On 27 Mar 2009 at 9:15, John Aldrich  wrote:

> Just personal opinion, but I wouldn't want to trust a proximity card alone
> for logins. Perhaps coupled with some sort of biometric reader to
> authenticate that the person with the card is the actual user, but not
> alone. I've worked for a company which used the cards for physical access to
> the building, and those cards can be problematic -- if they get cracked or
> too close to a strong magnetic field, they are dead.
>
> Not saying not to do it, but keep a good supply of blank cards handy along
> with the badge-making equipment. :-) Just my 2ยข worth.

True two-factor authentication requires something you HAVE and
something you KNOW.  A proximity card should IMHO be coupled with
something you KNOW like a PIN or password.  When coupled with
"something you have", you can relax password-complexity rules
significantly and still stay secure.  Banks have found four-digit PINs
to be "secure enough".

The Yubikey is an interesting device for two-factor authentication.

-- 
Angus Scott-Fleming
GeoApps, Tucson, Arizona
1-520-895-3270

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to