using either a biometric (fingerprint or face recognition)…
YubiKey or Nothing? There’s a Third Option.
Hardware security keys are the gold standard of enterprise 2FA. No serious security professional disputes that. The problem is not the YubiKey’s security properties – it is everything that comes with running them at scale. 1. The Real Cost of Hardware Keys at Scale The operational model for hardware security keys breaks down quickly in…
Beyond Copy Paste: Detecting Retyped AI Answers With Typing Biometrics
AI-generated answers are no longer always copied and pasted. Many applications block paste to prevent users from inserting AI-generated text directly. But users can still read text from ChatGPT or another source on a phone or second screen, then manually retype it into a question box. No paste. No clipboard. No obvious plagiarism trail. The…TypingDNA has been recognized in the Gartner® Hype Cycle™ for Digital Identity
Gartner recognized TypingDNA as a Sample Vendor for the Passive Behavioral Biometrics category in Gartner® Hype Cycle™ for Digital Identity 2025, and Gartner® Hype Cycle™ for Fraud and Financial Crime Prevention 2025. Both reports highlight that passive behavioral analytics is entering the plateau of productivity, which we believe means that the technology is now proven,…
NIST SP 800-63B Rev 4: SMS OTP is Now a Restricted Authenticator, But We Have the Fix
Update, February 4th 2026: TypingDNA SMS+ just released publicly. Check it out! NIST’s updated Digital Identity Guidelines (SP 800-63B-4) formally classify SMS/PSTN one-time passcodes as a restricted authenticator. This is the first time NIST has created an explicit “restricted” category, which comes with new obligations for any organization that continues to use these methods. While…