Live data from Hacker News

Intel Security True Key

intel.com

81–90 of 113 posts

Re: Intel Security True Key

#81
post #70

Earlier quoted context omitted.

Biometrics are in a really weird place as far as security goes. For the average person who's more concerned about opportunistic theft of a device than a targeted attack I'd argue that biometrics are more secure because you can't have the equivalent of a shitty password. There is no fingerprint equivalent of "1111" as your device PIN. A random pickpocket in the subway doesn't know who you are and thus can't implement…

Your fingerprints are probably all over the device they stole, though. It's like if you wrapped your laptop in a decorative cover of your password written everywhere. Similarly, if facial recognition becomes the standard, thieves will just take a snap when they rob you.

> Your fingerprints are probably all over the device they stole, though

Including very likely the fingerprint scanner itself.

Re: Intel Security True Key

#82

The truth is that we can't trust INTEL. Their CPU micro-code or ME (Management engine) can and does "phone home" to the internet, grab updates and update the CPU. They don't allow the customer to turn this OFF, which betray's the customer who purchased the CPU. Anyone who can sign the update and intercept the download channel can update your CPU with you having no ability to protect yourself. We can't trust intel. In…

> Anyone who can sign the update and intercept the download channel can update your CPU with you having no ability to protect yourself. We can't trust intel.

Intel's microcode updates are cryptographically signed; the CPU will not accept an update without Intel's signature. The format is not publicly documented, but independent research [1] suggests that it's 2048-bit RSA.

[1]: http://inertiawar.com/microcode/

Re: Intel Security True Key

#83
post #74

Earlier quoted context omitted.

Your fingerprints are probably all over the device they stole, though. It's like if you wrapped your laptop in a decorative cover of your password written everywhere. Similarly, if facial recognition becomes the standard, thieves will just take a snap when they rob you.

You average pick-pocket is not going to lift fingerprints of a phone. He will drop the phone in a plastic bag and fence it to someone who can lift the prints or factory reset it without the prints.

Can you factory reset an iPhone without the passcode? I thought Activation Lock was supposed to prevent this?

Re: Intel Security True Key

#84
post #79
post #74

Earlier quoted context omitted.

You average pick-pocket is not going to lift fingerprints of a phone. He will drop the phone in a plastic bag and fence it to someone who can lift the prints or factory reset it without the prints.

And this is better, somehow?

Depends if it reduces theft.

Re: Intel Security True Key

#85
post #48

Earlier quoted context omitted.

ME does have ability to do that, tho.

Do you think you could fit drivers for all common ethernet/wifi cards in there and proper TCP/IP implementation? It's below assembly abstraction level.

How else would you implement remote server management that works even when the hardware is shut down (put still connected to power) if not with a seperate CPU that has access to the NIC?

Re: Intel Security True Key

#86
post #68

> Intel Security Hmmm... Let's Google that. > Intel Security Group (previously McAfee, Inc. /ˈmækəfiː/[3]) And I'm out of here.

And in honor of the sacred McAfee traditions, Intel Security True Key is bundled by default within the Flash installer; once you've downladed the default installer, you can't even opt out of it. You need to pay attention and unchecked the bundleware before downloading it. Sneaky!

Also worth saying is that if True Key is installed via Flash Mcafee bundle you can't actually uninstall it, you have to manually remove the service and delete the files/reg keys.

Re: Intel Security True Key

#87
post #15

They never seem to understand: Your fingerprint like your face can be the username, but never the password. Your fingerprint is exactly like your username: you cannot change it and you always leave it in public.

Comparable to a social security number, but a SSN which you rubber stamp upon literally everything you touch. I make this analogy to illustrate the ridiculousness of both.

I think it's a good comparison, even if it may not seem quite like it yet because we still don't have that many things for which to use our fingerprints.

But soon we will have. All the banks are considering some form of biometric authentication for ATMs, and so on, and this could expand to many other types of services. That means you'll have to scan and store your fingerprint on a range of devices with highly variable security. Eventually your fingerprint will be sold on the black market, just like your SSN is.

Re: Intel Security True Key

#88

The truth is that we can't trust INTEL. Their CPU micro-code or ME (Management engine) can and does "phone home" to the internet, grab updates and update the CPU. They don't allow the customer to turn this OFF, which betray's the customer who purchased the CPU. Anyone who can sign the update and intercept the download channel can update your CPU with you having no ability to protect yourself. We can't trust intel. In…

> Anyone who can sign the update and intercept the download channel can update your CPU with you having no ability to protect yourself. We can't trust intel. Intel's microcode updates are cryptographically signed; the CPU will not accept an update without Intel's signature. The format is not publicly documented, but independent research [1] suggests that it's 2048-bit RSA. [1]: http://inertiawar.com/microcode/

The nice thing about that is the Intel and NSA could just share that key and everyone would be none the wiser.

Re: Intel Security True Key

#89

Earlier quoted context omitted.

> Don't use biometrics as a password; use them as a username Even then people's faces change and through accidents fingerprints can also be changed / removed and then you're shit out of luck. I'm terrified I would store my important shit in something like that then get into a car accident or something and be no longer able to open it.

"We couldn't detect your face/fingerprints please enter your username directly instead." What if you get into a car accident and no longer remember the master password to your hardware password safe? What if you remember it but lost your arms and are no longer able to type? The car accident scenario is not very useful.

You can write down your master password somewhere, or share it with a loved one. This is no different from having backups for important data. You can't easily backup your iris, face, or fingerprints.

Re: Intel Security True Key

#90
post #25

Fingerprint technology is hackable, easily so. Edit: Face recognition is even easier. Iris scanners are the only sure way to recognize someone.

This relies on all iris scanners everywhere not being hotwired to feed them a saved iris scan.
Post reply on HN