<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Blog Posts From  Tagged With security</title>
    <link>http://communities.intel.com/community/vproexpert/blog</link>
    <description />
    <pubDate>Wed, 10 Apr 2013 15:20:32 GMT</pubDate>
    <generator>Jive SBS 5.0.2.0  (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2013-04-10T15:20:32Z</dc:date>
    <item>
      <title>REGISTER NOW FOR TODAY'S EVENT! Deploying Windows* 8 and Touch in the Enterprise</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2013/04/10/register-now-for-todays-event-deploying-windows-8-and-touch-in-the-enterprise</link>
      <description>&lt;!-- [DocumentBodyStart:88f4ceca-3000-4a19-bf14-d780a7a87ae7] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; font-size: 12pt; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'MS Mincho'; mso-ascii-theme-font: major-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: JA; mso-bidi-language: AR-SA;"&gt;Intel IT is fully engaged in the process of integrating Windows* 8 into the corporate environment now that the new OS is running on thousands of business Ultrabooks, other mobile devices, and desktop PCs at Intel. &lt;a class="jive-link-external-small" href="http://intelitcenterwebinars.adobeconnect.com/touch/event/registration.html?campaign-id=fbvpro" target="_blank"&gt;&lt;strong&gt;Checkout today's live webinar&lt;/strong&gt; &lt;/a&gt;where Intel experts Tiffany Pany and David Scheer will share their team&amp;#8217;s insights and experiences on integrating Windows* 8. &lt;strong&gt;&lt;a class="jive-link-external-small" href="http://intelitcenterwebinars.adobeconnect.com/touch/event/registration.html?campaign-id=fbvpro" target="_blank"&gt;Register now&lt;/a&gt;&lt;/strong&gt;! &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:88f4ceca-3000-4a19-bf14-d780a7a87ae7] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">client_management</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">activation</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">microsoft</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">windows</category>
      <pubDate>Wed, 10 Apr 2013 15:20:32 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2013/04/10/register-now-for-todays-event-deploying-windows-8-and-touch-in-the-enterprise</guid>
      <dc:date>2013-04-10T15:20:32Z</dc:date>
      <clearspace:dateToText>2 months, 1 week ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/register-now-for-todays-event-deploying-windows-8-and-touch-in-the-enterprise</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15778</wfw:commentRss>
    </item>
    <item>
      <title>Protecting your Digital Identify Using IPT-PKI</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/11/27/protecting-your-digital-identify-using-ipt-pki</link>
      <description>&lt;!-- [DocumentBodyStart:136186d0-fe99-4408-aaf4-7d722b623b23] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;Currently, the most common way people verify their digital identity is by using a password. Exceptions often times are found with online banking, where most use a second factor for authentication (e.g. OTP token or even a confirmation code sent to mobile phone), that is costly or inconvenient for user experience, but due to the weakness of password&amp;nbsp; versus value at risk, this kind of approach is accepted and the costs justify the investment. However it is not reality for the vast majority of digital services. Passwords are used to sign in to your PC, webmail, social network, and lots of other places. There is a &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://research.microsoft.com/apps/pubs/?id=74164" target="_blank"&gt;&lt;span style="font-family: 'Tahoma','sans-serif';"&gt;research&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt; conducted by &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://research.microsoft.com/en-us/" target="_blank"&gt;&lt;span style="font-family: 'Tahoma','sans-serif';"&gt;Microsoft Research&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt; conducted with half million PC users showing that the average person typically has about 25 online accounts.Are you an average user? In fact, the data also shows that the number of unique passwords across those 25 accounts is only about 6, so around 4 passwords are reused across accounts. This is in addition to the tendency of websites to increase password complexities such as mixing lower case with upper case, special characters and numbers. Password reuse probably will increase among websites and cases&amp;nbsp; like those described by &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/" target="_blank"&gt;&lt;span style="font-family: 'Tahoma','sans-serif';"&gt;Mat Honan&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt; (&lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.wired.com/" target="_blank"&gt;&lt;span style="font-family: 'Tahoma','sans-serif';"&gt;Wired&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt; writer) will become even more frequent.&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;Dealing with username and password leads to a set of interesting challenges. We all want the web to be easy and safe. However, having to remember a dozen of complex passwords generally isn&amp;#8217;t easy, and is even harder for websites accessed less frequently. However, using the same easy-to-remember password across multiple sites isn&amp;#8217;t safe. The ideal solution here involves somehow finding a way to make it both easy and safe to use all of your different digital identities.&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;As I already explained in this &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.informationweek.com/security/storage/managing-identity-effectively-in-the-clo/231903463" target="_blank"&gt;&lt;span style="font-family: 'Tahoma','sans-serif';"&gt;post&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt; in InformationWeek, on how to effectively managing identity in the cloud, I introduced &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/architecture-and-technology/identity-protection/identity-protection-technology-general.html" target="_blank"&gt;&lt;span style="font-family: 'Tahoma','sans-serif';"&gt;Intel Identity Protection Technology&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt; and described about strategies adopted by online banking to increase security and how One Time Password (aka. OTP) as second factor authentication can be used to increase security. However, all these approaches, even those more sophisticated, are based on symmetric key and thereby not resistant against an active man-in-the-middle attack (e.g. phishing).&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;One alternative is public/private key pairs, i.e. based on &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://en.wikipedia.org/wiki/Public-key_infrastructure" target="_blank"&gt;&lt;span style="font-family: 'Tahoma','sans-serif';"&gt;Public Key Infrastructure&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt; (aka. PKI) &amp;#8211; these are the most commonly used methods for protecting network traffic on the Internet today. PKI is based on an asymmetric key &amp;#8211; the private key and the public key are different, so the public key should become public in a way proving that it belongs to user and not someone else. Also, the private key must be stored securely where only the user has access. With this method, the website sends a sign-in request to be signed by user&amp;#8217;s private key and sent back to website that uses the user&amp;#8217;s public key to confirm the user has a private key. So long as the private key is not compromised, this system is resistant against phishing and keylogging attacks. However this method is not widely used on the Internet today due to the high costs associated with having dedicated hardware to protect the private key such as Smart Cards and other associated logistics.&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="color: black; font-family: 'Tahoma','sans-serif';"&gt;&lt;strong&gt;Intel IPT-PKI architecture&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;Intel Identity Protection Technology (aka. &lt;a class="jive-link-external-small" href="http://ipt.intel.com/Home.aspx" target="_blank"&gt;Intel IPT&lt;/a&gt;) with PKI uses the Intel Management Engine (aka. Intel ME) and 3rd generation Intel Core vPro processor based systems to provide a hardware-based security solution similar to that of other hardware security modules like Smart Cards. Unlike most hardware security modules, Intel IPT-PKI is designed to be managed as software but hardware resistant against tampering.&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;The hardware based security is achieved by using the Intel ME to perform all cryptographic operations. This way, the keys are never exposed to software running on the computer&amp;#8217;s central processing unit (CPU). Furthermore, all certificates are tied to the platform on which they are created.&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: center;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15537-230620/IPT-PKI+diagram.png"&gt;&lt;img alt="IPT-PKI diagram.png" class="jive-image-thumbnail jive-image" height="363" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15537-230620/290-363/IPT-PKI+diagram.png" width="290"/&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: center;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;As you can see in this diagram, so long as the ME is part of chipset and tied with PC, the user&amp;#8217;s PC becomes part of authentication process. Intel IPT-PKI as showed exposes his capabilities as a Cryptographic Service Provides (CSP) via Microsoft CryptoAPI software layer. IPT-PKI can be used to:&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style="list-style-type: disc;"&gt;&lt;li&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;Generate a persistent RSA key pair in hardware;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;Generate PKI certificates, that can be used to identify user possession and password knowledge;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;Perform operation with RSA private key;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;And protect key usage with PIN&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;Intel IPT-PKI can be used to enhance user identity on several applications such as SSL web site authentication, &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://en.wikipedia.org/wiki/S/MIME" target="_blank"&gt;&lt;span style="font-family: 'Tahoma','sans-serif';"&gt;S/MIME&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt; with Microsoft Exchange Server/Outlook client or VPN authentication.&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;In order to avoid operating system attacks keylogging user&amp;#8217;s PIN and replaying automatically this PIN in a &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://en.wikipedia.org/wiki/Man-in-the-browser" target="_blank"&gt;&lt;span style="font-family: 'Tahoma','sans-serif';"&gt;MiTB&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt; attack, a second IPT building block, Intel IPT Protected Transaction Display (aka. IPT PDT) can be used to create a secure channel between user&amp;#8217;s interfaces. (I.e. keyboard, mouse and video, in order that operation system is not able to hook, as I explained in this Brazilian bank case in a previous &lt;/span&gt;&lt;a class="jive-link-blog-small" data-containerId="1001" data-containerType="37" data-objectId="15208" data-objectType="38" href="http://communities.intel.com/community/vproexpert/blog/2012/05/22/protected-transaction-display-in-online-banking"&gt;&lt;span style="font-family: 'Tahoma','sans-serif';"&gt;post&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;.)&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;If you are looking on how to start using IPT-PKI and IPT-PDT, there is an excellent &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://ipt.intel.com/Libraries/Documents/Intel_R_IPT_with_PKI_UCRD_v10.sflb.ashx" target="_blank"&gt;&lt;span style="font-family: 'Tahoma','sans-serif';"&gt;Use Case Reference Design&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt; that explains majority of scenarios and how to configure. The only requirement from client side is a Intel vPro machine with 3&lt;sup&gt;rd&lt;/sup&gt; Core generation and Windows operating system homologated for this particular machine.&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;Best Regards!&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:136186d0-fe99-4408-aaf4-7d722b623b23] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">pki</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">ipt</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">identity_protection_technology</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">bruno_domingues</category>
      <pubDate>Tue, 27 Nov 2012 14:24:37 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/11/27/protecting-your-digital-identify-using-ipt-pki</guid>
      <dc:date>2012-11-27T14:24:37Z</dc:date>
      <clearspace:dateToText>6 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/protecting-your-digital-identify-using-ipt-pki</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15537</wfw:commentRss>
    </item>
    <item>
      <title>Taking Control of Security: Key Log and Pin Pad Screen Scraping</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/10/05/taking-control-of-security-key-log-and-pin-pad-screen-scraping</link>
      <description>&lt;!-- [DocumentBodyStart:07bf437c-46f0-4374-9e7d-62a7febe5803] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Manage vulnerability with Intel&amp;reg; vPro&amp;#8482; technology built-in security features and McAfee software for multilayered protection against stealth attacks. Take a look at the video below to learn more about the combination protection offered by Intel hardware and McAfee software.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;em style="font-size: 12pt;"&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/enterprise-security/vulnerability-management-animation.html" target="_blank"&gt;Taking Control of Security: Key Log and Pin Pad Screen Scraping&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:07bf437c-46f0-4374-9e7d-62a7febe5803] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">mcafee</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">deep_command</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">stealthy_threats</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">deep_defender</category>
      <pubDate>Fri, 05 Oct 2012 21:24:45 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/10/05/taking-control-of-security-key-log-and-pin-pad-screen-scraping</guid>
      <dc:date>2012-10-05T21:24:45Z</dc:date>
      <clearspace:dateToText>8 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/taking-control-of-security-key-log-and-pin-pad-screen-scraping</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15416</wfw:commentRss>
    </item>
    <item>
      <title>SecureDisable* based on Intel® Anti-Theft Technology addresses the data encryption vulnerability in S3 state</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/10/04/securedisable-based-on-intel-anti-theft-technology-addresses-the-data-encryption-vulnerability-in-s3-state</link>
      <description>&lt;!-- [DocumentBodyStart:9f124e09-22ca-45c6-9d15-ea0de396665c] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="color: #333333;"&gt;The advantages of using encryption to protect data are well known. Typically all full disk encryption solutions require users to authenticate in a pre-boot environment (PBA &amp;#8211; Pre-Boot Authentication). After the successful authentication, the encryption keys are unlocked and disk is unencrypted. The machine then goes on to boot the OS and require users to authenticate in Windows* by providing login/password credentials.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #333333;"&gt;In our fast paced lives, we all hate the inconvenience of first entering the encryption credentials in PBA then Windows credentials at Windows login screen. Few may realize that while it&amp;#8217;s inconvenient to enter credentials in PBA, it&amp;#8217;s an important step in ensuring security of the data on a laptop. When a laptop is starting up (from shutdown state) or resuming from hibernation state (hibernation state &amp;#8211; memory contents are dumped to a hibernation file on the disk), user is asked to authenticate in PBA. If the laptop is resuming from the sleep state (also known as S3 state), the user doesn&amp;#8217;t have to go through the authentication step in PBA. In S3 state, the memory of the laptop is still active. OS, Applications, data including the encryption keys are loaded in the memory. That&amp;#8217;s where the vulnerability creeps in.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #333333;"&gt;In a typical usage scenario, a user just close the lid of the laptop after work, let the laptop go to sleep state, open the lid and resume quickly when need to work again. It sounds convenient but is data secure while the laptop is in sleep state? As I mentioned above, the memory is still active in the sleep state and encryption keys are in the memory. If a laptop is stolen while in sleep state, the data on the laptop is susceptible to breach.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #333333;"&gt;Intel&amp;reg; Anti-Theft Technology (Intel&amp;reg; AT) addresses this vulnerability and allows IT administrator to strike a balance between convenience and security. Intel AT includes a hardware based S3 timer which kicks-in as a laptop enters the S3 state and transition the laptop to hibernation state after the expiry. The timer value is defined by an IT administrator. It allows users to keep their laptop in sleep state for quick resume say, when moving between meetings, but it secures the data when the laptop has been in sleep state for longer duration. Since the timer is implemented in hardware and value defined by IT administrator, users won&amp;#8217;t be able to sacrifice security over convenience.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #333333;"&gt;SecureDisable* is an Intel AT solution offered by Softex Inc. The SecureDisable solution offers the asset and data protection features of Intel AT and it also provides other capabilities such as seamless plug-ins to existing enterprise IT consoles (Microsoft SCCM* and BMC Remedy*) for easier deployment and management, flexible service delivery model allowing enterprises to host the solution themselves, service providers (ITOs/MSPs) to host it either as standalone service or part of security service portfolio, or the service to be hosted in cloud. &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #333333;"&gt;SecureDisable release 2.5 is now available and contains the following new features -&lt;/span&gt;&lt;/p&gt;&lt;ul style="list-style-type: disc;"&gt;&lt;li&gt;&lt;span style="color: #333333;"&gt;Support for 3&lt;sup&gt;rd &lt;/sup&gt;Generation Intel&amp;reg; Core&amp;#8482; and Intel Core&amp;#8482; vPro&amp;#8482; Processors&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #333333;"&gt;Close the data encryption vulnerability in S3 state. If Windows* login is not completed before S3 timer expires, the laptop will gracefully enter S4 (hibernate) state. When resuming from S4, the users will be asked to provide encryption passphrase credential in PBA.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #333333;"&gt;Enhanced multi-tenancy support for ITO hosted anti-theft service. A new user class for help-desk has been created that can be attached and thus gain administrative rights to multiple hosted organizations.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #333333;"&gt;License management features - ability to allocate licenses on a per-organization level, and license tracking.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #333333;"&gt;Various UI and usability changes in the administrative web pages.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #333333;"&gt; Visit &amp;#8211; &lt;span style="color: #333333;"&gt;&lt;a class="jive-link-external-small" href="http://antitheft.intel.com/" target="_blank"&gt;Laptop Security with Intel&amp;reg; Anti-Theft Technology&lt;/a&gt; &lt;/span&gt;for more information on Intel AT&lt;span style="color: #333333;"&gt; or visit &lt;a class="jive-link-external-small" href="http://www.softexinc.com/" target="_blank"&gt;http://www.softexinc.com/&lt;/a&gt; &lt;/span&gt;for more information on SecureDisable&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:9f124e09-22ca-45c6-9d15-ea0de396665c] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">anti-theft</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intel_at</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">antitheft</category>
      <pubDate>Thu, 04 Oct 2012 14:10:21 GMT</pubDate>
      <author>nikhil.jain@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/10/04/securedisable-based-on-intel-anti-theft-technology-addresses-the-data-encryption-vulnerability-in-s3-state</guid>
      <dc:date>2012-10-04T14:10:21Z</dc:date>
      <clearspace:dateToText>8 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/securedisable-based-on-intel-anti-theft-technology-addresses-the-data-encryption-vulnerability-in-s3-state</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15409</wfw:commentRss>
    </item>
    <item>
      <title>McAfee® ePolicy Orchestrator™ Deep Command™ - How it Works Video</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/09/28/mcafee-epolicy-orchestrator-deep-command--how-it-works-video</link>
      <description>&lt;!-- [DocumentBodyStart:598d971c-27e2-415f-b9d5-40ad9824fa58] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;McAfee&amp;reg; ePolicy Orchestrator&amp;#8482; Deep Command&amp;#8482; employs Intel&amp;reg; vPro&amp;reg; Active Management Technology for automated, beyond the operating system management.&amp;nbsp; ePO Deep Command helps organizations using Intel&amp;reg; vPro&amp;reg; to get more value out of the features of Intel&amp;reg; vPro&amp;reg; by allowing access to PCs whehter powered off or disabled. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This animation will show how this offers benefits IT to help reduce operational costs, enhancing security and compliance and enabling &amp;#8220;green&amp;#8217;&amp;rdquo; practices for idle PCs. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Click here to view the animation: &lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/enterprise-security/core-vpro-mcafee-epo-deep-command-video.html\&amp;quot; data-mce-href=" target="_blank"&gt;http://www.intel.com/content/www/us/en/enterprise-security/core-vpro-mcafee-epo-deep-command-video.html&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Check out this blog on McAfee's site about the new features in the latest version of ePO Deep Command: &lt;strong&gt;&lt;a class="jive-link-external-small" href="http://blogs.mcafee.com/security-connected/get-the-most-out-of-your-intel-vpro-based-pcs-with-mcafee-epo-deep-command" target="_blank"&gt;Get The Most Out Of Your Intel vPro-based PCs With McAfee ePO Deep Command&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:598d971c-27e2-415f-b9d5-40ad9824fa58] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">management</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">command</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">mcafee</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">epo</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">secuirty</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">deep</category>
      <pubDate>Fri, 28 Sep 2012 14:10:21 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/09/28/mcafee-epolicy-orchestrator-deep-command--how-it-works-video</guid>
      <dc:date>2012-09-28T14:10:21Z</dc:date>
      <clearspace:dateToText>8 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/mcafee-epolicy-orchestrator-deep-command--how-it-works-video</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15380</wfw:commentRss>
    </item>
    <item>
      <title>McAfee Whitepapers Illustrate Need for Deeper Security</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/08/22/mcafee-whitepapers-illustrate-need-for-deeper-security</link>
      <description>&lt;!-- [DocumentBodyStart:ce627cfd-6d65-4ff7-8d47-88b671025b43] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;McAfee and Intel are working to transform the security industry by combining the power of hardware and software to create more sophisticated ways to help prevent attacks and better protect every segment across the compute continuum. The combination of McAfee and Intel brings fresh innovation to secure the future of computing and the Internet.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Today's threat landscape requires a deeper level of security to protect and stop the advanced threats that are being created on a daily basis.&amp;nbsp; From industrial based attacks to hackavism to embedded based threats, you must be vigilant in deploying a security strategy that is broad and comprehensive.&amp;nbsp; Check out these updated whitepapers describing the need for a deeper level of security to protect against these advanced threats. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;The New Reality of Stealth Crimeware Whitepaper&lt;/strong&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: blue; font-size: 8pt; text-decoration: underline; font-family: 'Tahoma','sans-serif';"&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/enterprise-security/new-reality-of-stealth-crimeware-paper.html" target="_blank"&gt;http://www.intel.com/content/www/us/en/enterprise-security/new-reality-of-stealth-crimeware-paper.html&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;2012 Threats Predictions&lt;/strong&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: blue; font-size: 8pt; text-decoration: underline; font-family: 'Tahoma','sans-serif';"&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/enterprise-security/mcafee-2012-stealth-threats-predictions-paper.html" target="_blank"&gt;http://www.intel.com/content/www/us/en/enterprise-security/mcafee-2012-stealth-threats-predictions-paper.html&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;McAfee ePO Deep Command Technology Blueprint - No Sleep for Security&lt;/strong&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: blue; font-size: 8pt; text-decoration: underline; font-family: 'Tahoma','sans-serif';"&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/enterprise-security/vpro-mcafee-epo-deep-command-no-sleep-for-security-brief.html" target="_blank"&gt;http://www.intel.com/content/www/us/en/enterprise-security/vpro-mcafee-epo-deep-command-no-sleep-for-security-brief.html&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Technical White Paper: McAfee&amp;nbsp; Deep Defender&lt;ul&gt;&lt;li&gt;&lt;span style="color: blue; font-size: 8pt; text-decoration: underline; font-family: 'Tahoma','sans-serif';"&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/enterprise-security/mcafee-deep-defender-deepsafe-rootkit-protection-paper.html" target="_blank"&gt;http://www.intel.com/content/www/us/en/enterprise-security/mcafee-deep-defender-deepsafe-rootkit-protection-paper.html&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:ce627cfd-6d65-4ff7-8d47-88b671025b43] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security_technology</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">mcafee_security_solutions</category>
      <pubDate>Wed, 22 Aug 2012 17:03:46 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/08/22/mcafee-whitepapers-illustrate-need-for-deeper-security</guid>
      <dc:date>2012-08-22T17:03:46Z</dc:date>
      <clearspace:dateToText>10 months, 23 hours ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/mcafee-whitepapers-illustrate-need-for-deeper-security</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15312</wfw:commentRss>
    </item>
    <item>
      <title>McAfee ePO Deep Command Demo Video</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/08/16/mcafee-epo-deep-command-demo-video</link>
      <description>&lt;!-- [DocumentBodyStart:ec3136b1-ae13-4936-a361-4f60b7a6ed3f] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black; font-size: 9pt;"&gt;You might have heard of McAfee ePO Deep Command and how it enables McAfee customers using Intel vPro based PCs to manage security remotely at the hardware level.&amp;nbsp; Utilizing Intel vPro Active Management (AMT) to take control or access vPro based PCs will enable customers to more efficiently and cost effectively manage security on PCs in their environment.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black; font-size: 9pt;"&gt;This &lt;/span&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black; font-size: 9pt;"&gt;in-depth video examineshow McAfee ePO Deep Command uses the Intel vPro technology to provide security management beyond the OS.&amp;nbsp; This video will drill into the popular use cases of McAfee ePO Deep Command, such as deploying security ahead of an attack, remote remediation and wake and patch.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black; font-size: 9pt;"&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/enterprise-security/mcafee-epo-deep-command-use-case-video.html" target="_blank"&gt;http://www.intel.com/content/www/us/en/enterprise-security/mcafee-epo-deep-command-use-case-video.html&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'Tahoma','sans-serif'; color: black; font-size: 9pt;"&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15311-229874/DC+Video.jpg"&gt;&lt;img alt="DC Video.jpg" class="jive-image-thumbnail jive-image" height="453" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15311-229874/620-453/DC+Video.jpg" width="620"/&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:ec3136b1-ae13-4936-a361-4f60b7a6ed3f] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security_management</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">mcafee</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">epo</category>
      <pubDate>Thu, 16 Aug 2012 14:00:58 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/08/16/mcafee-epo-deep-command-demo-video</guid>
      <dc:date>2012-08-16T14:00:58Z</dc:date>
      <clearspace:dateToText>10 months, 1 week ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/mcafee-epo-deep-command-demo-video</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15311</wfw:commentRss>
    </item>
    <item>
      <title>Take user-authentication to the next level.</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/07/10/take-user-authentication-to-the-next-level</link>
      <description>&lt;!-- [DocumentBodyStart:b3425505-478c-416b-a1f3-507f00d3b28e] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Today's hackers have moved well beyond the viruses and Trojan horses that attack at the operating system level. Recent rootkit attacks and other new techniques have suddenly made tokens and smart cards insufficient at blocking unauthorized access to the client's IT system. This has become a critical issue as remote users and cloud computing are becoming commonplace. So how can you combat these cutting-edge hackers? &lt;br/&gt;&lt;br/&gt;Amy Doescher, Enterprise Security Product Marketing Engineer at Intel, and Marty Jost, senior manager of product marketing at Symantec, will explain how you can take authentication to the next level. Register for our webinar to learn how embedded, hardware-based authentication solutions can help you:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Fend off attacks that circumvent traditional software-only-based security measures.&lt;/li&gt;&lt;li&gt;Step up authentication with embedded hardware-based storage of authentication tokens and certificates.&lt;/li&gt;&lt;li&gt;Prevent screen scraping and other malware attacks by verifying a human presence at the PC.&lt;/li&gt;&lt;li&gt;Reduce costs associated with lost smart cards or tokens, and minimize IT staff time associated with traditional token and smart card provisioning.&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Marty and Amy will also discuss how our new solutions can assist you in disaster recovery scenarios. They'll even be answering questions live, so be sure to bring a question or two to ask. It's a great chance to get answers directly from industry experts on IT security.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Intel IT Center Talk to an Expert webinar series&lt;br/&gt;IT Security and Cost Control without Compromise: A Fresh Look at Authentication&lt;br/&gt;Thursday, July 19, 2012&lt;br/&gt;9 a.m. Pacific Daylight Time &lt;br/&gt;&lt;span style="font-family: verdana,geneva; color: #58595b;"&gt;&lt;br/&gt;&lt;span style="font-size: 14pt;"&gt;&lt;strong&gt;&lt;a class="jive-link-external-small" href="http://www.brighttalk.com/r/khC" target="_blank"&gt;Register now &amp;gt;&lt;/a&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:b3425505-478c-416b-a1f3-507f00d3b28e] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">webinar</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">hacker</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">user_authentication</category>
      <pubDate>Tue, 10 Jul 2012 14:03:46 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/07/10/take-user-authentication-to-the-next-level</guid>
      <dc:date>2012-07-10T14:03:46Z</dc:date>
      <clearspace:dateToText>11 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/take-user-authentication-to-the-next-level</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15262</wfw:commentRss>
    </item>
    <item>
      <title>Take user-authentication to the next level!</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/07/02/take-user-authentication-to-the-next-evel</link>
      <description>&lt;!-- [DocumentBodyStart:ffd5959a-6840-4777-b87e-136ab21ba07e] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Today's hackers have moved well beyond the viruses and Trojan horses that attack at the operating system level. Recent rootkit attacks and other new techniques have suddenly made tokens and smart cards insufficient at blocking unauthorized access to the client's IT system. This has become a critical issue as remote users and cloud computing are becoming commonplace. So how can you combat these cutting-edge hackers? &lt;br/&gt; &lt;br/&gt; Amy Doescher, Enterprise Security Product Marketing Engineer at Intel, and Marty Jost, senior manager of product marketing at Symantec, will explain how you can take authentication to the next level. Register for our webinar to learn how embedded, hardware-based authentication solutions can help you:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Fend off attacks that circumvent traditional software-only-based security measures.&lt;/li&gt;&lt;li&gt;Step up authentication with embedded hardware-based storage of authentication tokens and certificates.&lt;/li&gt;&lt;li&gt;Prevent screen scraping and other malware attacks by verifying a human presence at the PC.&lt;/li&gt;&lt;li&gt;Reduce costs associated with lost smart cards or tokens, and minimize IT staff time associated with traditional token and smart card provisioning.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp; Marty and Amy will also discuss how our new solutions can assist you in disaster recovery scenarios. &lt;br/&gt; &lt;br/&gt; They'll even be answering questions live, so be sure to bring a question or two to ask. It's a great chance to get answers directly from industry experts on IT security. L&lt;br/&gt; &lt;br/&gt; Intel IT Center Talk to an Expert webinar series&lt;br/&gt; IT Security and Cost Control without Compromise: A Fresh Look at Authentication&lt;br/&gt; Thursday, July 19, 2012&lt;br/&gt; 9 a.m. Pacific Daylight Time &lt;br/&gt; &lt;br/&gt;&lt;span style="font-size: 14pt;"&gt; &lt;a class="jive-link-external-small" href="http://www.brighttalk.com/r/khC" target="_blank"&gt;Register now &amp;gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:ffd5959a-6840-4777-b87e-136ab21ba07e] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">webinar</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">hackers</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intelit</category>
      <pubDate>Mon, 02 Jul 2012 14:03:46 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/07/02/take-user-authentication-to-the-next-evel</guid>
      <dc:date>2012-07-02T14:03:46Z</dc:date>
      <clearspace:dateToText>11 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/take-user-authentication-to-the-next-evel</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15258</wfw:commentRss>
    </item>
    <item>
      <title>Remotely unlock McAfee encrypted drives using Intel AMT</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/06/15/remotely-unlock-mcafee-encrypted-drives-using-intel-amt</link>
      <description>&lt;!-- [DocumentBodyStart:9151e04e-5df4-4da8-b2be-60e3035cd537] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Are you using McAfee Endpoint Encryption for PC (EEPC) today?&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Then you are very familiar with the following screen (For those who are not - this is the default McAfee EEPC preboot authentication screen that occurs at system start-up before the host operating system loads)&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15235-229263/McAfeePBA.png"&gt;&lt;img alt="McAfeePBA.png" class="jive-image" height="385" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15235-229263/515-385/McAfeePBA.png" width="515"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Later this year, McAfee EEPC v7 will be released.&amp;nbsp;&amp;nbsp; In connection with McAfee ePO Deep Command and Intel AMT, you will have the ability of remote unlock, reset passwords, and set location based unlock policies.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To put that in context - you can power\patch systems with a real-time secure unlock of the pre-boot environment without using the EEPC bypass feature of old.&amp;nbsp;&amp;nbsp; (For those who are wondering - the bypass feature refers to a policy\setting that MUST be applied when the system is on\operational and policies synchronized.&amp;nbsp;&amp;nbsp;&amp;nbsp; What if the system is already off and you need to perform a power\patch immediately?&amp;nbsp;&amp;nbsp; This is where the remote unlock feature is very much needed... and will soon be available &lt;img height="16px" src="http://communities.intel.com/5.0.2/images/emoticons/wink.gif" width="16px"/&gt;)&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;If you are not already familiar with McAfee ePO Deep Command, please see &lt;a class="jive-link-external-small" href="http://www.mcafee.com/deepcommand" target="_blank"&gt;http://www.mcafee.com/deepcommand&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp; This product includes a gateway\proxy service to connect to Intel AMT over the internet.&amp;nbsp;&amp;nbsp; Overlay the upcoming McAfee EEPC v7 and yes - you also will have the ability to unlock or password reset encrypted drives both inside and outside your enterprise &lt;img height="16px" src="http://communities.intel.com/5.0.2/images/emoticons/cool.gif" width="16px"/&gt;)&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Like to see and read more?&amp;nbsp; Check out &lt;a class="jive-link-external-small" href="https://community.mcafee.com/docs/DOC-3921" target="_blank"&gt;https://community.mcafee.com/docs/DOC-3921&lt;/a&gt;.&amp;nbsp;&amp;nbsp; Be sure to view the two demonstration videos at that link.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;One last item - what if you are using a different Intel AMT capable solution for daily Life-Cycle Management of the systems?&amp;nbsp;&amp;nbsp; If the Intel AMT configuration is compatible with McAfee ePO Deep Command, you have the ability to power-on via that non-McAfee solution and still have the secure remote unlock capabilities of McAfee.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:9151e04e-5df4-4da8-b2be-60e3035cd537] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intel_amt</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">mcafee</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">mcafee_security_solutions</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">mcafee_epo</category>
      <pubDate>Fri, 15 Jun 2012 15:00:44 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/06/15/remotely-unlock-mcafee-encrypted-drives-using-intel-amt</guid>
      <dc:date>2012-06-15T15:00:44Z</dc:date>
      <clearspace:dateToText>1 year, 4 days ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/remotely-unlock-mcafee-encrypted-drives-using-intel-amt</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15235</wfw:commentRss>
    </item>
    <item>
      <title>Ask two Intel experts about the built-in security features and key capabilities of 3rd generation Intel® Core™ vPro™ processors!</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/06/13/webinar-ask-two-intel-experts-about-the-built-in-security-features-and-key-capabilities-of-3rd-generation-intel-core-vpro-processors</link>
      <description>&lt;!-- [DocumentBodyStart:a664700f-d293-4b9e-bbdf-2324f57f5014] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="font-family: Arial, sans-serif; color: #58595b; font-size: 10pt;"&gt;Learn about embedded security features that come with new 3rd generation Intel Core vPro processors for client PCs. Join Intel processor architect Yasser Rasheed and John Mahvi, client product line manager for Intel IT, as they reveal how these distinctive built-in features were designed to address the key concerns of IT security management. From threat management and identity and access, to data protection and monitoring and remediation, learn about embedded security technologies to help you: &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: Arial, sans-serif; color: #58595b; font-size: 10pt;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;Protect against unauthorized remote access.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;Improve two-factor authentication to protect sensitive data.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;Stop malware and rootkit attacks below the operating system level.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;Ensure strong client encryption.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;Automatically protect missing mobile assets.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span style="font-family: Arial, sans-serif; font-size: 10pt;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp; &lt;span style="color: #58595b; font-size: 10pt; font-family: 'Arial','sans-serif';"&gt;Yasser and John will also share some new innovative form factors with consumer-friendly capabilities and business-grade security and manageability. &lt;/span&gt;&lt;span style="font-size: 10pt; color: #58595b; font-family: Arial, sans-serif;"&gt;Bring your questions about the new features of the 3rd generation Intel Core vPro processor for Yasser and John to answer live during the moderated question-and-answer portion of the webinar.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: Arial, sans-serif; color: #58595b;"&gt;&lt;span style="font-size: 8.5pt;"&gt; &lt;/span&gt;&lt;br/&gt;&lt;span style="font-size: 10pt;"&gt; Intel IT Center Talk to an Expert webinar series&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size: 10pt;"&gt; Client Security: New Intel Processors Come with Embedded Security&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size: 10pt;"&gt; Thursday, June 21, 2012&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size: 10pt;"&gt; 9 a.m. Pacific Daylight Time&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size: 8.5pt;"&gt; &lt;/span&gt;&lt;br/&gt;&lt;span style="font-size: 18pt;"&gt; &lt;a class="jive-link-external-small" href="http://www.brighttalk.com/r/HgB" target="_blank"&gt;Register now &amp;gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:a664700f-d293-4b9e-bbdf-2324f57f5014] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">it_security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">webinar</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">integrated_security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">corevpro</category>
      <pubDate>Wed, 13 Jun 2012 15:05:59 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/06/13/webinar-ask-two-intel-experts-about-the-built-in-security-features-and-key-capabilities-of-3rd-generation-intel-core-vpro-processors</guid>
      <dc:date>2012-06-13T15:05:59Z</dc:date>
      <clearspace:dateToText>1 year, 6 days ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/webinar-ask-two-intel-experts-about-the-built-in-security-features-and-key-capabilities-of-3rd-generation-intel-core-vpro-processors</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15227</wfw:commentRss>
    </item>
    <item>
      <title>e92plus  Adds Value with Intel® Anti-Theft Technology</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/02/24/e92plus-adds-value-with-intel-anti-theft-technology</link>
      <description>&lt;!-- [DocumentBodyStart:db6407c9-5882-42fc-b540-962e03dcdb2d] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/enterprise-security/enterprise-security-core-i5-i7-vpro-e92plus-brief.html" target="_blank"&gt;&lt;strong&gt;Download Now &lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15067-226471/e92plus_sm.jpg"&gt;&lt;img alt="e92plus_sm.jpg" class="jive-image" height="169" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15067-226471/300-169/e92plus_sm.jpg" style="float: right;" width="300"/&gt;&lt;/a&gt;&amp;#8220;There has been an increasing need to strengthen security for laptop users,&amp;rdquo; said Neil Langridge, marketing manager for UK-based value-added distributor e92plus, which specializes in security technologies. &amp;#8220;Every year, about 200,000 laptops go missing at European airports alone. Add to this the fact that 71 percent of lost or stolen laptops result in some sort of data breach and it&amp;#8217;s clear that laptop security needed to be strengthened.&amp;rdquo;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;For e92plus, the solution was 2nd generation &lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/processors/vpro/core-processors-with-vpro-technology.html" target="_blank"&gt;Intel&amp;reg; Core&amp;reg; i5 and i7 vPro&amp;#8482; processors&lt;/a&gt; with &lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/architecture-and-technology/anti-theft/anti-theft-business-technology.html" target="_blank"&gt;Intel&amp;reg; Anti-Theft Technology (Intel&amp;reg; AT).&amp;nbsp; &lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;#8220;Thanks to Intel AT, laptops protected by this hardware-based technology are no longer worth stealing,&amp;rdquo; explained Langridge.&amp;nbsp; &amp;#8220;As soon as a laptop has gone missing or is stolen, it can be shut down remotely. The operating system won&amp;#8217;t start up and all the data is protected. It even supersedes the need for encryption because a thief just can&amp;#8217;t get into the computer.&amp;rdquo;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;For all the details, download our new &lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/enterprise-security/enterprise-security-core-i5-i7-vpro-e92plus-brief.html" target="_blank"&gt;e92plus business success story&lt;/a&gt;. As always, you can find many more like this on the Intel.com &lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/it-management/business-success-stories-for-it-managers.html" target="_blank"&gt;Business Success Stories for IT Managers page&lt;/a&gt; or the &lt;a class="jive-link-external-small" href="http://itunes.apple.com/us/podcast/business-solutions-for-it/id489682121" target="_blank"&gt;Business Success Stories for IT Managers channel on iTunes&lt;/a&gt;. And to keep up to date on the latest business success stories, follow &lt;a class="jive-link-external-small" href="http://twitter.com/ReferenceRoom" target="_blank"&gt;ReferenceRoom on Twitter&lt;/a&gt;.&amp;nbsp; &lt;br/&gt; &lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:db6407c9-5882-42fc-b540-962e03dcdb2d] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">case_study</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">anti_theft</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intel_at</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">core_vpro</category>
      <pubDate>Fri, 24 Feb 2012 17:45:05 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/02/24/e92plus-adds-value-with-intel-anti-theft-technology</guid>
      <dc:date>2012-02-24T17:45:05Z</dc:date>
      <clearspace:dateToText>1 year, 3 months ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/e92plus-adds-value-with-intel-anti-theft-technology</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15067</wfw:commentRss>
    </item>
    <item>
      <title>Orange and Green Builds New Revenue Streams Based on 2nd Generation Intel® Core™ i5 vPro™ Processor</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/01/05/orange-and-green-builds-new-revenue-streams-based-on-2nd-generation-intel-core-i5-vpro-processor</link>
      <description>&lt;!-- [DocumentBodyStart:334cae2a-4162-4da0-ab19-420a3e24d663] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/remote-support/remote-support-2nd-gen-core-i5-vpro-orange-and-green-study.html" target="_blank"&gt;&lt;strong&gt;Download Now&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-14997-224146/orangeandgreen.jpg"&gt;&lt;img alt="orangeandgreen.jpg" class="jive-image" height="192" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-14997-224146/382-192/orangeandgreen.jpg" style="float: right;" width="382"/&gt;&lt;/a&gt;Declining margins on hardware sales were undermining Orange &amp;amp; Green, a Czech reseller. Customers were increasingly asking for IT services like PC management. Orange &amp;amp; Green activated Intel&amp;reg; vPro&amp;#8482; technology, a component of 2nd generation &lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/processors/vpro/core-processors-with-vpro-technology.html" target="_blank"&gt;Intel&amp;reg; Core&amp;#8482; i5 vPro&amp;#8482; processors&lt;/a&gt;, for remote IT management. It also used this technology to launch a new line of business focused on IT services, strengthening the service by using Intel&amp;reg; Anti-Theft Technology (Intel&amp;reg; AT), which protects data if a computer is lost or stolen. Ultimately, Orange &amp;amp; Green was able to offset losses from hardware margin decreases and deliver a new line of business&amp;#8212;and is looking forward to a profitable future.&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&amp;#8220;We have certainly grown the business and more than offset falling revenues experienced by declining margins on hardware sales,&amp;rdquo; notes Pavel Kraus, CEO of Orange &amp;amp; Green. &amp;#8220;In fact, we are anticipating 20 percent growth and return on investment within 12 months.&amp;rdquo;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;For all the details, download our new &lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/remote-support/remote-support-2nd-gen-core-i5-vpro-orange-and-green-study.html" target="_blank"&gt;Orange &amp;amp; Green business success story&lt;/a&gt;. As always, you can find many more like this on the Intel.com &lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/it-management/business-success-stories-for-it-managers.html" target="_blank"&gt;Business Success Stories for IT Managers page&lt;/a&gt; or the &lt;a class="jive-link-external-small" href="http://itunes.apple.com/us/podcast/business-solutions-for-it/id489682121" target="_blank"&gt;Business Success Stories for IT Managers channel on iTunes&lt;/a&gt;. And to keep up to date on the latest business success stories, follow &lt;a class="jive-link-external-small" href="http://twitter.com/ReferenceRoom" target="_blank"&gt;ReferenceRoom on Twitter&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:334cae2a-4162-4da0-ab19-420a3e24d663] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">case_study</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">anti_theft</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">remote_manageability</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">core_vpro</category>
      <pubDate>Thu, 05 Jan 2012 21:22:31 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/01/05/orange-and-green-builds-new-revenue-streams-based-on-2nd-generation-intel-core-i5-vpro-processor</guid>
      <dc:date>2012-01-05T21:22:31Z</dc:date>
      <clearspace:dateToText>1 year, 5 months ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/orange-and-green-builds-new-revenue-streams-based-on-2nd-generation-intel-core-i5-vpro-processor</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=14997</wfw:commentRss>
    </item>
    <item>
      <title>Why consider TLS within Intel AMT configuration?</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2011/09/09/why-consider-tls-within-intel-amt-configuration</link>
      <description>&lt;!-- [DocumentBodyStart:2e3affb1-cef8-4066-9dfe-da0642b61ca7] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;If you are concerned about securing communications on your internal network, here are a few items you should know.&amp;nbsp;&amp;nbsp;&amp;nbsp; Be sure to share these insights with those you might not be concerned.&amp;nbsp;&amp;nbsp; This blog provides a few more insights beyond to the statement "Risks of not using TLS" found in the &lt;a class="jive-link-wiki-small" data-containerId="2005" data-containerType="14" data-objectId="1989" data-objectType="102" href="http://communities.intel.com/docs/DOC-1989"&gt;vPRO Security FAQ&lt;/a&gt;&lt;span&gt; .&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Two key security risks should be considered in regards to Intel AMT network traffic:&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;Risk of data exposure to an eavesdropper&lt;/li&gt;&lt;li&gt;Risk of machine being hijacked by an eavesdropper&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Key points to consider for these risks:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Intel AMT authentication method used (i.e. Digest or Kerberos)&lt;/li&gt;&lt;li&gt;Encryption of Intel AMT network traffic (i.e. no-TLS or TLS)&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Focusing in on the risk of data exposure, if no encryption is used communications to Intel AMT are in the clear on the network.&amp;nbsp;&amp;nbsp; An eavesdropper can see data sent back and forth.&amp;nbsp;&amp;nbsp; The majority of the data will be Intel AMT messages over HTTP or WS-Management traffic.&amp;nbsp;&amp;nbsp;&amp;nbsp; In addition to Intel AMT traffic, the eavesdropper will see other communications between the client and the infrastructure.&amp;nbsp;&amp;nbsp; (Side note: This assumes the eavesdropper has placed a network sniffer between the client and infrastructure connection AND that they know when to capture packets specific to Intel AMT.&amp;nbsp;&amp;nbsp; If the eavesdropper is capturing packets between the server and network infrastructure, they will likely be looking for more than Intel AMT related traffic)&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To address the data exposure risk, use TLS with the Intel AMT configuration.&amp;nbsp;&amp;nbsp; The method of authentication (i.e. Digest or Kerberos) will not address the data exposure risk.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Focusing on the risk of hijacking requires a little more understanding of Intel AMT authentication.&amp;nbsp;&amp;nbsp; If Kerberos authentication is used, no username or password are sent on the network.&amp;nbsp; Instead, Intel AMT authentication is handled via a Microsoft Kerberos sequence with the Intel AMT device acting as a network service.&amp;nbsp;&amp;nbsp; If Digest authentication is used, the majority of Intel AMT use cases require an MD5 digest authentication.&amp;nbsp;&amp;nbsp;&amp;nbsp; In this scenario, the username for authentication is sent in the clear but the password is a hashed nonce (i.e. hashed value calculated based on that specific session using among other items the password value known by server and client).&amp;nbsp;&amp;nbsp;&amp;nbsp; The exception is redirection scenarios (i.e. IDE-Redirect and Serial-over-LAN).&amp;nbsp;&amp;nbsp;&amp;nbsp; In these scenarios, if digest authentication is to be used the username and password are sent in the clear.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To help reinforce the above points, there are 3 images below of various network traces.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The first image shows a network capture of an MD5 Digest authentication to Intel AMT for a power-on event.&amp;nbsp; Note that the username is seen, but the password is a nonce value. (which cannot be repeated\replayed)&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-14760-219664/MD5+Digest.png"&gt;&lt;img alt="MD5 Digest.png" class="jive-image-thumbnail jive-image" height="100" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-14760-219664/620-100/MD5+Digest.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The second image shows network capture with digest authentication during an IDE-Redirect session.&amp;nbsp; Note that the username and password are in clear text.&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-14760-219665/Digest+IDER.png"&gt;&lt;img alt="Digest IDER.png" class="jive-image-thumbnail jive-image" height="266" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-14760-219665/620-266/Digest+IDER.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The third image shows network capture with digest authentication and TLS enabled.&amp;nbsp;&amp;nbsp; What you see is the TLS session being established followed by garbled data due to the encryption.&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-14760-219675/Digest+TLS.png"&gt;&lt;img alt="Digest TLS.png" class="jive-image-thumbnail jive-image" height="351" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-14760-219675/620-351/Digest+TLS.png" width="620"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The following chart may be a useful summary:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellpadding="3" cellspacing="0" style="width: 100%; border: #000000 1px solid;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align="center" style="border:1px solid black;border: #000000 1px solid;background-color:#6690BC;" valign="middle"&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Authentication \ Encryption&lt;/strong&gt;&lt;/span&gt;&lt;/th&gt;&lt;th align="center" style="border:1px solid black;border: #000000 1px solid;background-color:#6690BC;" valign="middle"&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;TLS&lt;/strong&gt;&lt;/span&gt;&lt;/th&gt;&lt;th align="center" style="border:1px solid black;border: #000000 1px solid;background-color:#6690BC;" valign="middle"&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;No TLS&lt;/strong&gt;&lt;/span&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;Kerberos&lt;/td&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;Data cannot be read.&amp;nbsp;&amp;nbsp; Machine cannot be hijacked&lt;/td&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;Data can be read.&amp;nbsp;&amp;nbsp; Machine cannot be hijacked&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;Digest (Username/password)&lt;/td&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;Data cannot be read.&amp;nbsp;&amp;nbsp; Machine cannot be hijacked&lt;/td&gt;&lt;td style="border:1px solid black;border: #000000 1px solid;"&gt;&lt;p&gt;Data can be read.&amp;nbsp;&amp;nbsp; Username can be captured.&lt;/p&gt;&lt;p&gt;If using redirection, password can also be captured.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;span&gt; &lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;A few additional points to consider:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;If you are not planning to use Intel AMT redirection and want best performance, a Digest with no-TLS situation may be preferred.&lt;/li&gt;&lt;li&gt;From a performance standpoint, a simple digest authentication with no-TLS (i.e. no encryption) will be the best situation.&amp;nbsp;&amp;nbsp; &lt;/li&gt;&lt;li&gt;The longest latency will occur with TLS added to the Intel AMT configuration.&amp;nbsp;&amp;nbsp; &lt;/li&gt;&lt;li&gt;Both Kerberos and TLS will require the FQDN of the Intel AMT device to be synchronized with the operating system hostname and correctly resolved within the infrastructure.&amp;nbsp; &lt;/li&gt;&lt;li&gt;Adding TLS configuration to Intel AMT will require an internal Certificate Authority with the root certificate applied to all systems accessing the Intel AMT device&lt;/li&gt;&lt;li&gt;If you want to ensure that only certain management systems are able to communication with Intel AMT systems, a mutual TLS configuration is recommended (note: this is very rare and may not be supported by all Intel AMT capable applications)&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:2e3affb1-cef8-4066-9dfe-da0642b61ca7] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intel_amt</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">tls</category>
      <pubDate>Fri, 09 Sep 2011 14:30:37 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2011/09/09/why-consider-tls-within-intel-amt-configuration</guid>
      <dc:date>2011-09-09T14:30:37Z</dc:date>
      <clearspace:dateToText>1 year, 9 months ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/why-consider-tls-within-intel-amt-configuration</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=14760</wfw:commentRss>
    </item>
    <item>
      <title>Intel® Core™ vPro™ Processor Gives CHEC Efficient Desktop Terminal Collaborative Management</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2011/06/17/intel-core-vpro-processor-gives-chec-efficient-desktop-terminal-collaborative-management</link>
      <description>&lt;!-- [DocumentBodyStart:3ae3de21-48d2-423f-859a-99820a14d74a] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/references/pdfs/chec.pdf" target="_blank"&gt;&lt;strong&gt;Download Now&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-14547-217695/chec.jpg"&gt;&lt;img alt="chec.jpg" class="jive-image" height="187" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-14547-217695/269-187/chec.jpg" style="float: right;" width="269"/&gt;&lt;/a&gt;There are over a thousand computer terminals at &lt;a class="jive-link-external-small" href="http://www.chec.com.cn/En/index.aspx" target="_blank"&gt;China Huadian Engineering Co., Ltd. (CHEC)&lt;/a&gt; headquarters and its 12 branch companies. But the IT operation and maintenance for the entire CHEC Group is monitored by a team of just 15 people. With such a low IT-staff-to-assets ratio, CHEC faced numerous challenges and a lot of pressure to keep its IT operations running smoothly. Challenges included reliable management of&amp;nbsp; IT assets, efficient IT maintenance, network security, and various other issues related to keeping the company&amp;#8217;s IT resources operating efficiently with few manpower resources.&lt;/p&gt;&lt;p&gt;&lt;br/&gt;To meet the challenges, CHEC deployed an &lt;a class="jive-link-external-small" href="http://www.intel.com/itcenter/products/core/core_vpro/index.htm?wapkw=(core+vpro)" target="_blank"&gt;Intel&amp;reg; Core&amp;#8482; vPro&amp;#8482; processor&lt;/a&gt;-based desktop terminal integrated management solution that included a Lenovo* manageable PC and GeneralSoft* network abnormality investigation system. The result? Greater efficiency and accuracy in collecting statistics on IT assets, improved IT maintenance efficiency, and enhanced defense against network anomalies.&lt;/p&gt;&lt;p&gt;&lt;br/&gt;To learn more, read our new &lt;a class="jive-link-external-small" href="http://www.intel.com/references/pdfs/chec.pdf" target="_blank"&gt;CHEC business success story&lt;/a&gt;. As always, you can find this one, and many more, in the Intel.com &lt;a class="jive-link-external-small" href="http://www.intel.com/references" target="_blank"&gt;Reference Room&lt;/a&gt; and &lt;a class="jive-link-external-small" href="http://www.intel.com/itcenter" target="_blank"&gt;IT Center&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:3ae3de21-48d2-423f-859a-99820a14d74a] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">client_management</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">remote_management</category>
      <pubDate>Fri, 17 Jun 2011 15:31:03 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2011/06/17/intel-core-vpro-processor-gives-chec-efficient-desktop-terminal-collaborative-management</guid>
      <dc:date>2011-06-17T15:31:03Z</dc:date>
      <clearspace:dateToText>2 years, 3 days ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/intel-core-vpro-processor-gives-chec-efficient-desktop-terminal-collaborative-management</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=14547</wfw:commentRss>
    </item>
  </channel>
</rss>

