Forum Discussion

Raghav_205317's avatar
Raghav_205317
Icon for Nimbostratus rankNimbostratus
Jan 07, 2016

Biometric authentication

I have a requirement for a two factor authentication for SSL VPN users. first one being LDAP and second one being biometric using thumb / finger scan.

 

Please share your experience for such a solution.

 

Thanks, Raghav

 

2 Replies

  • Hamish's avatar
    Hamish
    Icon for Cirrocumulus rankCirrocumulus

    Yes.

     

    Biometrics don't (currently) work reliably. Especially thumb/finger scanning. Way too easy to fake. Way too easy for people to get thoroughly annoyed when it doesn't work for them because they're sweaty, been working and scuffed their fingertips, swimming, cleaning, having a bath... etc etc..

     

    There are numerous sites round showing how to fake fingerprints just with a copy from a glass and a bit of gelatin (or PVA etc). Or if it's really important some bloke loses his finger (That was a real one IIRC from back in the early 2000's).

     

    On the other hand, I have implemented situations where two authentications are required. e.g. 2 factor secureID PLUS password... That's supported OOTB by the BigIP APM login pages.

     

    H