faq
flatforty
contribute
subscribe
configure
search
rdf
main
parent
thread
|
Re: Fingerprint reader integration?
by elsewhere on Monday 18/Feb/2008, @21:20
|
>>Perhaps the devs don't see it as a must-have feature (since not all computers have embedded sensors). But, to put it on another light: it's not *just* fingerprint readers, but all of the upcoming biometric/smartcard/multi-token security features of which we'll be soon seing a surge, specially in corporate environments.
Well, I've been selling two-factor authentication solutions for almost a decade, mostly RSA's, and I'm still waiting for the surge in corporate environments that everyone has been talking about for years now. Was supposed to happen with the dot-com, then it was supposed to happen with SarBox, and now compliance is the alleged driver. The fish still aren't biting... ;)
Having said that, it would be nice to see KDM have some sort of hook or mechanism for strong-authentication, without having to resort to workarounds. Though I'm not sure there is a standard mechanism for this yet that would allow it to be a simple hook.
>>Also, it'd be nice to have KDM auto-unlock KWallet. Single Sign-on, anyone?
That's not SSO. The point of kwallet is to keep your data secure by requiring authentication even within your user environment, it's a separate mechanism from the PAM authentication that the login requires. If you're not concerned about that, then set your wallet with an empty password, and it will still be restricted to you only. |
|
|
The Fine Print: The following comments
are owned by whomever posted them.
( Reply )
|
Re: Fingerprint reader integration?
by Vide on Tuesday 19/Feb/2008, @01:47
|
"That's not SSO. The point of kwallet is to keep your data secure by requiring authentication even within your user environment, it's a separate mechanism from the PAM authentication that the login requires. If you're not concerned about that, then set your wallet with an empty password, and it will still be restricted to you only."
No, then my data will be stored in clear text, and if my laptop get stolen, we have a problem. And while encripting all the home partition is overkill, having PAM authentication to work with kwallet it's not.
I hope that when Gnome will have it (maybe they already do, don't know) we'll really start to feel how useful this feature is.
|
[
Reply To This | View ]
|
Re: Fingerprint reader integration?
by jcs on Thursday 24/Apr/2008, @09:51
|
one good solution is to use an encrypted home and login with pam_mount .. then it's fine to leave kwallet sans password since your passwords will still be encrypted on disk, as will your email, im logs, whatever.
|
[
Reply To This | View ]
|
|
The Fine Print: The previous
comments are owned by whomever posted them.
( Reply )
|
|