[KDE Dot News]
 faq
 flatforty
 contribute
 subscribe
 configure
 search
 rdf

 main
 parent
 thread


Re: Fingerprint reader integration?
by elsewhere on Monday 18/Feb/2008, @21:20
>>Perhaps the devs don't see it as a must-have feature (since not all computers have embedded sensors). But, to put it on another light: it's not *just* fingerprint readers, but all of the upcoming biometric/smartcard/multi-token security features of which we'll be soon seing a surge, specially in corporate environments.

Well, I've been selling two-factor authentication solutions for almost a decade, mostly RSA's, and I'm still waiting for the surge in corporate environments that everyone has been talking about for years now. Was supposed to happen with the dot-com, then it was supposed to happen with SarBox, and now compliance is the alleged driver. The fish still aren't biting... ;)

Having said that, it would be nice to see KDM have some sort of hook or mechanism for strong-authentication, without having to resort to workarounds. Though I'm not sure there is a standard mechanism for this yet that would allow it to be a simple hook.

>>Also, it'd be nice to have KDM auto-unlock KWallet. Single Sign-on, anyone?

That's not SSO. The point of kwallet is to keep your data secure by requiring authentication even within your user environment, it's a separate mechanism from the PAM authentication that the login requires. If you're not concerned about that, then set your wallet with an empty password, and it will still be restricted to you only.
  Related Links
 ·   Articles on Developer
 ·   Also by elsewhere
 ·   Contact author

Thread Threshold:

The Fine Print: The following comments are owned by whomever posted them.
( Reply )

Re: Fingerprint reader integration?
by Vide on Tuesday 19/Feb/2008, @01:47
"That's not SSO. The point of kwallet is to keep your data secure by requiring authentication even within your user environment, it's a separate mechanism from the PAM authentication that the login requires. If you're not concerned about that, then set your wallet with an empty password, and it will still be restricted to you only."

No, then my data will be stored in clear text, and if my laptop get stolen, we have a problem. And while encripting all the home partition is overkill, having PAM authentication to work with kwallet it's not.
I hope that when Gnome will have it (maybe they already do, don't know) we'll really start to feel how useful this feature is.
[ Reply To This | View ]
  • Re: Fingerprint reader integration?
    by jcs on Thursday 24/Apr/2008, @09:51
    one good solution is to use an encrypted home and login with pam_mount .. then it's fine to leave kwallet sans password since your passwords will still be encrypted on disk, as will your email, im logs, whatever.
    [ Reply To This | View ]

 
The Fine Print: The previous comments are owned by whomever posted them.
( Reply )

  "I tried to play with some toy applications and enjoyed it." -- Werner Trobin
KDE®, "K Desktop Environment", "KDE Dot News", "got the dot?" and the KDE Logo® are trademarks or registered trademarks of KDE e.V. in the European Union, the United States and other countries. All other trademarks and copyrights on this page are owned by their respective owners. Comments are owned by the poster. The rest: Copyright © 2000-2008 KDE e.V. for The KDE Project. For further information or comments on this site, please contact the Webmaster.
[ home | post article | flat forty | subscribe | search | rdf ]