Live data from Hacker News

20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

twitter.com

41–50 of 476 posts

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#41

Fingers crossed that this will enable some smart person to completely disable the management engine.

AFAIK the ME is required to initialize the processor so it can never be completely disabled. The best you could do is remove any code beyond necessary initialization which has mostly already been done by me_cleaner.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#42
post #14

Someone have a mirror? Seems the actual files are here: https://t.me/exconfidential/590 Edit: files are here https://mega.nz/folder/CV91XLBZ#CPSDW-8EWetV7hGhgGd8GQ or magnet:?xt=urn:btih:38f947ceadf06e6d3ffc2b37b807d7ef80b57f21

You can't download from mega.nz unless you have their "downloader" app or an account, or if you have Firefox or Safari. It's useless.

The torrent works.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#43
post #2

> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel. Can't say I'm surprised, people are lazy. Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things…

Password protection may have been used to bypass antivirus and other filters. While you should treat dumps like this with a lot of suspicion, treat password protected zips with a heaping dose of care as they may have been used to evade automated defenses.

Yes. Whenever I email or transfer a zip via any method really I always put a basic password on it.

I've been bitten way too many times by dumb filters that pick some file out of the zip and declare that it is malicious. I also don't trust messenger apps to not pull my files out and do who knows what with them. A basic password prevents this junk 99% of the time for almost no effort.

It won't stop a determined system from cracking the password. But that isn't what I'm trying to defend against.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#44
post #27
post #6

The advice to try a password of “Intel123” on any protected files says it all. This organisation genuinely deserves whatever is coming for them.

This type of passwords are use in almost all big corporations. People are being asked to encrypt things but without password managers or keys management tools.

Yeah, I know of plenty of other companies with similar multi-time-use passwords. The data in that zip file probably isn't that confidential.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#45
post #28
post #17

Earlier quoted context omitted.

Of course it's not legal. This is exfiltrated intellectual property being shared without license.

Is the person publishing this liable or just their source? Because this seems to be a hobby for the person publishing it and yet they also aren't concealing their identity. They list their former employer on their website.

Is the person publishing it or are they linking people to a place where it is published?

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#46
post #27
post #6

The advice to try a password of “Intel123” on any protected files says it all. This organisation genuinely deserves whatever is coming for them.

This type of passwords are use in almost all big corporations. People are being asked to encrypt things but without password managers or keys management tools.

> People are being asked to encrypt things but without password managers or keys management tools.

That doesn't really make me think better of the company; if the company fails to support secure workflows, it's still on them when people fail to use secure workflows.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#47
post #33
post #29

Intel denies it was hacked: https://twitter.com/TheRegister/status/1291461942624677889

... They're claiming it came from an NDA'd source of IP that's shared with customers. Given that it _appears_ like there are backdoors in this Firmware code, we can conclude that if there are such backdoors then they were shared with numerous customers. That really doesn't improve the optics of the breach.

Imagine what they aren’t sharing

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#48
post #26

Earlier quoted context omitted.

It would be illegal, but some of that code might help Coreboot development.

> but some of that code might help Coreboot development Unlikely. Most projects won't come anywhere near this sort of thing. There may be a possibility of doing clean room implementation, but writing the spec based on stolen IP is the problematic step. Then again, there is a high chance that none of this will be useful.

It will be more or less impossible to prove or disprove that anyone obtained some crucial information from there. The info will always somehow make it's way into the places it's needed eventually.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#49
post #18

Earlier quoted context omitted.

Optimistically, the exposure of backdoors in the firmware may cause Intel to patch and close them. Realistically, Intel will patch the firmware and replace the backdoors with new ones.

Besides the backdoors I mean, I was thinking about performance or usability improvements...

[deleted]

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#50
post #28

Earlier quoted context omitted.

Is the person publishing this liable or just their source? Because this seems to be a hobby for the person publishing it and yet they also aren't concealing their identity. They list their former employer on their website.

Is the person publishing it or are they linking people to a place where it is published?

It seems that they are the ones publishing it, from the wording of the tweets.
Post reply on HN