Something you know, something you have, something you are. Google may be trying to prefer something you have, but that's hardly going to kill "something you know" forever and ever. I also look forward to the silly "two-factor authentication" that involves having two "something you have"s. It'll complement my bank's silly use of two "something you know"s nicely. (Perhaps they can get together for the true security ult…
> Something you know, something you have, something you are. Excellent point - and oddly reflects a subtle point: Something you are (bio-id) is what we are asserting, and using one or both of the others to give the far point a guage of how likely fraud is. In short: * Something you are -> Username * Something you know -> Password * Something you have -> RSA fob
So, the "something you are" is still distinct from "who you really are", which is the thing we are trying to establish. (And we should have at least another two or three decades before that becomes a tricky question of its own.)