On Fri, Mar 27, 2009 at 12:01 PM, Angus Scott-Fleming <[email protected]> wrote: > True two-factor authentication requires something you HAVE and > something you KNOW.
Indeed. Credentials can be: - Something you know (e.g., password, PIN, etc.) - Something you have (e.g., key, card, etc.) - Something you are (biometric, e.g., fingerprint, hand geometry) Using only one of those is only one factor. So if one replaces passwords with cards, one still only has single-factor authentication. If one supplements passwords with cards, one has two-factor. I've also heard the list stated as: - Something you can forget - Something you can lose - Something that can change YMMV. :) -- Ben ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
