Live data from Hacker News

20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

twitter.com

11–20 of 476 posts

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#11
At a previous workplace we had a few places in the code which used the word backdoor. It was not an actual backdoor though, but merely a debugging server that could be enabled and allowed you to inspect internal state during runtime. At some point I removed the word backdoor, fearing it would get to a customer or during an audit someone would misunderstand. :|

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#17
post #16

Is releasing this legal? It seems like this person isn't really disguising their identity or concerned about breaking the law. In their profile they even seem to brag about leaking company's code.

Of course it's not legal. This is exfiltrated intellectual property being shared without license.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#18

In what ways can an end user of intel processor expect to benefit from this? I'm guessing none, since ever consumer interface is already a standard ... Can anybody chime in?

Optimistically, the exposure of backdoors in the firmware may cause Intel to patch and close them.

Realistically, Intel will patch the firmware and replace the backdoors with new ones.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#19
post #14

Someone have a mirror? Seems the actual files are here: https://t.me/exconfidential/590 Edit: files are here https://mega.nz/folder/CV91XLBZ#CPSDW-8EWetV7hGhgGd8GQ or magnet:?xt=urn:btih:38f947ceadf06e6d3ffc2b37b807d7ef80b57f21

The t.me page is a Telegram comment containing a mega.co.nz download link

I think the tg:// link is just the site trying to open up in the Telegram app.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#20
post #2

> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel. Can't say I'm surprised, people are lazy. Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things…

Also, the passwords are listed in docs that appear to be alongside the encrypted files. That's a bit like leaving the keys to your house _on top_ of your front doormat.
Post reply on HN