The life of a secret
The two pages before this one show that authentication is just maths over a secret. Which means the whole game is what happens to that secret from the moment it is created to the moment it is destroyed. This page follows that loop, shows where it gets attacked, what changed now that AI agents hold secrets too, and how a company proves it is handling them properly.
First, what is a secret?
Anything that, if copied, lets someone else be you or your system. The four you met on this site, and the one you meet every day.
Both your phone and the server hold it. Whoever copies it makes valid codes forever. Symmetric: two copies exist by design.
Only your device holds it. The server holds a public key that cannot be used to sign. Asymmetric: one copy exists.
What the server hands you after login. Stealing it skips authentication entirely. This is what most real attacks go after.
A secret used by software, not a person. Today that increasingly means an AI agent. Nobody feels it when it is copied.
One loop, five stages, three points of view
Click a stage. The left lane is how it gets attacked, the middle is what you personally do, the right is what a company must do and be able to prove.