Live data from Hacker News

Intel Security True Key

intel.com

71–80 of 113 posts

Re: Intel Security True Key

#71

This is an adorably bad idea: + As fdik said above, you can't change your fingerprint or face easily, and it's always public + Face recognition and fingerprint scanning are not robust against spoofing — there are known ways to circumvent both + You can be compelled to authenticate a biometric without a warrant Don't use biometrics as a password; use them as a username.

> Don't use biometrics as a password; use them as a username Even then people's faces change and through accidents fingerprints can also be changed / removed and then you're shit out of luck. I'm terrified I would store my important shit in something like that then get into a car accident or something and be no longer able to open it.

Implement it like the Xbox Kinect auto-signin where you still have a username but the camera lets the device figure it out on its own. That way people can still manually enter their username in the event of any disfiguring injury or technical glitches but don't have to normally.

Re: Intel Security True Key

#72

This is an adorably bad idea: + As fdik said above, you can't change your fingerprint or face easily, and it's always public + Face recognition and fingerprint scanning are not robust against spoofing — there are known ways to circumvent both + You can be compelled to authenticate a biometric without a warrant Don't use biometrics as a password; use them as a username.

Indeed, Microsoft (of all companies) had a blog post about this that I came across a while ago that nicely summarizes this.

https://technet.microsoft.com/en-us/library/cc512578.aspx

Re: Intel Security True Key

#73
post #70

This is an adorably bad idea: + As fdik said above, you can't change your fingerprint or face easily, and it's always public + Face recognition and fingerprint scanning are not robust against spoofing — there are known ways to circumvent both + You can be compelled to authenticate a biometric without a warrant Don't use biometrics as a password; use them as a username.

Biometrics are in a really weird place as far as security goes. For the average person who's more concerned about opportunistic theft of a device than a targeted attack I'd argue that biometrics are more secure because you can't have the equivalent of a shitty password. There is no fingerprint equivalent of "1111" as your device PIN. A random pickpocket in the subway doesn't know who you are and thus can't implement…

Your fingerprints are probably all over the device they stole, though.

It's like if you wrapped your laptop in a decorative cover of your password written everywhere.

Similarly, if facial recognition becomes the standard, thieves will just take a snap when they rob you.

Re: Intel Security True Key

#74
post #70

Earlier quoted context omitted.

Biometrics are in a really weird place as far as security goes. For the average person who's more concerned about opportunistic theft of a device than a targeted attack I'd argue that biometrics are more secure because you can't have the equivalent of a shitty password. There is no fingerprint equivalent of "1111" as your device PIN. A random pickpocket in the subway doesn't know who you are and thus can't implement…

Your fingerprints are probably all over the device they stole, though. It's like if you wrapped your laptop in a decorative cover of your password written everywhere. Similarly, if facial recognition becomes the standard, thieves will just take a snap when they rob you.

You average pick-pocket is not going to lift fingerprints of a phone. He will drop the phone in a plastic bag and fence it to someone who can lift the prints or factory reset it without the prints.

Re: Intel Security True Key

#75

Earlier quoted context omitted.

You can use fingerprints as a password. They aren't perfect but in many situations they are fine. Security isn't black and white.

> You can use fingerprints as a password. Provided you have them, medical amputations of limbs is a thing that happens.

Something along these lines was recently in the news: http://usa.chinadaily.com.cn/china/2016-11/22/content_274557...

Re: Intel Security True Key

#76

The truth is that we can't trust INTEL. Their CPU micro-code or ME (Management engine) can and does "phone home" to the internet, grab updates and update the CPU. They don't allow the customer to turn this OFF, which betray's the customer who purchased the CPU. Anyone who can sign the update and intercept the download channel can update your CPU with you having no ability to protect yourself. We can't trust intel. In…

Source on CPU micro-code phoning home?

Re: Intel Security True Key

#77
After reading all the comments there is not one person who is in support for the biometrics as a secure method but I see people being okay with biometric on iPhones by saying apples security better.

Re: Intel Security True Key

#78
post #68

> Intel Security Hmmm... Let's Google that. > Intel Security Group (previously McAfee, Inc. /ˈmækəfiː/[3]) And I'm out of here.

And in honor of the sacred McAfee traditions, Intel Security True Key is bundled by default within the Flash installer; once you've downladed the default installer, you can't even opt out of it. You need to pay attention and unchecked the bundleware before downloading it. Sneaky!

Re: Intel Security True Key

#79
post #74

Earlier quoted context omitted.

Your fingerprints are probably all over the device they stole, though. It's like if you wrapped your laptop in a decorative cover of your password written everywhere. Similarly, if facial recognition becomes the standard, thieves will just take a snap when they rob you.

You average pick-pocket is not going to lift fingerprints of a phone. He will drop the phone in a plastic bag and fence it to someone who can lift the prints or factory reset it without the prints.

And this is better, somehow?

Re: Intel Security True Key

#80

This is an adorably bad idea: + As fdik said above, you can't change your fingerprint or face easily, and it's always public + Face recognition and fingerprint scanning are not robust against spoofing — there are known ways to circumvent both + You can be compelled to authenticate a biometric without a warrant Don't use biometrics as a password; use them as a username.

> Don't use biometrics as a password; use them as a username Even then people's faces change and through accidents fingerprints can also be changed / removed and then you're shit out of luck. I'm terrified I would store my important shit in something like that then get into a car accident or something and be no longer able to open it.

"We couldn't detect your face/fingerprints please enter your username directly instead."

What if you get into a car accident and no longer remember the master password to your hardware password safe?

What if you remember it but lost your arms and are no longer able to type?

The car accident scenario is not very useful.

Post reply on HN