Earlier quoted context omitted.
What are some good resources to learn more about the phone-home functionality in their microcode? I've been trying to find more details and have been unable to do so.
You've been unable to find that information because no such "functionality" exists. Microcode just patches bugs or configuration details of the CPU; it doesn't "phone home".
Intel Security True Key
51–60 of 113 posts
Re: Intel Security True Key
#52Earlier quoted context omitted.
The thing is that Apple actually has a pretty good track record for security and not violating the privacy or integrity of customers' products. I have a lot more trust in Apple doing this correctly. I'd be fine with Intel taking on secure computing, but there's been some pretty bad stuff with the IME (like sending data to the internet outside of user control when using intel NICs), so I'm skeptical of this approach (…
> but there's been some pretty bad stuff with the IME (like sending data to the internet outside of user control when using intel NICs) That's also a typical concern about baseband processors - and Apple has a baseband processor integrated into their iPhones and iPads. OK, there is a difference: While for ethernet ports (and with a little bit more effor WiFi connections) you can at least theoretically analyze whether…
I'm sure if it were up to apple they'd be putting high-level radio functionality in the main CPU. It's cheaper that way, and matches with Apple's security/privacy-oriented marketing.
Re: Intel Security True Key
#53Earlier quoted context omitted.
You can use fingerprints as a password. They aren't perfect but in many situations they are fine. Security isn't black and white.
Dear IshKebab, We at startup xyz take security seriously. We regret to inform you that on the night of 1st December 2016 our database was compromised. The database contained your name, address and fingerprint data. Please see a plastic surgeon about resetting your fingerprints at as soon as possible. Thank you, Startup Xyz
Or think about locking your phone. Most people only want to stop their friends and family - they're not going to copy you fingerprint. Even FBI nearly defeated by TouchID. (You're probably thinking that they could have easily bypassed it, but they only had 48 hours to do so.)
Re: Intel Security True Key
#54They never seem to understand: Your fingerprint like your face can be the username, but never the password. Your fingerprint is exactly like your username: you cannot change it and you always leave it in public.
There is a market for it because the average Joe and Jane are pretty lazy and would rather touch something to unlock it than having to go through the hassle of typing and remembering (forgetting) a password. They probably don't understand the secrutiy implications of it either.
Re: Intel Security True Key
#55Earlier quoted context omitted.
Do you think you could fit drivers for all common ethernet/wifi cards in there and proper TCP/IP implementation? It's below assembly abstraction level.
The ME is basically an independent universal computer in its own right, it comes with its own clock, RAM, CPU etc... It is like a Matryoshka doll sitting inside the Intel CPU of your computer. Therefore, yes, it can contain all of that. For further details see my other two posts.
1. https://en.wikipedia.org/wiki/Intel_Active_Management_Techno...
Re: Intel Security True Key
#56Earlier quoted context omitted.
You've been unable to find that information because no such "functionality" exists. Microcode just patches bugs or configuration details of the CPU; it doesn't "phone home".
How could it possibly patch bugs without phoning home? Are you claiming that it is self modifying code?
The implication the comment I was replying to gave was that the device sent unexpected network traffic back to Intel HQ, with the connotation that it was doing so to leak information about my system.
Re: Intel Security True Key
#57Earlier quoted context omitted.
How could it possibly patch bugs without phoning home? Are you claiming that it is self modifying code?
I wouldn't consider "running an update where it pulls new code" to be "phoning home", any more than my car is "phoning home" when I drive it to the dealership for repairs. The implication the comment I was replying to gave was that the device sent unexpected network traffic back to Intel HQ, with the connotation that it was doing so to leak information about my system.
Re: Intel Security True Key
#58Earlier quoted context omitted.
Who exactly has been storing fingerprints centrally? I know plenty of devices that store them locally, but have not seen one phoning it home.
The EU is planning to. http://europa.eu/rapid/press-release_IP-16-1247_en.htm : "The proposed system stores alphanumeric and biometric data (a combination of four fingerprints and the facial image). [...] The System is composed of a central database connected to national entry points." If/when this comes to be, that database will probably be both well-protected and an incredibly tempting attack target.
*more to the point, the only way I see a government who stores biometric data being an issue WRT security: the government is after you (in which case they're likely getting what they want anyway), or it's a targeted attack from a foreign government (in which case biometric theft is the least of your concerns).
Re: Intel Security True Key
#59Earlier quoted context omitted.
Genuinely surprised to not see this happen yet. I guess it's a good thing Apple and Google are the ones who typically store Fingerprints and not third party apps.
Who exactly has been storing fingerprints centrally? I know plenty of devices that store them locally, but have not seen one phoning it home.