Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Bill Gates Is Right?
Scott Granneman, 2004-11-19

Bill Gates is right about one thing: asking people to use a two-factor form of authentication would go a long way toward alleviating a lot of the password problems that plague computer security today.

Comments Mode:
Bill Gates Is Right? 2004-11-20
dreamss
Bill Gates Is Right? 2004-11-20
Todd Knarr (1 replies)
Bill Gates Is Right? 2004-11-30
Prasad
Bill Gates Is Right? 2004-11-20
Me
Bill Gates Is Right? 2004-11-20
dfy (1 replies)
Man-in-the-Middle 2004-11-22
Anonymous (2 replies)
Man-in-the-Middle 2004-11-22
Anonymous
Man-in-the-Middle 2004-11-23
David Deaves
Bill Gates Is Right? 2004-11-20
Anonymous
Bill Gates Is Right? 2004-11-20
Anonymous
Bill Gates Is Right? 2004-11-20
Borja Marcos
Bill Gates Is Right? 2004-11-20
Florencio Cano
Yeah he's right, but... 2004-11-21
Roger
Bill Gates Is Right? 2004-11-22
Anonymous
Bill Gates Is Right? 2004-11-22
AR
Bill Gates Is Right? 2004-11-22
Anonymous (1 replies)
Bill Gates Is Right? 2004-11-25
Anonymous
Bill Gates Is Right? 2004-11-22
Dmitriy
Bill Gates Is Right? 2004-11-22
Anonymous
Bill Gates Is Right? NO. 2004-11-22
Anonymous
Granneman is wrong? 2004-11-22
Mene Tekel
Smart cards maybe, but not biometrics 2004-11-22
Nicholas Chase
Bill Gates Is Right? 2004-11-22
Anonymous
Biometrics isn't the best method 2004-11-23
Anonymous
Bill Gates Is Right? 2004-11-23
hanzie
Bill Gates Is Right? 2004-11-23
Jay
Bill Gates Is Right? 2004-11-23
michaels
People being Human 2004-11-23
Dan J.
Bill Gates Is Right? 2004-11-23
Ean Meyer
Bill Gates Is Right? - Open standard doesn't matter 2004-11-23
Paul (1 replies)
Regardless of biometrics etc, we are not talking about a single and secure method to vlidate who a user is, correct?

If so (single authentication method for the world), who will validate me? (using biometrics or whatever) - Is there going to be some central/world server that validates my credentials, and passes a token (or whatever) back to the site that is attempting to validate me saying yes, he is who he says he is? Who owns this central authentication server?. Are we not talking about another form of passport all over again. (Private or open, nobody is going to buy into it)

It doesn't matter if the validation standards used are open. I'm not doing this central authentication method, therefore, my thumb print and Multiple smart cards. Therefore, it doesn't matter if there is an open standard e.g. My Visa smart card and my thumb for Visa payments (using standard X), My IBM smart card and my thumb for IBM.com (using standard Z) etc etc you get the idea...

i.e. Biometrics get's us around remembering multiple passwords - regardless of standards. (the caveat being federation. i.e. IBM trust what Visa says, but IBM ain't gonna trust Oracle, so once again, multiple cards (regardless of startdards))



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/277/29196#29196
Smart-card != SecurID 2004-11-23
Souterrain
I respectfully disagree 2004-11-23
Michael Cloppert
Bill Gates Is Right? 2004-11-25
Anonymous
Bill Gates Is Right? 2004-11-25
Anonymous
Bill Gates Is Right? 2004-11-29
Anonymous
Bill Gates Is Right? 2004-12-01
Anonymous
Bill Gates Is Right? 2006-04-26
M Capp







 

Privacy Statement
Copyright 2009, SecurityFocus