martin wrote:
You lose the security.
.. by storing the required information to logon. right. But we very well watch who & where the information is stored.
In real life, you gain a lot security by requiring both pw and key. For many of our larger partners for example it is quite hard to replace a key without some work (equals money) and implications to the running business. But it is easy to change the password periodically. With this they prevent ex employees that had access to the key to use the system after they had been laid off. And using password only is to unsecure for other partners that have theyr keys stored/accessed in a better way.
On the other hand, on the already secured administrators workstations, it saves a lot time to have the pw and key stored in a saved session.
Or the other line of reasoning: It's a feature. you don't have to use it. You may loose some security, but it's your choice. Other SW offers this too. why not offer it too?
greetings
Beejai