Live data from Hacker News

Intel Security True Key

intel.com

101–110 of 113 posts

Re: Intel Security True Key

#101
post #43
post #38

Earlier quoted context omitted.

What are some good resources to learn more about the phone-home functionality in their microcode? I've been trying to find more details and have been unable to do so.

You've been unable to find that information because no such "functionality" exists. Microcode just patches bugs or configuration details of the CPU; it doesn't "phone home".

A more subtle way to communicate with the mother ship would be to ship an update that makes the CPU leak some desired information. For example change how some specific cryptographic operation works under certain conditions to make it possible for eavesdropper to break the encryption. Or just make some funny things with memory and make certain information available to be retrieved via web browser when user visits malicious page.

Re: Intel Security True Key

#102
Fingerprints can be faked in very ingenious ways. For example, [1] gives "Hacker fakes German minister's fingerprints using photos of her hands".

Photos. Not even required to recover the fingerprint from the surface of something. Tell me how secure is that.

[1] https://www.theguardian.com/technology/2014/dec/30/hacker-fa...

Re: Intel Security True Key

#103
post #2

Can the mods or OP change the url to the english version? https://www.truekey.com/

I was just going to say the same. The intel.com page does not have pricing information and just states that it's free for up to 15 passwords, whereas the True Key site [1] provides pricing information ($19.99 a year for unlimited passwords) and also has links to the mobile apps.

[1]: https://www.truekey.com/

Re: Intel Security True Key

#104
post #84
post #79

Earlier quoted context omitted.

And this is better, somehow?

Depends if it reduces theft.

I think post Activation Lock and similar features on smartphone platforms, thieves usually sell stolen devices to those who rip them apart to get to specific parts that they can resell. That will continue until the phone makers figure out how to disable the display, digitizer, battery and other parts that have value even in a "bricked" phone.

Re: Intel Security True Key

#105
post #71

Earlier quoted context omitted.

Implement it like the Xbox Kinect auto-signin where you still have a username but the camera lets the device figure it out on its own. That way people can still manually enter their username in the event of any disfiguring injury or technical glitches but don't have to normally.

Right but the post I was responding to said to use biometrics as the username hence my comment. You're suggesting using it as a type of password :)

No I'm not, I'm suggesting it be used to identify the user, then they can enter their password the same as always.

Re: Intel Security True Key

#106
post #42
post #27

Earlier quoted context omitted.

The thing is that Apple actually has a pretty good track record for security and not violating the privacy or integrity of customers' products. I have a lot more trust in Apple doing this correctly. I'd be fine with Intel taking on secure computing, but there's been some pretty bad stuff with the IME (like sending data to the internet outside of user control when using intel NICs), so I'm skeptical of this approach (…

Just to give an idea of how bad the stuff is with the IME, I recommend reading up Chapter 4 here: Intel x86 considered harmful by Joanna Rutkowska https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf The IME is basically a second computer inside your computer, running as the most privileged component on the platform. It has privileged access to all components of the system, and runs as long as the computer is…

We need a "Rutkowska Hand-Waving Considered Harmful".

This paper is a bunch of insinuation. It goes into great dramatic length to describe how Intel ME is more evil than AMT/vPro, which runs in the same service processor context, but then selectively uses the features of AMT and attributes them to ME. If we were talking about servers, this paper would be talking about how the service processors on HP servers could be used to build a "bad iLO" that phoned home or allowed unauthorized parties to access.

Intel devices aren't "phoning home". These claims require evidence... I don't see a network capture. Activated AMT implementations will phone back to your home, and allow things like remote control, remote bricking, or remote repair of management software.

Saying that ME is "an ideal rootkiting infrastructure" is a statement without a lot of meaning. You could make the same statement about Windows, Linux or any number of components in a modern computer.

Re: Intel Security True Key

#107
post #70

This is an adorably bad idea: + As fdik said above, you can't change your fingerprint or face easily, and it's always public + Face recognition and fingerprint scanning are not robust against spoofing — there are known ways to circumvent both + You can be compelled to authenticate a biometric without a warrant Don't use biometrics as a password; use them as a username.

Biometrics are in a really weird place as far as security goes. For the average person who's more concerned about opportunistic theft of a device than a targeted attack I'd argue that biometrics are more secure because you can't have the equivalent of a shitty password. There is no fingerprint equivalent of "1111" as your device PIN. A random pickpocket in the subway doesn't know who you are and thus can't implement…

What's your point? If a random pick-pocketer steals a phone from me, they don't care about accessing my data. If they wanted to, it's easier with face/fingerprint recognition. Just grab my picture from facebook/twitter/find me by email or phone number, fingerprints are on my phone, batter, sim card, screen... everywhere. It's slightly more expensive than printing my picture from facebook but many times proven, doable. On the other hand... how can you guess my pattern lock or SHITYPassword1111?

If I'm a victim of a targetted attack, better not to have a phone at all.

Re: Intel Security True Key

#108
post #92
post #83

Earlier quoted context omitted.

Can you factory reset an iPhone without the passcode? I thought Activation Lock was supposed to prevent this?

You can wipe without a passcode, but if the user turned on Find My iPhone before the phone was wiped, the phone will be a brick until one logs into the associated iCloud account.

Probably worth more as parts to a more shady repair shop. Last I heard, a shiny new laptop's only worth a couple hundred when fenced.

Re: Intel Security True Key

#109

Earlier quoted context omitted.

The owner of this website (www.truekey.com) has banned the country or region your IP address is in (BY) from accessing this website. Awesome.

Strangely - Tor may work. I connected via a Brazillian VPN (from Australia) and got a Cloudflare challenge.

I don't see why I'd want to use a service that bans my country from even accessing their website.

Re: Intel Security True Key

#110

Earlier quoted context omitted.

The owner of this website (www.truekey.com) has banned the country or region your IP address is in (BY) from accessing this website. Awesome.

Strangely - Tor may work. I connected via a Brazillian VPN (from Australia) and got a Cloudflare challenge.

I don't see why I'd want to use a service that bans my country from even accessing their website.
Post reply on HN