Tuesday, June 5, 2007

Alternative Authentication Methods

This article is a great primer on non-hardware multifactor authentication - things like face identification rather than passwords, voice pattern recognition, typing pattern recognition, etc.

http://www.networkworld.com/research/2007/060407-multifactor-authentication.html?page=1

While these methods sound innovative and flexible, I remain somewhat skeptical - if someone tries hard enough, there must be a way to spoof a voice or typing pattern, for instance. I don't pretend to know how, but I've got to assume it exists.

For my money, I'd look at these methods as 3rd factor authentication mechanisms, and stick with a solid hardware token - back to the "online ATM card" analogy - as my primary authentication credential.

No comments: