Live data from Hacker News

Intel Security True Key

intel.com

21–30 of 113 posts

Re: Intel Security True Key

#21
post #15

They never seem to understand: Your fingerprint like your face can be the username, but never the password. Your fingerprint is exactly like your username: you cannot change it and you always leave it in public.

You can use fingerprints as a password. They aren't perfect but in many situations they are fine. Security isn't black and white.

Since you can't change them, long term security is nonexistant.

Re: Intel Security True Key

#22
post #15

They never seem to understand: Your fingerprint like your face can be the username, but never the password. Your fingerprint is exactly like your username: you cannot change it and you always leave it in public.

You can use fingerprints as a password. They aren't perfect but in many situations they are fine. Security isn't black and white.

Providing you have them, I can chop then off and use them.

Seriously, use your eye or fingerprint as a password and there is someone ruthless enough to remove them from your body.

Re: Intel Security True Key

#24
post #7

I'm rather concerned about the face recognition part and how easily that might be fooled. Has anyone tried that? It's an interesting take on a password manager though, I do like the second factor through an additional device before it grants access.

Although not this particular face recognition. I managed to fool face recognition passwords in the past with a simple photograph of the person. As you would expect it works perfectly fine.

This is part of the reason Windows Hello won't use standard webcams for facial recognition. They require a depth camera (very unusual feature on laptops, usually marketed as Intel Real Sense) so that a simple photograph isn't enough to fool the camera.

This is still far from perfect though; a truly determined bad actor could create a passable 3D model, or even a face mask, and probably still fool the sensor. It just takes more work. The whole point of passwords is that no one can know them but the person intending to use them. Using a publicly visible part of my body is just asking for trouble.

Re: Intel Security True Key

#27
post #12

True Key makes use of the Intel Management Engine (IME). It gives a hint at what Intel is up to with the IME. One of the intended uses is "identity protection", storing secrets like e.g. biometric data in the realm of the IME, and to ultimately get rid of passwords. Considering the security concerns regarding the IME, I doubt that it is a good idea to hand your passwords over to Intel (ME). At least I don't want to s…

Interesting that Apple is doing similar things with the embedded ARM stuff in the new touchbar MBPs.

The thing is that Apple actually has a pretty good track record for security and not violating the privacy or integrity of customers' products. I have a lot more trust in Apple doing this correctly. I'd be fine with Intel taking on secure computing, but there's been some pretty bad stuff with the IME (like sending data to the internet outside of user control when using intel NICs), so I'm skeptical of this approach (especially when they're talking about facial recognition as a security measure).

Re: Intel Security True Key

#28
post #27

Earlier quoted context omitted.

Interesting that Apple is doing similar things with the embedded ARM stuff in the new touchbar MBPs.

The thing is that Apple actually has a pretty good track record for security and not violating the privacy or integrity of customers' products. I have a lot more trust in Apple doing this correctly. I'd be fine with Intel taking on secure computing, but there's been some pretty bad stuff with the IME (like sending data to the internet outside of user control when using intel NICs), so I'm skeptical of this approach (…

iTunes

Re: Intel Security True Key

#29
post #15

They never seem to understand: Your fingerprint like your face can be the username, but never the password. Your fingerprint is exactly like your username: you cannot change it and you always leave it in public.

You can use fingerprints as a password. They aren't perfect but in many situations they are fine. Security isn't black and white.

Dear IshKebab,

We at startup xyz take security seriously. We regret to inform you that on the night of 1st December 2016 our database was compromised. The database contained your name, address and fingerprint data.

Please see a plastic surgeon about resetting your fingerprints at as soon as possible.

Thank you, Startup Xyz

Post reply on HN