Kaffis Mark V wrote:
Diamondeye wrote:
shuyung wrote:
Two-factor authentication. We've solved this problem, people need to get on board.
If this is the thing you were talking about in the cartoon earlier, that is awesome. Why no one seems to do that is beyond me.
It's not. The thing in the XKCD comic is simply an observation on password strength.
Passwords are still only one authentication factor, no matter how strong they are.
I'm really rather surprised that you're not familiar with 2-factor authentication. I would have thought that it's in common use, if not required, in our military.
Two-factor authentication combines two different types of authentication to help mitigate the risk of any one factor being compromised. The most common implementations of two-factor authentication are cards or dongles issued to individuals plus their password. WoW keychain/phone authenticators are an example.
The easy way to remember authentication types are: Something you
have, Something you
are, and Something you
know.
Ahh, ok. I guess I did know that, it just didn't "click" for some reason. I thought the 4-word password thing was so cool, I guess I just fixated on that.
In that case, yes it actually is in use. You have your ID card which has a chip on it. Then, you put it in a computer slot and type in a PIN. You could even think of it as 3-factor since you have to have a computer with the right kind of slot and the software to make the card work too. It can be installed on a home computer too, which is really handy. My unit administrator can prepare forms I need to sign, e-mail them to me, and then I digitally sign and send them back. It saves me a 45-minute drive to the unit, and her a lot of time.
The card reader itself is a pain, though. You either have to be issued one or special order it; They don't sell them in office supply stores last I checked (and I did actually look for one at one point, because the first one I was issued had all the instructions in German.)