Re: Fingerprint



"Wim" <Wim@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:0CE09A91-170E-46E5-9020-0229F6B36B6B@xxxxxxxxxxxxxxxx
To increase our system security I woul like to increase the complexity of
our password settings, but I also want to avoid that users start putting
their password on a little peace of paper under their keyboard or in their
drawer.
To avoid this I started thinking about the usage of fingerprint
technology.
I know their are fingerprint systems that can be used for conveniance but
that are not realy secure. Can you recommend me a secure fingerprint
system?

We tried a few of these, and my general feeling is that they all work 90% of
the time, and none of them is well integrated with Remote Desktop. The
first moment a user needs to remotely access another computer, guess what:
they need their post it notes again. As a simple convenience feature for
the local desktop that does get rid of post it notes with passwords for a
limited number of users, they are okay. For a sophisticated intruder, they
are easy to fake out.

The cat's meow for secure passwords is two factor authentication using
tokens that generate pseudo-random numbers, combined with a simple password
your user remembers. We evaluated these recently and selected Cryptocard,
but we have not implemented it yet so I can't recommend it yet. They seem
to have thought about the integration to Active Directory more deeply than
their competitors, and I really like the fact that they don't change the AD
schema.

All of the two factor systems tend to implement as RADIUS servers, so a nice
side effect is you can use them for firewall VPNs, independent of any AD
authentications.

--
Will


.



Relevant Pages

  • But most of all. . .I LIKE THE WAY YOU MOO-OUVE!
    ... experience on OpenVMS and with OpenVMS security that I would tend to ... avoid using UWSS constructs where I can avoid it, ... and to protect and to secure the trusted code behind the memory ...
    (comp.os.vms)
  • Re: Fingerprint
    ... It has a client that allows Remote Desktop integration and has a number of other options available including smart card integration for more secure authentication. ... our password settings, but I also want to avoid that users start putting ... To avoid this I started thinking about the usage of fingerprint technology. ... I know their are fingerprint systems that can be used for conveniance but ...
    (microsoft.public.windows.server.security)
  • Re: SSL web site config
    ... "This page contains both secure ... How do I change config settings in IIS for SSL to avoid ... Do you want to display the nonsecure items?" ...
    (microsoft.public.win2000.security)
  • Re: Stop having to do the authentication check in OS X?
    ... DJW wrote: ... Is there a way that I can avoid the ... Stop modifying system files. ... I have not entered a password for authentication anyway. ...
    (comp.sys.mac.system)
  • Re: KDC Hardware
    ... > so sorry i didn't mean that, i mean to secure not to avoid to secure ... But you should keep the LDAP server safe as well. ... then you can consider your KDC cracked as well. ...
    (comp.protocols.kerberos)