Live data from Hacker News

Intel Security True Key

intel.com

91–100 of 113 posts

Re: Intel Security True Key

#91
post #87

Earlier quoted context omitted.

Comparable to a social security number, but a SSN which you rubber stamp upon literally everything you touch. I make this analogy to illustrate the ridiculousness of both.

I think it's a good comparison, even if it may not seem quite like it yet because we still don't have that many things for which to use our fingerprints. But soon we will have. All the banks are considering some form of biometric authentication for ATMs, and so on, and this could expand to many other types of services. That means you'll have to scan and store your fingerprint on a range of devices with highly variabl…

> All the banks are considering some form of biometric authentication for ATMs

First I've heard of this. Is this a regional thing or a global trend? Got any sources?

Re: Intel Security True Key

#92
post #83
post #74

Earlier quoted context omitted.

You average pick-pocket is not going to lift fingerprints of a phone. He will drop the phone in a plastic bag and fence it to someone who can lift the prints or factory reset it without the prints.

Can you factory reset an iPhone without the passcode? I thought Activation Lock was supposed to prevent this?

You can wipe without a passcode, but if the user turned on Find My iPhone before the phone was wiped, the phone will be a brick until one logs into the associated iCloud account.

Re: Intel Security True Key

#93
post #25

Fingerprint technology is hackable, easily so. Edit: Face recognition is even easier. Iris scanners are the only sure way to recognize someone.

> Iris scanners […]

Iris scanners for authentication kind of lost their appeal to me after watching Demolition Man.

Re: Intel Security True Key

#94
post #47

Earlier quoted context omitted.

ME does have ability to do that, tho.

Just like IPMI, or any other standard for allowing hardware-level admin of a system.

By using the word 'standard' you're trying to legitimize something that's fully encrypted, impossible to code-audit and fully under control of Intel, while pretending to be your property and controlled by you.

So yes, it's a standard. I believe there was also a standard on how to tie a noose for hanging a human, but that didn't mean much to the one getting hanged.

Re: Intel Security True Key

#95
post #69

Earlier quoted context omitted.

Obviously fingerprints can't be used in that situation, buy think about something like your front door lock. You don't need paranoia-level security (you probably have breakable windows anyway) but you want to stop random people who aren't motivated enough to steal your fingerprint from walking in. Or think about locking your phone. Most people only want to stop their friends and family - they're not going to copy you…

I don't understand the qualifier "in that situation": the user cannot determine what the "situation" may be at some point in the future. I do use the fingerprint reader on my iPhone, and I believe that the fingerprint data is never sent to another device. Ever. There are real problems to using the iPhone fingerprint with apps, in that the apps tells me it needs to store an encrypted version of my password on iCloud i…

In the situation where a website stores your fingerprint.

Re: Intel Security True Key

#96
post #2

Can the mods or OP change the url to the english version? https://www.truekey.com/

The owner of this website (www.truekey.com) has banned the country or region your IP address is in (BY) from accessing this website. Awesome.

Strangely - Tor may work. I connected via a Brazillian VPN (from Australia) and got a Cloudflare challenge.

Re: Intel Security True Key

#97

This is an adorably bad idea: + As fdik said above, you can't change your fingerprint or face easily, and it's always public + Face recognition and fingerprint scanning are not robust against spoofing — there are known ways to circumvent both + You can be compelled to authenticate a biometric without a warrant Don't use biometrics as a password; use them as a username.

Fingerprint and face recognition don't have the same threat models. And two differ from password too. For end users, fingerprint makes sense:

- Stealing fingerprint requires access to your fingerprint in the first place. That narrows down the attack surface A LOT. - Coercing someone to authenticate is possible for password too. Unlike fingerprints passwords can be stolen remotely. - People tend to use same PIN everywhere. Therefore "can't change your biometric info" isn't that big of a problem. Fingerprints aren't prone to dictionary attack either because there are no "common fingerprints".

Face recognition can be bypassed more easily thanks to a huge database of faces called facebook.

But we shouldn't reject a security solution outright before properly analyzing the threat model. They all can have their legitimate use cases for certain scenarios.

Re: Intel Security True Key

#98
post #71

Earlier quoted context omitted.

> Don't use biometrics as a password; use them as a username Even then people's faces change and through accidents fingerprints can also be changed / removed and then you're shit out of luck. I'm terrified I would store my important shit in something like that then get into a car accident or something and be no longer able to open it.

Implement it like the Xbox Kinect auto-signin where you still have a username but the camera lets the device figure it out on its own. That way people can still manually enter their username in the event of any disfiguring injury or technical glitches but don't have to normally.

Right but the post I was responding to said to use biometrics as the username hence my comment. You're suggesting using it as a type of password :)

Re: Intel Security True Key

#99
post #42
post #27

Earlier quoted context omitted.

The thing is that Apple actually has a pretty good track record for security and not violating the privacy or integrity of customers' products. I have a lot more trust in Apple doing this correctly. I'd be fine with Intel taking on secure computing, but there's been some pretty bad stuff with the IME (like sending data to the internet outside of user control when using intel NICs), so I'm skeptical of this approach (…

Just to give an idea of how bad the stuff is with the IME, I recommend reading up Chapter 4 here: Intel x86 considered harmful by Joanna Rutkowska https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf The IME is basically a second computer inside your computer, running as the most privileged component on the platform. It has privileged access to all components of the system, and runs as long as the computer is…

Even if I would not consider "... considered harmful" essays as screamers for attention, I would still take detraction about ME with a grain of salt, because:

* it's easy to counteract, just not use an Intel NIC * it gets a lot of scrutinity * Intel is quite open about what it does, short of releasing signing keys for the firmware * the mobile platforms have similar secure enclaves (think baseband processors on phones), which nobody actually audits

All of these make me think Rutkowska found out that bashing x86 gets her attention, and now she uses it as a beating horse.

Re: Intel Security True Key

#100
post #97

This is an adorably bad idea: + As fdik said above, you can't change your fingerprint or face easily, and it's always public + Face recognition and fingerprint scanning are not robust against spoofing — there are known ways to circumvent both + You can be compelled to authenticate a biometric without a warrant Don't use biometrics as a password; use them as a username.

Fingerprint and face recognition don't have the same threat models. And two differ from password too. For end users, fingerprint makes sense: - Stealing fingerprint requires access to your fingerprint in the first place. That narrows down the attack surface A LOT. - Coercing someone to authenticate is possible for password too. Unlike fingerprints passwords can be stolen remotely. - People tend to use same PIN everyw…

> Stealing fingerprint requires access to your fingerprint in the first place.

This is not as difficult as some might think. We leave them all over our devices for example, but physical access is not even necessary. Jan Krissler managed to get the fingerprint of the German defense minister 2 years ago using only photos of her.

Post reply on HN