As a cherry on top you can put the password in LDAP or RADIUS server and hook up traditional 2FA (Google Auth, Yubikey, Email, SMS) for that legendary 3FA (ah... "something (else) you have"). Sounds hokey, but defense is best in depth.
As a cherry on top you can put the password in LDAP or RADIUS server and hook up traditional 2FA (Google Auth, Yubikey, Email, SMS) for that legendary 3FA (ah... "something (else) you have"). Sounds hokey, but defense is best in depth.
3 FA is :
* Something you have (normally one OR MORE user IDs)
* Something you know (normally the associated password or passwords for the user ID(s))
* Something you are (normally biometric)
[edit: technically, it's multi-factor when using multiple user/passwords - here's a useful link https://pciguru.wordpress.com/2010/05/01/one-two-and-three-f...]
You have your fingers. You have your eyes.
In fiction and movies, these things that you have which could be taken from you (your fingers severed, your eyes plucked out) and used for getting past biometric scanners.
In real life there are easier, stealthier, and less gruesome methods for getting those things: just copy them. (gummy bear fingerprints, anyone? [1][2][3])
[1] - http://www.theregister.co.uk/2002/05/16/gummi_bears_defeat_f...
[2] - http://www.cryptome.org/gummy.htm
[3] - http://www.it.slashdot.org/story/10/10/28/0124242/aussie-kid...
I think biometrics may have a place in tamper-proof devices like iphones (infamous error 53) or biometric smartcards (need fingerprint to unlock secrets).