Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Right. There are three types of authentication factors: something you know, something you have, something you are.

Obscurity and passwords fall under "something you know". Biometrics like what you describe would fall under "something you are". A physical key such as a yubikey or the sim card matching an SMS challenge would be "something you have". Multi-factor authentication is more secure but it doesn't negate the discussion here about hardening the "something you know" factor.



What's interesting is that (mostly impractical at the moment) attacks on biometrics authentication mechanisms end up summarizing that category to also "something you have", rather than "something you are" -- not that it negate its particular utility.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: