Biometrics are a terrible idea. Password + token is much safer and infinitely revokable. And the server can even tell when an HOTP device has been cloned.
Personally, I think most biometrics are bunk, unless you use multiple (fingerprint, iris, etc) along with some kind of password.
Biometrics are a terrible idea. Password + token is much safer and infinitely revokable. And the server can even tell when an HOTP device has been cloned.