On 27 Mar 2009 at 9:15, John Aldrich wrote: > Just personal opinion, but I wouldn't want to trust a proximity card alone > for logins. Perhaps coupled with some sort of biometric reader to > authenticate that the person with the card is the actual user, but not > alone. I've worked for a company which used the cards for physical access to > the building, and those cards can be problematic -- if they get cracked or > too close to a strong magnetic field, they are dead. > > Not saying not to do it, but keep a good supply of blank cards handy along > with the badge-making equipment. :-) Just my 2ยข worth.
True two-factor authentication requires something you HAVE and something you KNOW. A proximity card should IMHO be coupled with something you KNOW like a PIN or password. When coupled with "something you have", you can relax password-complexity rules significantly and still stay secure. Banks have found four-digit PINs to be "secure enough". The Yubikey is an interesting device for two-factor authentication. -- Angus Scott-Fleming GeoApps, Tucson, Arizona 1-520-895-3270 ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
