TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Intel Security True Key

63 点作者 Jack5500超过 8 年前

15 条评论

Seylerius超过 8 年前
This is an adorably bad idea:<p>+ As fdik said above, you can&#x27;t change your fingerprint or face easily, and it&#x27;s always public<p>+ Face recognition and fingerprint scanning are not robust against spoofing — there are known ways to circumvent both<p>+ You can be compelled to authenticate a biometric without a warrant<p>Don&#x27;t use biometrics as a password; use them as a username.
评论 #13102026 未加载
评论 #13103613 未加载
评论 #13103643 未加载
评论 #13104543 未加载
moppl超过 8 年前
True Key makes use of the Intel Management Engine (IME). It gives a hint at what Intel is up to with the IME. One of the intended uses is &quot;identity protection&quot;, storing secrets like e.g. biometric data in the realm of the IME, and to ultimately get rid of passwords.<p>Considering the security concerns regarding the IME, I doubt that it is a good idea to hand your passwords over to Intel (ME). At least I don&#x27;t want to support this technology by using apps that utilize the IME.<p>To read up on the IME there is a free book by one of the developers on it...<p><a href="http:&#x2F;&#x2F;link.springer.com&#x2F;book&#x2F;10.1007%2F978-1-4302-6572-6" rel="nofollow">http:&#x2F;&#x2F;link.springer.com&#x2F;book&#x2F;10.1007%2F978-1-4302-6572-6</a><p>Inside is an entire chapter on Intel&#x27;s identity protection.
评论 #13101844 未加载
fdik超过 8 年前
They never seem to understand:<p>Your fingerprint like your face can be the username, but never the password.<p>Your fingerprint is exactly like your username: you cannot change it and you always leave it in public.
评论 #13101839 未加载
评论 #13102329 未加载
评论 #13101680 未加载
HashThis超过 8 年前
The truth is that we can&#x27;t trust INTEL. Their CPU micro-code or ME (Management engine) can and does &quot;phone home&quot; to the internet, grab updates and update the CPU. They don&#x27;t allow the customer to turn this OFF, which betray&#x27;s the customer who purchased the CPU. Anyone who can sign the update and intercept the download channel can update your CPU with you having no ability to protect yourself. We can&#x27;t trust intel.<p>Intel needs to allow 3rd parties to build a small piece of hardware for private key storage, generation, signing and encryption, with self-distruction upon tampering. Then customers need to be able to go to the store, pick which vendor they want, and they plug it into their motherboard. By selling them in the store when the customer can make a surprise purchase, then that prevents tampering upon shipping withe ecommerce deliverables.
评论 #13102079 未加载
评论 #13103834 未加载
评论 #13103779 未加载
daenney超过 8 年前
I&#x27;m rather concerned about the face recognition part and how easily that might be fooled. Has anyone tried that?<p>It&#x27;s an interesting take on a password manager though, I do like the second factor through an additional device before it grants access.
评论 #13101493 未加载
msimpson超过 8 年前
First, it&#x27;s important to realize that biometric identifiers are not constitutionally protected in the United States under the fifth amendment given current legal precedents:<p>&quot;A Virginia Circuit Court judge ruled Tuesday that police officers cannot force criminal suspects to divulge cellphone passwords, but they can force them to unlock the phone with a fingerprint scanner.&quot;<p>Source: <a href="http:&#x2F;&#x2F;blogs.wsj.com&#x2F;digits&#x2F;2014&#x2F;10&#x2F;31&#x2F;judge-rules-suspect-can-be-required-to-unlock-phone-with-fingerprint&#x2F;" rel="nofollow">http:&#x2F;&#x2F;blogs.wsj.com&#x2F;digits&#x2F;2014&#x2F;10&#x2F;31&#x2F;judge-rules-suspect-c...</a><p>Second, as others have already noted, you cannot hide or change most biometric identifiers and some people may not even have them at all. Therefore, passwords will always be the safest, most accessible option. However, more education regarding their creation, use, and support needs to occur:<p>Password Strength: <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;936&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;936&#x2F;</a><p>Password Reuse: <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;792&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;792&#x2F;</a><p>NIST’s new password rules – what you need to know: <a href="https:&#x2F;&#x2F;nakedsecurity.sophos.com&#x2F;2016&#x2F;08&#x2F;18&#x2F;nists-new-password-rules-what-you-need-to-know&#x2F;" rel="nofollow">https:&#x2F;&#x2F;nakedsecurity.sophos.com&#x2F;2016&#x2F;08&#x2F;18&#x2F;nists-new-passwo...</a><p>Personally, I like to choose a small token representing the site or service at hand, then surround it with multiple pass phrases I&#x27;ve memorized over the years. This creates a strong password which is both unique and easy to remember. Not to mention when a site I use is inevitably hacked and my hash is stolen, I only need to update a single instance of this pattern--not reevaluate my entire system.
atemerev超过 8 年前
Nice try, NSA.
quink超过 8 年前
&gt; Intel Security<p>Hmmm... Let&#x27;s Google that.<p>&gt; Intel Security Group (previously McAfee, Inc. &#x2F;ˈmækəfiː&#x2F;[3])<p>And I&#x27;m out of here.
评论 #13103783 未加载
woliveirajr超过 8 年前
Fingerprints can be faked in very ingenious ways. For example, [1] gives &quot;Hacker fakes German minister&#x27;s fingerprints using photos of her hands&quot;.<p>Photos. Not even required to recover the fingerprint from the surface of something. Tell me how secure is that.<p>[1] <a href="https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2014&#x2F;dec&#x2F;30&#x2F;hacker-fakes-german-ministers-fingerprints-using-photos-of-her-hands" rel="nofollow">https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2014&#x2F;dec&#x2F;30&#x2F;hacker-fa...</a>
ForFreedom超过 8 年前
After reading all the comments there is not one person who is in support for the biometrics as a secure method but I see people being okay with biometric on iPhones by saying apples security better.
dfarts超过 8 年前
Fingerprint technology is hackable, easily so.<p>Edit: Face recognition is even easier. Iris scanners are the only sure way to recognize someone.
评论 #13102008 未加载
评论 #13104191 未加载
评论 #13104139 未加载
iou超过 8 年前
My skeptic-sense is tingling!
shshhdhs超过 8 年前
Here is the English landing page on Intel&#x27;s direct site: <a href="http:&#x2F;&#x2F;www.intel.com&#x2F;content&#x2F;www&#x2F;us&#x2F;en&#x2F;architecture-and-technology&#x2F;true-key&#x2F;intel-true-key-technology.html" rel="nofollow">http:&#x2F;&#x2F;www.intel.com&#x2F;content&#x2F;www&#x2F;us&#x2F;en&#x2F;architecture-and-tech...</a>
评论 #13101449 未加载
shock超过 8 年前
Can the mods or OP change the url to the english version? <a href="https:&#x2F;&#x2F;www.truekey.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.truekey.com&#x2F;</a>
评论 #13104891 未加载
评论 #13101907 未加载
评论 #13101416 未加载
robinhoodexe超过 8 年前
&gt;AES-256, one of the strongest encryption algorithms available<p>Hmm... I&#x27;d take 4096-bit GPG over this any day. I rather like using pass[0]<p>[0]<a href="https:&#x2F;&#x2F;www.passwordstore.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.passwordstore.org&#x2F;</a>
评论 #13101548 未加载
评论 #13101476 未加载
评论 #13101549 未加载